What is an Upstream EDE Entity?

There are three categories for an upstream EDE Entity: For all upstream arrangements, the following must be observed: It’s important to note that all EDE Web Brokers, DE Technology Providers, and Hybrid Entities meet all CMS requirements for both REMEDIATION and AUDIT. This includes remaining up-to-date on all requirements applicable to Upstream EDE Entities with a single sign-on (SSO). All Upstream EDE Entities with an SSO are required to retain an independent auditor to conduct a privacy and security audit. This audit must be completed by the deadline (or prior to approval, for new entities). Failure to submit the required audit could result in the CMS suspending access to the EDE Entity’s access to use the EDE for production. Summation of Audit requirements for Hybrid Issuer Upstream EDE Entity: The current requirements for an EDE Hybrid Issuer Upstream EDE Entity are as follows: Elevate has extensive audit experience conducting operational, security, and privacy audits and we can efficiently assess and manage compliance with each CMS program requirement. Elevate can work with your organization to get ready to pass the audit and meet all CMS requirements and/or perform the audit. We have helped EDE Web Brokers and EDE Technology Provider get approved by CMS and DE Web Brokers meet the requirements.
2023 AI Bias Audit Laws

USA AI Bias Audit Laws The NY automated employment decision tools law Update as of December 15, 2022: Due to the volume of comments the NYC Department of Consumer & Worker Protection received in response to the proposed rule, Local Law 144 will not be enforced until April 15, 2023. ___________________________________________________________________________ The NY Local Law #2021/144 amending the administrative code of the city of New York, in relation to automated employment decision tools which will take effect Jan. 2, 2023, would require that a bias audit be conducted on an automated employment decision tool prior to the use of said tool. The bill would require that candidates or employees that reside in the city be notified about the use of such tools in the assessment or evaluation for hire or promotion, as well as be notified about the job qualifications and characteristics that will be used by the automated employment decision tool. Violations of the provisions of the bill would be subject to a civil penalty between $500 to $1,500 each day on which an automated employment decision tool is used in violation of this section. Failure to provide any notice to a candidate or an employee constitutes a separate violation. The law focuses on conducting bias audits of the tools to identify its potential discrimination based on race/ethnicity or gender. Under the law, employers will be prohibited from using an AI-type tool to screen job candidates or evaluate employees unless the technology has been audited for bias no more than one year before its use and a summary of the audit’s results has been made publicly available on the employer’s website. The law defines automated employment decision tools as “any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues simplified output, including a score, classification, or recommendation, that is used to substantially assist or replace discretionary decision making for making employment decisions that impact natural persons.” The law is unclear in many aspects such as whether it includes applications such as the pre-employment personality test or how often this assessment needs to be performed (e.g., anytime there is a code change). The Illinois Artificial Intelligence Video Interview Act (HB 2557) The law requires employers who use artificial intelligence to analyze video interviews to do the following when considering applicants for positions based in Illinois before asking applicants to submit video interviews: Elements of concern: NIST Special Publication 1270- Towards a Standard for Identifying and Managing Bias in Artificial Intelligence NIST (National Institute of Standards and Technology) created this document with the intent to develop methods for increasing assurance, governance, and practice improvements for identifying, understanding, measuring, managing, and reducing bias. This proposal is part of NIST’s broader work in developing a risk management framework for Trustworthy and Responsible AI. The document covers the following: In this document, NIST provides an initial socio-technical framing for AI bias, including key context and terminology, highlights of the main challenges, and foundational directions for future guidance. An example on how to audit AI Bias using a Black Box approach Each algorithm and related processes associated with training the AI must be evaluated to determine a strategy to test the AI algorithm for bias. We are auditing AI Bias (the code), not the process (human actions). This article focuses on one possible way of testing, considering a black box approach where the AI engine code and the database structure and data are not