• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » FISMA

FISMA

Definition

FISMA

FISMA is the United States law requiring federal agencies to run information security programmes for the systems they depend on. Its reach extends to contractors through the contract, which is how outsourced operations end up inside a federal security regime.

The law does not address contractors directly — it addresses agencies.

Agencies then pass the obligations down in the contracts they sign, which is why a commercial provider with federal clients finds itself operating to federal security requirements it never negotiated with the government.

That indirect route matters, because it means the source of your obligation is a clause rather than a statute.

Key takeaways

  • FISMA is the Federal Information Security Modernization Act of 2014, amending the 2002 original.
  • It applies directly to federal Executive Branch civilian agencies.
  • Contractors inherit requirements through contract terms rather than by direct statutory reach.
  • Agencies must report major incidents and breaches to Congress.

How it works

The current statute is the Federal Information Security Modernization Act of 2014 (FISMA 2014), which amended the 2002 Act of a similar name. The Cybersecurity and Infrastructure Security Agency records that it applies to federal Executive Branch civilian agencies.

Reporting is one visible obligation. The law requires agencies to report major information security incidents as well as data breaches to Congress as they occur and annually.

Implementation runs through NIST. The control requirements agencies apply come from the federal catalogue of Security and Privacy Controls for Information Systems and Organizations, which is where the operational detail lives.

The contractor position follows from how agencies discharge these duties. An agency responsible for the security of a system cannot ignore that the system is run by a supplier, so the requirements appear in the contract.

For a provider, this produces a familiar pattern — obligations arrive as flow-down clauses, referencing federal publications, with an agency rather than a regulator as the enforcing party.

PartyHow FISMA reaches them
Federal civilian agencyDirectly, as the addressee of the statute
Prime contractorThrough contract clauses imposed by the agency
SubcontractorThrough flow-down from the prime
Cloud providerOften through FedRAMP, which operationalises the baselines
Commercial buyerNot at all, unless it chooses to adopt the standards

The bottom row is worth stating plainly — a commercial organisation has no FISMA obligation, whatever a vendor’s marketing implies.

Examples

Federal security requirements reach commercial organisations in ways that surprise them, almost always through a contract rather than a regulator. What follows are engagements where the compliance question shaped the commercial one.

A BPO provider wins an agency contract and inherits security requirements written for federal systems. Its government outsourcing practice has to operate to a different standard than its commercial one.

A subcontractor receives flow-down clauses referencing federal publications it has never read. The obligation is contractual and enforceable regardless.

An agency moving to cloud relies on FedRAMP to satisfy its own obligations. The programme exists partly to make this route workable.

A commercial firm is told it must be FISMA compliant by a vendor. No such obligation exists outside federal contracting, and compliance outsourcing teams should push back on the claim.

Related terms

Federal security obligations, the programmes implementing them and the general services around security are distinct layers. Each definition here is short by design, since breadth is what creates the confusion.

FAQ

What does FISMA stand for?

The Federal Information Security Modernization Act of 2014, which amended the Federal Information Security Management Act of 2002.

Does FISMA apply to contractors?

Not directly. It applies to federal agencies, which impose corresponding requirements on contractors through contract terms.

Can a commercial company be FISMA compliant?

Not in any formal sense. A commercial organisation can adopt the same NIST controls, but there is no compliance status to hold outside federal contracting.

How does FISMA relate to FedRAMP?

FedRAMP operationalises cloud security assessment in a way that helps agencies meet their FISMA obligations. It is a programme, not a separate law.

What reporting does it require?

Agencies must report major information security incidents and data breaches to Congress as they occur and on an annual basis.

Where do the controls come from?

From the NIST catalogue of security and privacy controls, which supplies the baselines agencies apply to their systems.

Begin at Outsource Accelerator and trace the obligation from the agency down to the contract.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image