FISMA
Definition
FISMA
FISMA is the United States law requiring federal agencies to run information security programmes for the systems they depend on. Its reach extends to contractors through the contract, which is how outsourced operations end up inside a federal security regime.
The law does not address contractors directly — it addresses agencies.
Agencies then pass the obligations down in the contracts they sign, which is why a commercial provider with federal clients finds itself operating to federal security requirements it never negotiated with the government.
That indirect route matters, because it means the source of your obligation is a clause rather than a statute.
Key takeaways
- FISMA is the Federal Information Security Modernization Act of 2014, amending the 2002 original.
- It applies directly to federal Executive Branch civilian agencies.
- Contractors inherit requirements through contract terms rather than by direct statutory reach.
- Agencies must report major incidents and breaches to Congress.
How it works
The current statute is the Federal Information Security Modernization Act of 2014 (FISMA 2014), which amended the 2002 Act of a similar name. The Cybersecurity and Infrastructure Security Agency records that it applies to federal Executive Branch civilian agencies.
Reporting is one visible obligation. The law requires agencies to report major information security incidents as well as data breaches to Congress as they occur and annually.
Implementation runs through NIST. The control requirements agencies apply come from the federal catalogue of Security and Privacy Controls for Information Systems and Organizations, which is where the operational detail lives.
The contractor position follows from how agencies discharge these duties. An agency responsible for the security of a system cannot ignore that the system is run by a supplier, so the requirements appear in the contract.
For a provider, this produces a familiar pattern — obligations arrive as flow-down clauses, referencing federal publications, with an agency rather than a regulator as the enforcing party.
| Party | How FISMA reaches them |
|---|---|
| Federal civilian agency | Directly, as the addressee of the statute |
| Prime contractor | Through contract clauses imposed by the agency |
| Subcontractor | Through flow-down from the prime |
| Cloud provider | Often through FedRAMP, which operationalises the baselines |
| Commercial buyer | Not at all, unless it chooses to adopt the standards |
The bottom row is worth stating plainly — a commercial organisation has no FISMA obligation, whatever a vendor’s marketing implies.
Examples
Federal security requirements reach commercial organisations in ways that surprise them, almost always through a contract rather than a regulator. What follows are engagements where the compliance question shaped the commercial one.
A BPO provider wins an agency contract and inherits security requirements written for federal systems. Its government outsourcing practice has to operate to a different standard than its commercial one.
A subcontractor receives flow-down clauses referencing federal publications it has never read. The obligation is contractual and enforceable regardless.
An agency moving to cloud relies on FedRAMP to satisfy its own obligations. The programme exists partly to make this route workable.
A commercial firm is told it must be FISMA compliant by a vendor. No such obligation exists outside federal contracting, and compliance outsourcing teams should push back on the claim.
Related terms
Federal security obligations, the programmes implementing them and the general services around security are distinct layers. Each definition here is short by design, since breadth is what creates the confusion.
- Government outsourcing: public sector contracting, the route by which these obligations travel.
- Cybersecurity outsourcing: buying security capability, which is how many providers meet the requirements.
- Compliance outsourcing: delegating regulatory work, which cannot remove a contractual obligation.
- Information security analyst: the role operating the controls the catalogue specifies.
- Data center outsourcing: the hosting arrangement agencies must account for.
- Security operations outsourcing: delegating monitoring, relevant to the incident reporting duty.
- Risk outsourcing: transferring exposure commercially, which statutory duties resist.
FAQ
What does FISMA stand for?
The Federal Information Security Modernization Act of 2014, which amended the Federal Information Security Management Act of 2002.
Does FISMA apply to contractors?
Not directly. It applies to federal agencies, which impose corresponding requirements on contractors through contract terms.
Can a commercial company be FISMA compliant?
Not in any formal sense. A commercial organisation can adopt the same NIST controls, but there is no compliance status to hold outside federal contracting.
How does FISMA relate to FedRAMP?
FedRAMP operationalises cloud security assessment in a way that helps agencies meet their FISMA obligations. It is a programme, not a separate law.
What reporting does it require?
Agencies must report major information security incidents and data breaches to Congress as they occur and on an annual basis.
Where do the controls come from?
From the NIST catalogue of security and privacy controls, which supplies the baselines agencies apply to their systems.
Begin at Outsource Accelerator and trace the obligation from the agency down to the contract.







Independent