accessible to the auditor. The example relates to testing against the NY Bias Audit Law, where candidate selection for a job search should not be based on race/ethnicity or gender. Caveat – before performing any kind of analysis, please review your contract agreement with the manufacturer, as any approach to measure and identify a tendency or bias can be considered an attempt to reverse engineer the algorithm and infringe their Intellectual Property. For those cases, make sure you obtain a written consent and authorization from your provider. Information Gathering and Documentation Analysis Request the job description for the positions to use in the test. That documentation will explain how the algorithm would be instructed to identify the optimal skills for candidate selection criteria (e.g., which skills are needed, what is the value assigned to them, and any other factor used to select best candidates for a job), and the information process and classification to determine the final score and criteria for identifying valid candidates (e.g., a skill may be missing but still a valid candidate, or the weight of experience, etc.). Seek to understand how the algorithm works and process parsing of the data for the algorithm to analyze. Seek to understand the sets of selection criteria and determine if there is any inherent bias even before the algorithm is fed the data. If the data is Bias, the algorithm will respond accordingly. Garbage in garbage out. Data Analysis From the data set provided (all applicants for a particular job posting), perform a regression Analysis. In the example of a testing for AI bias for selection of candidates for employment based on race or gender, run the regression analysis to identify candidate population, segment it by race and gender, and analyze population of rejected candidates and accepted ones, compare skills between both populations for potential discrimination (similar skills found in the accepted and rejected populations). Additionally, perform Multiple Regression Analysis by groups (gender, race). In multiple regression, the objective is to develop a model that describes a dependent variable x(Candidate selection) to more than one independent variable y, z (gender and race). Regression is used to predict the future result. If one segment (variable) shows a higher predictive result, it will identify the algorithm’s “ideal” characteristics of a candidate (in this example would be gender and race), it will show its biases. To be unbiased, the regression should be “not significant”. You can use any statistical software (e.g., SPSS, Excel, R, Q, etc.) to perform the analysis. Review of Data Criterion Provided to the
Are You Ready for SWIFT ISO 20022 In November?

On July 5, 2018, an announcement was published by the Federal Reserve Board, which described the intent to adopt and migrate to the new ISO 20022 standard to replace the existing financial transaction messaging service. In response, last year SWIFT also announced a planned, formal migration to ISO 20022 MX, an established global messaging system that is emerging as the established standard for virtual payment messaging and processing transactions in a simplified and standardized manner. The US Federal Reserve Bank has already indicated that its new FedNOW payment system and FedWire Funds Service will be based on the ISO 20022, expecting to be fully transitioned by November 2023, to stay in step along with 70+ other participating countries. It is expected that the ISO 20022 standard will navigate 87% of worldwide transactions in value within the next 5 years. Some perks to making the move to ISO 20022 MX is the ability to request Real-Time Payments, operate outside of business hours, and improve security, while minimizing delays in transaction processing. SWIFT’s quickly-approaching commencement date is June 2022 and the complete migration is anticipated to roll out over a 3-year period, during which the MT standard will remain active in tandem with ISO 20022 through Q3 of 2025 to inspire a smooth transition. As SWIFT makes a move to begin the transition from the previous MT standard to the ISO 20022MX system for global cross-border payments, there are imminent milestones that are on the horizon. All financial institutions (FIs) should keep these changes on their radar to prepare accordingly their internal governance, technology, and processes to avoid the risk of being excluded from the international payments system and access to central banks. It’s recommended that FIs have an assessment performed of their financial framework in order to anticipate any updates needed to welcome the ISO 20022 standard. On March 31, 2022, SWIFT released the following timeline guidance, mandating that all banks currently on the SWIFT network have the ability to process and receive transactions using MX messages, or ISO 20022, starting in November 2022. While the official migration date is slated for Q4 of 2023, several benefits can already be realized within the improved SWIFT network.
