Federal Information Security Management Act

· About Federal Information Security Management Act

Key Takeaways

  • FISMA applies to federal agencies and, through agency contracts and oversight, to contractors that operate or handle federal information systems or federal information.
  • The operative law is the Federal Information Security Modernization Act of 2014, which amended the original 2002 FISMA; there is no verified enacted 2025–2026 replacement as of 6 September 2026.
  • Agencies must maintain a risk-based information security program, document it, test it, and report annually on compliance, incidents, and remediation status.
  • The law is enforced through OMB oversight, CISA coordination, and agency IG audits; FISMA itself does not create a standalone criminal penalty schedule, but noncompliance can trigger audit findings, adverse congressional attention, budget consequences, and contract actions.
  • Security incidents affecting federal systems must be reported under OMB and CISA requirements tied to FISMA implementation, with timelines and formats set by executive-branch guidance.
  • The statutory framework is still current, but much of the operational detail comes from OMB memoranda, CISA directives, and NIST standards rather than the statute’s text alone.

What It Is

FISMA is the federal information security law that requires executive-branch agencies to develop, document, and implement information security programs to protect federal information, operations, and assets against threats. The current governing statute is the Federal Information Security Modernization Act of 2014, which amended the original Federal Information Security Management Act of 2002. CISA states that the 2014 act amends the 2002 law, and CMS’s 2026 review page likewise describes the 2014 modernization as the operative amendment.

The enforcement and coordination structure centers on the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and agency inspectors general. Congress first enacted FISMA in 2002 as part of the E-Government Act, and the modernization act was enacted in 2014; the 2014 act is the current statutory baseline. Public materials available in 2025–2026 indicate no enacted 2025–2026 amendment that displaced the 2014 framework, although several bills and proposals have circulated.

Who Must Comply

FISMA applies directly to federal agencies, meaning executive-branch agencies and, by extension, the systems they operate or use to conduct federal business. It also reaches contractors, cloud providers, and other service providers when they handle federal information or operate federal information systems on an agency’s behalf through contractual, acquisition, or oversight requirements.

The practical trigger is not only ownership of a system but also whether the system supports agency operations or stores, processes, or transmits federal information. The law is implemented through agency security programs and procurement clauses, so contractors often inherit obligations through contract terms, security authorizations, and reporting duties.

There is no general private-sector applicability threshold like revenue, employee count, or sector size. Instead, applicability turns on the entity’s relationship to a federal agency and whether the information or system falls within the federal boundary. State, local, and tribal governments are not generally subject to FISMA as such, though they may interact with federal systems or grants and therefore encounter related control expectations.

Core Requirements

  1. Agency security program. Each agency must maintain a risk-based information security program with policies, procedures, and controls tailored to its operations and information systems.
  1. Risk management and system categorization. Agencies must assess risks, categorize systems and information, and apply safeguards commensurate with sensitivity and mission impact, typically using the NIST framework.
  1. Security planning and authorization. Agencies must document system security plans, authorize systems before operation, and keep authorizations current through review and remediation.
  1. Continuous monitoring and testing. Agencies must monitor controls, test effectiveness, remediate weaknesses, and track vulnerabilities and known exploited issues in line with executive-branch guidance.
  1. Incident detection and reporting. Agencies must identify, report, and respond to cybersecurity incidents under OMB and CISA reporting rules that implement FISMA duties.
  1. Independent review and audit. Inspectors general or equivalent independent assessors must evaluate agency compliance and report results annually to OMB and Congress.
  1. Contractor oversight. Agencies must ensure contracts and service arrangements require appropriate security controls, incident handling, and access to evidence needed for oversight.

