The Federal Information Security Modernization Act (FISMA) is the US federal law that requires federal agencies to protect their information and information systems through a risk-based security program. It covers systems an agency runs itself and systems used or operated by contractors on its behalf. The 2014 law amended the earlier Federal Information Security Management Act of 2002, and both are commonly called FISMA. For IT buyers and providers, FISMA matters mostly through contracts: if you build, host or run a system for a federal agency, you will likely inherit FISMA-based security requirements. This entry is general information, not legal advice; confirm requirements with the contracting agency or counsel.
At a glance
- FISMA applies to federal agencies and to systems contractors operate for them.
- It relies on NIST standards and guidelines for how systems are categorized, secured, assessed and authorized.
- Each system is categorized as Low, Moderate or High impact, which sets its baseline of controls.
- Systems receive an agency authorization to operate (ATO); there is no FISMA certification.
- Agencies report on their security programs and on major incidents to oversight bodies and Congress.
What problem it solves
Federal agencies hold enormous amounts of sensitive information and depend on thousands of systems, many built or run by contractors. Without a common legal framework, security would vary widely from one agency to another, and no one would be clearly accountable.
FISMA sets that framework. It makes agency leaders responsible for information security, requires a documented, risk-based program, and creates oversight through central agencies and inspectors general. For contractors, it means federal customers ask for consistent, well-documented security rather than ad hoc assurances.
How it works
Categorize. Each system is categorized by the potential impact of a loss of confidentiality, integrity or availability.
Select and implement controls. Controls are drawn from NIST’s federal security control catalog, tailored to the system’s impact level.
Assess. Independent assessors test whether controls are in place and working.
Authorize. A senior agency official reviews the results and risks and decides whether to grant an ATO.
Monitor and report. Systems are monitored continuously, incidents are reported, and agencies report on their programs each year, with independent evaluation by inspectors general.
Cloud services. For cloud, agencies generally rely on FedRAMP to standardize the assessment, then make their own authorization decision.
Impact levels and roles
FISMA does not certify vendors in tiers. Its closest structures are the impact level assigned to each system and the roles involved, summarized here in general terms.
| Level or role | What it covers | How it is decided or validated | Typical evidence |
|---|---|---|---|
| Low impact | Systems where a breach would have limited adverse effect | Agency categorization; baseline controls assessed | System security plan, assessment, ATO |
| Moderate impact | Systems where a breach would have serious adverse effect | Agency categorization; larger control baseline assessed | System security plan, assessment, ATO |
| High impact | Systems where a breach would have severe or catastrophic effect | Agency categorization; most extensive baseline assessed | System security plan, assessment, ATO |
| Agency | Owns the system’s risk and the ATO decision | Agency leadership and authorizing official | ATO letter and continuous monitoring |
| Contractor | Builds or operates a system on the agency’s behalf | Contract terms and agency assessment | Security documentation and monitoring reports |
| Oversight bodies | Set policy, guidance and operational directives, and evaluate programs | OMB, CISA, NIST and inspectors general, each in its role | Policy, directives, standards, annual evaluations |
When it matters for buyers
- When you run a system for a federal agency. Expect contract clauses requiring FISMA-aligned controls and an ATO.
- When you choose cloud services for a federal workload. FedRAMP status is usually the starting point.
- When a provider claims “FISMA compliant”. Ask which system, which impact level and which agency granted the ATO.
- When you are a subcontractor. Requirements may flow down from the prime contract.
- When you build a security program. NIST guidance used under FISMA is a common reference for others too.
Our governance, risk and compliance overview covers advisors and platforms that manage control documentation and assessments.
Questions to ask vendors
- Which systems or services hold an agency ATO, at which impact level, and from which agency?
- Do you hold FedRAMP status for the cloud services involved, and for which exact offering?
- Which controls do you implement, and which remain our responsibility?
- How do you report incidents to us, and how quickly?
- Can you support continuous monitoring and annual reporting requirements in our contract?
How it differs from FedRAMP
FISMA is a law that applies to agencies’ information systems in general. FedRAMP is a program operating within that broader framework that standardizes the security assessment of cloud services so agencies can reuse it. FedRAMP status supports an agency’s FISMA decision but does not replace it. State and local buyers may use GovRAMP instead. Contractors that hold federal information on their own systems, rather than operating a system for an agency, are more often measured against NIST Special Publication 800-171, while the NIST Cybersecurity Framework (NIST CSF) is voluntary guidance for any organization. A risk assessment and a GRC platform are common tools for managing all of them.