DUNS Has Been Replaced, Say Hello to UEI

In this article, we look at the switch from DUNS to the Federal Contractor UEI Number. Early last month, the United States federal government announced the retirement of and discontinued its use of the Data Universal Numbering Systems (known as DUNS). The DUNS was the previous primary means of identifying entities for federal contract awards. Effective April 4th, DUNS numbers are no longer accepted and all federal contractors will be redirected to obtain the new 12-character alphanumeric identification number, referred to as the Unique Entity Identification, or UEI. In order to remain compliant, all federal contractors are advised to update their E-Verify accounts after obtaining their new UEI from Sam.gov. Here are some items to be aware of during this update: If you haven’t done so already, log in to SAM.gov and identify the new UEI assigned to your firm. Ensure all saved searches and APIs are no longer reflecting the previously utilized DUNS number and have been transitioned to the UEI. Now is a great time to do a maintenance check-up on your firm’s federal contractor status and ensure that a current and active registration in SAM.gov contains the new UEI identifier congruently.
PCI DSS v4.0.1: The Current Standard and What Your Organization Must Do

If your organization touches credit card data in any way, the Payment Card Industry Data Security Standard (PCI DSS) is central to how you operate. The standard underwent its first major overhaul in more than a decade with the release of v4.0, and the transition is now complete. The future-dated requirements that were once optional are mandatory, the older versions are retired, and v4.0.1 is the sole active standard. This guide explains where PCI DSS stands today, what changed, and what you need to have in place to remain compliant. Where PCI DSS Stands Today Here is the current state of the standard, which matters because organizations still operating under older assumptions are now out of compliance. PCI DSS v4.0.1 is the current and sole active version of the standard. It became the only valid version on December 31, 2024, when PCI DSS v4.0 was retired. The previous major version, v3.2.1, retired earlier still. The PCI Security Standards Council officially retired PCI DSS v3.2.1 on March 31, 2024, leaving v4.0 and then v4.0.1 (collectively v4.x) as the active standard. Most importantly, the phase-in period is over. As of March 31, 2025, all 51 future-dated requirements from PCI DSS v4.0 are mandatory and must be validated during PCI DSS assessments, with no grace period. If your organization is still operating as though v3.2.1 controls are sufficient, or if you validated under v4.0 in 2024 but treated the future-dated requirements as optional, your next assessment will not pass unless those controls are now implemented. How PCI DSS Got Here: The Timeline The path from the old standard to today’s requirements unfolded over three years, and the milestones explain why the requirements you face now are not negotiable. PCI DSS v4.0 was published in March 2022, the result of a multi-year revision process. The PCI SSC had gathered over 3,000 feedback items from participating organizations through a formal request-for-comment process to shape the update. Version 4.0 introduced 64 new or updated requirements: 13 became effective immediately, and 51 were designated as future-dated best practices until March 31, 2025. The Council deliberately built in a long runway. Organizations were given roughly two years to understand the impact of the changes and prepare for when the new requirements would become required. After v3.2.1 retired on March 31, 2024, all assessments had to be conducted against v4.0 or v4.0.1. Then, in June 2024, the Council issued v4.0.1. What v4.0.1 Changed (and Did Not) A common point of confusion is whether v4.0.1 added new obligations. It did not. Version 4.0.1 was a limited revision that corrected typographical and formatting errors, clarified the intent and applicability of certain requirements, and improved guidance. It introduced no new requirements and deleted none. This distinction matters for planning. All substantive changes to merchant and service-provider obligations come from the v4.0 requirements themselves, including the future-dated requirements that became mandatory on March 31, 2025. The v4.0.1 limited revision did not change the March 31, 2025 effective date for those new requirements. In other words, if you are working from a v4.0 understanding of the controls, v4.0.1 did not move the goalposts; it only sharpened the language. The Biggest Shift: Compliance Is Now Continuous Beyond any single requirement, v4.x changed the philosophy of PCI compliance. The most significant shift is that compliance is now treated as an ongoing practice rather than an annual event. Controls need to be in place and documented year-round, not assembled in the run-up to an assessment. This reframes what readiness means. An organization that scrambles to document controls before its annual assessment is no longer aligned with how the standard expects security to operate. The future-dated