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Original FISMA enacted | 2002 | Federal agencies became subject to a government-wide information security framework. | | FISMA modernization enacted | 2 December 2014 | The 2014 act amended the 2002 law and shifted operational detail toward OMB, CISA, and agency implementation. | | Ongoing annual IG review cycle | recurring each fiscal year | Agencies undergo annual independent security evaluation and reporting. | | Incident-reporting deadlines | set by current OMB/CISA guidance | Federal incidents must be reported within the current executive-branch timeframes. |

FISMA is primarily an administrative and oversight statute, so it does not specify a single universal civil fine schedule for routine noncompliance. The main consequences are adverse IG findings, OMB remedial directives, congressional scrutiny, funding and authorization pressure, and procurement or contractor remedies when security requirements are embedded in contracts. In serious cases, related misconduct can also expose individuals or contractors to liability under other laws, but that comes from those other authorities rather than FISMA’s core text.

How to Comply

  1. Map your federal footprint. Identify every system, data flow, and contract that touches federal information, federal operations, or agency-operated environments.
  1. Assign governance. Give a named executive owner, security lead, and compliance lead responsibility for FISMA duties, reporting, and remediation tracking.
  1. Build a control baseline. Use NIST CSF 2.0 for program structure and NIST SP 800-53 for control selection; map implementation against ISO 27001 if the organization already runs an ISMS.
  1. Document the system inventory and authorization state. Maintain current system security plans, assessment results, authorization packages, and POA&Ms for each federal system or service.
  1. Operationalize monitoring and evidence collection. Use continuous logging, vulnerability scanning, configuration management, and incident triage so evidence is ready for audits and reporting.
  1. Align incident response to federal timelines. Ensure playbooks, escalation paths, and forensic retention meet the applicable OMB/CISA reporting windows and preserve evidence for IG review.
  1. Control suppliers and cloud services. Flow FISMA requirements into contracts, verify subcontractor controls, and validate shared-responsibility boundaries before go-live.
  1. Use ISO 42001 where AI is in scope. If an agency or contractor uses AI in federal environments, ISO 42001 can support governance and risk management, but it does not replace FISMA controls or NIST-required safeguards.

Related Regulations

  • Federal Information Security Modernization Act of 2014 — This is the current statutory amendment that modernized the original 2002 law and remains the operative federal baseline.
  • Federal Risk and Authorization Management Program (FedRAMP) — FedRAMP overlaps with FISMA for cloud services used by agencies, because FedRAMP authorization is built on federal security assessment and authorization principles.
  • Federal Information Processing Standards (FIPS) and NIST SP 800-53 — These standards supply much of the technical control content agencies use to satisfy FISMA obligations.
  • Privacy Act of 1974 — This law can overlap where FISMA-protected systems also contain personal data, requiring privacy controls and notice obligations in addition to security controls.
  • CISA binding operational directives — These directives do not replace FISMA, but they often operationalize urgent remediation duties for federal systems and contractors.

Does FISMA apply to contractors outside the federal government?

Yes. Contractors are covered when they operate, maintain, or process federal information or federal information systems for an agency. The exact duties usually come from agency contracts, security clauses, and inherited control requirements rather than from a standalone private-sector registration scheme.

Is FISMA still the current law in 2026?

Yes. The current operative statute is still the Federal Information Security Modernization Act of 2014, which amended the 2002 law. Publicly available 2026 materials describe that 2014 framework as the governing baseline, and no enacted replacement displaced it.

Does FISMA set one fixed penalty for noncompliance?

No. FISMA is mainly an oversight and administrative compliance regime, not a single-fine statute. The usual consequences are audit findings, remediation orders, budget and oversight pressure, and contract consequences when security failures occur in federal service arrangements.

Are state and local governments subject to FISMA?

Not generally. FISMA is aimed at federal agencies and the systems and contractors that support them. State and local entities may still encounter FISMA-like requirements when they receive federal funding or connect to federal systems, but that is indirect applicability.

What standards should agencies use to implement FISMA?

NIST standards are the core implementation layer, especially control baselines and assessment guidance. ISO 27001 can help structure an information security management system, and ISO 42001 is useful where AI governance is part of the federal environment, but neither replaces FISMA-specific duties.

Sources

Put it into practice

More compliance guides