Skip to main content
Updates
from Policy

CISO Memo 25-03: ATO requirements for systems migrating to the OIT Hybrid Cloud

Learn about Authorization to Operate (ATO) requirements for CMS systems migrating to the Office of Information Technology (OIT) Hybrid Cloud environment

Published on: 12/18/2025

2 minute read

Purpose and audience

This memorandum is for all Business and System Owners, Information System Security Officers (ISSOs), and Application Development Organizations (ADOs) at the Centers for Medicare and Medicaid Services (CMS).

This memorandum provides CMS guidance regarding Authorization to Operate (ATO) requirements for information systems migrating to the OIT Hybrid Cloud environment.

Policy

A system migrating to the OIT Hybrid Cloud environment does not require a new ATO provided a Security Impact Analysis (SIA) is completed, signed and approved by: 

  • The system team 
  • Infrastructure and User Services Group (IUSG)
  • Information Security and Privacy Group (ISPG)

Additional requirements

A new ATO is not required when the following conditions are met:

  • The system has a current, active ATO.
  • The system’s hosting environment is a CMS-authorized environment.
  • An SIA documenting the migration scope and security impact is completed and signed / approved by the system team, IUSG, and ISPG.
  • The system is integrated with Continuous Diagnostics and Mitigation (CDM) tooling, Enterprise Cloud-Native Protection Platform (CNAPP), and Enterprise Security Information and Event Management (SIEM)

Documentation

Collection and verification of the following artifacts must be completed upon migration to ensure there are no unintended consequences of the migration to the security and privacy controls of the system: 

• Approved Security Impact Analysis (SIA) signed by the system team, IUSG and ISPG

Contact

If you have questions, please contact the Information Security and Privacy Group (ISPG): CISO@cms.hhs.gov.


See all blog posts

Policy articles and updates

About the publisher

The Information Security and Privacy Policy Team (also known as CMS CISO Team) manages the policies, standards, and guidance that keep information and systems safe at CMS. Our goal is to help you understand requirements and apply them effectively in your project environments – so you can focus on delivering value to CMS beneficiaries and customers.

View all posts by Policy