requirements reinforce this, emphasizing continuous monitoring, defined roles and responsibilities, and documented processes that run throughout the year. Examples of Now-Mandatory Requirements The future-dated requirements that became enforceable in March 2025 reflect modern threats, particularly around web-based payment pages and authentication. A few illustrate the scope of what is now required. For payment page security, Requirement 6.4.3 calls for keeping an inventory of client-side scripts on payment pages, authorizing them, and documenting their purpose, while Requirement 11.6.1 requires deploying tamper and change-detection mechanisms on payment pages that alert on unauthorized modifications. These address e-skimming and Magecart-style attacks that target the browser. Authentication also tightened significantly. Most changes specific to Requirement 8 took effect on March 31, 2025, and because of the complexity of the new multi-factor authentication requirements, organizations were warned not to wait until the last minute to bring their identity systems and policies up to standard. Many of these controls are simply modern cybersecurity good practice, so implementing them addresses real risk in addition to satisfying the assessment. What Your Organization Should Do Now The transition window has closed, so the priorities are straightforward. Confirm that you are assessing against v4.0.1, not any earlier version, since it is the only active standard. Treat all 51 formerly future-dated requirements as mandatory, because they are, and verify each is implemented and documented rather than planned. Shift your posture from annual scramble to year-round operation, with controls live and evidence maintained continuously. And give particular attention to the newer, more complex requirements, especially payment-page script integrity (6.4.3 and 11.6.1) and the expanded MFA obligations under Requirement 8, which tend to take the most time to implement correctly. If you validated under v4.0 in 2024 and deferred the future-dated items, treat closing those gaps as the immediate priority, because your next assessment depends on them. How Elevate Can Help Using payment card technology safely is essential to your organization’s reputation, and the current PCI DSS standard demands continuous, documented security rather than a once-a-year exercise. Elevate Consult is well-versed in PCI DSS controls and the v4.x requirements, and we help organizations confirm their environment meets the current standard, close gaps left by deferred future-dated requirements, and build the year-round compliance posture v4.0.1 expects. Schedule a PCI DSS consultation to assess where your environment stands against the current standard. Frequently Asked Questions What is
CMMC 2.0 – Extended-Release Dates Among Rule-Making Delays

In this article, we look at factors affecting DoD CMMC 2.0 Release Date. Since its initial release in the fall of 2021, the original CMMC model (now referred to as CMMC 1.0) received pushback from smaller and medium-scale corporations who vocalized their opinion that a self-assessment should serve as appropriate for operators who are not handling sensitive CUI. As a result, early last November, the DoD announced that the newly released CMMC (Cyber Security Maturity Model Certification) security model would be receiving an immediate makeover to create a leaner and cleaner guideline, with the intention of creating a more collaborative relationship with the industry and creating increased opportunities for self-attestation for qualifying organizations. CMMC 1.0 (as it’s now known) has been officially retired and the replacement, CMMC 2.0, remains in the early stages of Rule-Making and initial review. In early February, a directive from Kathleen H. Hicks, Deputy Secretary of Defense, re-assigned the responsibility of the CMMC 2.0 away from the USD (A&S) and over to the DoD in order to establish united leadership and guidance for all cybersecurity interests and programs. This week, both the DoD and the CMMC-AB held Town Halls to update the progress of CMMC 2.0. The CMMC-AB advised on continued available training for CMMC auditors wishing to become certified and enter the marketplace, mentioning that the 6th C3PAO was recently accepted into the marketplace and that currently, the applications for RPs, RPOs, and LTPs have doubled since February of 2021. The Delta training for CCP candidates who have completed CCP 1.0 courses was released on the 15th of February, and Delta training for Registered Practitioners (RPs) is expected to be released by March 1st. The training is anticipated to take 2-3 hours to complete. The DoD Town Hall re-outlined the approved proposed adjustments that will be incorporated into the new model 2.0. This includes eliminating both Levels 2 and 4, which were considered “transition levels” and creating a leaner model with 3 tiers, Foundational, Advanced, and Expert. The DoD feels that the CMMC 2.0 addresses the self-assessment concerns which spurred the re-evaluation, which now had been adjusted to allow self-attestation for all companies who fall under Level 1. Level 1 companies hold federal contracting information only, not critical programs or CUI. Companies included in the Level 2 designation and higher will be evaluated on a case-by-case basis to be considered for self-attestation for infrequent exceptions. There was mention as well that the removed control items from CMMC 1.0 could possibly be added back into the requirements for NIST 800-171. The main takeaways from the Town Hall updates are as follows: Rulemaking is still in progress, but the finalization of the CMMC DFARS may take up to 2 years. (Last September the estimate was 9-24 months) As a result, an implementation may be pushed back and it could be as long as 3 years before CMMC is required in government contracts. Most Contractors (approx. 