GRCCopilot
Sign In
U.S. Congress / Office of Management and Budget (OMB) / NIST

FISMA Compliance Assessment

U.S. federal law mandating information security programs for all federal agencies and their contractors

Start Assessment Create Free Account
13
Controls
39
Questions
Active
Status
May 2029
Expires

About this Framework

The Federal Information Security Modernization Act (FISMA) requires U.S. federal agencies to develop, document and implement agency-wide information security programs. Implemented through NIST 800-series publications and OMB directives, FISMA mandates risk categorisation (FIPS 199), security control selection (NIST 800-53), annual assessments, system authorisations (ATO) and continuous monitoring. Non-compliance can result in reduced appropriations and heightened oversight by inspectors general and Congress.

Key Control Domains

System Categorisation (FIPS 199)
Security Control Selection (NIST 800-53)
Security Assessment & Authorisation (ATO)
Continuous Monitoring (ISCM)
POA&M Management
Incident Reporting (CISA/US-CERT)
Contingency Planning
Privacy Compliance (OMB A-130)

Who Needs This?

  • All U.S. federal executive branch agencies
  • Federal IT contractors and managed service providers
  • Grant recipients and state agencies using federal systems
  • Universities conducting federally funded research with federal information systems

Compliance Benefits

  • Legal compliance with U.S. federal information security law
  • Foundation for FedRAMP cloud authorisation pathway
  • Systematic risk management across federal information systems
  • Required for federal contracts involving government information systems

Official Reference

FISMA Guidance — CISA
https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act

Assessment Details

Issuer / AuthorityU.S. Congress / Office of Management and Budget (OMB) / NIST
FrameworkFISMA Compliance Assessment
Controls13
Questions39
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2029

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/fisma-compliance-assessment

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.