CISA published new FY2026 FISMA metrics documents — the FY2026 CIO FISMA Metrics and FY 2026 SAOP FISMA Metrics — which set the annual reporting requirements for federal agencies. Previous versions of this page only ran through FY2025.
VIEW SOURCE ↗← ALL FRAMEWORKS
FISMA
Government SecurityIssued by CISA
FISMA, in its current form the Federal Information Security Modernization Act of 2014, requires US federal agencies to develop, document, and implement agency-wide information security programs based on NIST standards, including the risk categorization in FIPS 199 and control baselines in NIST SP 800-53. OMB holds oversight authority, while CISA provides operational guidance. Compliance is assessed annually. Federal agencies and any contractor operating an information system on an agency's behalf fall under FISMA, typically demonstrating compliance through a NIST Risk Management Framework authorization package.
Get notified the moment FISMA actually changes — reviewed by a human before it ever reaches you.
Get started freeMost recent update
major