80,000) Level 2 and above possessing CUI will likely require a 3rd party assessment, this differs from the original thought that CMMC 2.0 would provide more opportunities for self-attestation. What does all of this mean? Despite the delay, while the DoD is working on Rule-Making, it is important to remember that all indications state that Level 2 or higher companies will still be expected to conform to the CMMC requirement for third-party attestation of compliance. Has your company determined if this third-party attestation is necessary for certification? If so, keep in mind that even with the extended delay before we’ll see CMMC 2.0 certification requirements appear in RFPs, the rule’s forthcoming is inevitable and the preparation for this assessment can be intricate and time-consuming. In order to be as proactive as possible, conducting an objective Gap Assessment is an important first step towards assessment to be as confident as possible going into the CMMC 2.0 assessment by a certified C3PAO. By calling Elevate, you can make the process of becoming compliant much less painful. Our Elevate professionals will prepare your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice.
Is your Financial Institution aware of the FTC’s Final Rule Implemented in January 2022?

In October of last year, in an effort to strengthen data security measures, the Federal Trade Commission (“FTC”) announced that there were plans to implement important updates in an effort to rejuvenate and modernize what is known as the Standards for Safeguarding Customer Information (‘‘Safeguards Rule’’). The Safeguards Rule provides a guideline for businesses to have information security processes in practice to prevent consumer harm and promote good business practices and healthy competition in the marketplace. This anticipated change was initiated and implemented due to the dramatically increased infiltration of virtual networks in so many aspects of everyday business and personal life, demanding increased security in the realm of information security. This, along with a drastic uptick in data breach incidents and large-scale cybersecurity threats and attacks, spurred the FTC to announce these imminent changes. As a result, effective January 10, 2022, the FTC issued a final rule (‘‘Final Rule’’) to amend the Standards for Safeguarding Customer Information (‘‘Safeguards Rule’’). The recent changes were published in early December 2021 by the FTC and passed with a 3-2 vote. Overall, the Final Rule maintains the roadmap originally outlined in the 2019 adaption of the same with notable amendments and clarifications as summarized below. The Final Rule guidelines contain five main modifications from the existing Rule. Provides more detailed guidance on how to develop and implement specific aspects of an overall information security program, including access controls, authentication, and encryption. Risk Assessment requirements are clarified as well as employee training criteria. Second, it adds provisions designed to improve the accountability of financial institutions’ information security programs, such as by requiring periodic reports to boards of directors or governing bodies to increase awareness and involvement of senior management roles. It exempts financial institutions that collect data from 5.000 customers or less from certain requirements. It expands the definition of ‘‘financial institution’’ to include entities engaged in activities the Federal Reserve Board determines to be incidental to financial activities. This change adds ‘‘finders’’— companies that bring together buyers and sellers of a product or service within the scope of the Rule. Defines several terms and provides related examples in the Rule itself to provide an ease of reference, rather than invoke the need to the separate Privacy of Consumer Financial Information Rule (‘‘Privacy Rule’’). As the Final Rule was implemented on January 10, 2022, now is the time to take action – your qualifying financial institution should ensure your organization has a satisfactorily documented consumer information security process in place. This is where Elevate can help! We can do the legwork for you. Elevate is already familiar with GBLA and the Safeguard and Final Rules, and can assist in evaluating your company’s current information security system, perform a Risk Assessment, then advise on areas that need improvement, and provide a plan of action.
CMMC 2.0 Update – What Do These Changes Mean for Your Organization?

CMMC 2.0 Update Three major changes were announced for CMMC: fewer security tiers, new level definitions and requirements, and allowance for “Plan of Action & Milestone” reports. Learn more about the DoD’s major changes to the CMMC program. Like everyone else in the world of federal compliance, we’ve been closely tracking the Cybersecurity Maturity Model Certification (CMMC) since the U.S. Department of Defense (DoD) shared its initial draft of the model in early 2020. The controversial certification program has simultaneously been praised for its potential to raise cybersecurity standards for DoD contractors and criticized for the cost to comply, which is seen as a burden for many small businesses that are executing federal contracts. Pairing Down the Scope The initial CMMC draft established five tiers of cybersecurity requirements for contractors. The tier with which a contractor needs to comply is based on the types of data they work with to execute federal contracts. With the CMMC 2.0 update there are now only three security tiers designed to simplify the program requirements: The CMMC 2.0 Update Removes Some Third-Party Assessment Requirements Under the new model, Level 1 contractors will no longer be required to get a third-party certification. Instead, they will follow a self-assessment protocol that can significantly reduce compliance costs for many contractors. These self-assessments will require an annual affirmation by company leadership. CMMC 2.0 Level 2 assessment requirements have also been updated allowing for self-assessments in some cases, instead of the required independent assessments. Under CMMC 2.0, third-party assessments will only be required for companies “supporting the highest priority programs.” To ensure compliance and avoid any penalties, many of which are significant, it’s highly recommended you hire a third-party assessor to complete your CMMC certification. A third-party assessment will help to accelerate your revenue and market growth to differentiate your business by providing your customers with the assurance that you have the necessary controls in place. Minimizing Barriers to Pass Assessment The self-assessments are just one part of the changes implemented to remove assessment barriers for contractors. Another key piece is the decision to allow “Plans of Action & Milestones” (POA&Ms) reports in certain cases. With these reports, contractors can pass an assessment even if they do not currently meet every security control required — provided their report properly outlines a plan of action, and deadlines, to meet those controls in the future. We expect the DoD to further refine the POA&M requirements for CMMC 2.0. Expect to see DoD requirements for findings to be resolved within 180 days and guidance on what may constitute a “showstopper” preventing a CMMC Certification. What’s Next? Overall, the changes implemented significantly streamline the requirements to comply with CMMC and remove a lot of barriers to compliance for smaller contractors. At this time, it appears that CMMC pilots and contract requirements will be temporarily suspended until the DoD finalizes these CMMC 2.0 changes. For contractors who are waiting in the wings, the wait continues. We continue to advise that companies prepare for CMMC by staying up to date with changes and announcements from the DoD, researching options for assessment partners (if a third-party assessment is still relevant to your company), and seeking compliance with the existing NIST 800-171 framework to give your company a leg up on eventual CMMC compliance. On November 4, 2021, the DoD announced several updates and changes with the introduction of “CMMC 2.0,” which clarifies how CMMC will be implemented. Elevate can make the process of becoming compliant much less painful by preparing your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice. Contact us today and let Elevate take the heavy lifting out of CMMC! Read the complete article by Tony Bai: https://a-lign.com/articles/blog-cmmc-2-0-updates/
Is the CMMC Leaning Towards Self Certification for 2022?

In this article, we the progress toward CMMC Self Certification. That is the question that everyone is placing a major bet on. Unfortunately, the CMMC has not offered much information on when they will be releasing the CMMC Certified Professionals training classes required to become CMMC Certified Professionals and Certified Assessors. According to the CMMC frequently asked questions classes were supposed to be authorized in mid-to-late summer 2021. To date, only four authorized C3PAOs are currently announced on Marketplace, and we still are yet to see what a successful CMMC audit entails. The good news is that since no audits have been completed, no company is yet to fail the DIBCAC ML3 assessment. Nonetheless, progress is still being made (at minuscule levels). Currently, there are 67 C3PAO Candidates pending CMMC ML3 Assessment. Background checks are in process and there are 45 approved Licensed Training Providers. Meanwhile, the list of Registered Practitioners (RP) and respective Registered Provider Organization (RPO) continues to grow. All signs are showing commitment to the CMMC and we are advising our clients to continue to prepare for some level of certification come 2022. Whether you are currently in the assessment process or you are considering becoming certified next year, we advise you to be familiar and compliant with the established CMMC Ethics. Based on the September CMMC Town Hall over 9 discrete allegations of improper conduct/conflict-of-interest and ethics violations by CMMC-AB Board members were addressed. As you can imagine, the CMMC is taking this very seriously and will no doubt emphasize compliance with the Code of Ethics for all board members as well as applicants going forward. Underlying the spirit of the CMMC are baseline principles that establish the high standards of honesty and integrity required to operate within the CMMC Ecosystem. The CMMC has taken great care to construct its Code of Ethics, which is intended to provide a guideline for acceptable business practices. This is applicable and expected for all entities that facilitate cyber security services both domestic and internationally and includes all major regulatory agencies and all entities wishing to successfully bid on any DoD contract requiring CMMC. The CMMC Code of Ethics is amplified and supported by the CMMC Code of Conduct, which outlines specific requirements in the following areas: • Promotion of Good Practices• Professional Representation• CMMC-COE Assignments• Regulations• Competencies• Client Interests• Sanctions• Ethics• Responsible Reporting Additionally, it’s important to remember that at this time, the CMMC does not allow for self-attestation of compliance. As more C3PAOs join the marketplace, a larger number of companies will be working towards becoming certified in order to remain viable contractors and continue to participate in bidding on all government contracts. Ensure yours is one of the initial organizations to achieve the status of being CMMC certified, assuring less competition when bidding DoD contracts that require CMMC. Keep in mind that preparation for this assessment can be intricate and time-consuming. In order to take the first step towards assessment, it is prudent to candidly evaluate your organization’s current level of cybersecurity by conducting a Gap Assessment. Elevate can make the process of becoming compliant much less painful by preparing your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice. Contact us today and let Elevate take the heavy lifting out of CMMC!
Are you ready to Attest to the 12/31/21 Federal Reserve Bank’s Security Standard?

In this article, we discuss the New FedLine Standard. Starting December 31st, 2021, all institutions that use FedLine Advantage or FedLine Web are required to annually self-certify that their organization meets the Federal Reserve Bank’s security Standards. Depending on the environment and tools used, institutions may have to certify to over 50 controls. As with most modern security frameworks, the self-assessment is risk-based. However, at the discretion of the Federal Reserve Bank, independent validation by third parties or internal audit functions may be required. The requirements for the assurance program are outlined in the Federal Reserve Operating Circular No. 5. The program is focused on reducing the risk of fraudulent payments being sent through the systems. The scope of the program could extend not only to institutions but to potential service providers as well. The Federal Reserve Bank has followed in the footsteps of the SWIFT (Society for Worldwide Interbank Financial Telecommunication) CSCF and has announced the development and implementation of a Security & Resiliency Assurance Program (“Assurance Program”). The assurance program is a collection of controls that stem from both the FedLine Advantage Security and Control Procedures and the FedLine Web Security and Control Procedures. Institutions can access these documents via the EUAC Center in FedLine Home. The self-assessment consists of the following steps: Click here for an overview of how to self-certify to the FedLine Solutions Security and Resiliency Assurance Program. Need help in determining your institution’s scope and assessment of compliance with the Assurance Program? We Can Help! Our teams of IT Security and IT Compliance advisors can work with you to assess your internal environment, determine the scope of controls applicable to your institution, based on your risks, and perform a comprehensive review and validation of your controls’ in accordance with the Fedline SRAP guidelines. Call us for more information to get your organization started on the way to compliance with the Federal Reserve Banks.