Presentation Center

Wipro Health Plan Services · MarketLink

CMS EDE production requirements

The CMS production-entry standard, the MarketLink capability that addresses it, and the evidence required for authorization.

Production entry is a governed decision. Implemented capability + production-like execution + independent audit evidence + CMS review.
01

Identity & MFA

Control foundation
CMS production-entry requirement

Consumer remote identity proofing through RIDP-RBA/GetRecord or documented NIST IAL2/AAL2 service; agent/broker IDM-Okta identity proofing and separate MFA.

MarketLink capability

Role-aware consumer and broker access gates, TOTP with protected backup codes, session controls, and IDM-Okta/RIDP integration services.

Implementation reference: identity, session, and multi-factor authentication services
Evidence required

Consumer and broker pathway recordings; successful identity transaction records; MFA challenge evidence; IAL2/AAL2 provider documentation where applicable.

02

CMS Hub trust & transport

Secure integration
CMS production-entry requirement

Assigned Partner credentials, OAuth2 client credentials where specified, mTLS certificates, CMS request headers, approved scopes, and unique interaction identifiers.

MarketLink capability

Certificate-backed Hub client, OAuth token lifecycle, Exchange User and Consumer User headers, correlation IDs, resilient calls, and raw evidence capture.

Implementation reference: CMS Hub connectivity and validation services
Evidence required

Certificate inventory and expiry controls; successful connectivity results; correlation-linked, unmodified request and response headers and bodies.

03

Required 22-API suite

Complete module surface
CMS production-entry requirement

A primary EDE entity implements the full required API suite regardless of phase and demonstrates functional use in a production-like environment.

MarketLink capability · 22 service modules
Store ID Proofing Person Search Create App Create App from Prior Year App Store Permission Revoke Permission Get App Add Member Remove Member Update App Submit App Get DMI Get SVI Metadata Search Notice Retrieval Submit Enrollment Document Upload System and State Reference Data Get Enrollment Payment Redirect Update Policy Events Based Processing
Implementation reference: CMS Hub service inventory
Evidence required

FIT execution for consumer and agent/broker pathways, with complete UI evidence and raw, unmodified headers and bodies mapped to each case and step.

04

Broker NPN, NIPR & RCL

Access assurance
CMS production-entry requirement

Validate NPN and state licensing through NIPR before access; confirm current Marketplace registration and training through the CMS Registration Completion List.

MarketLink capability

NIPR-first verification, CMS RCL validation, fail-closed outcomes, scheduled revalidation, audit events, and automatic access suspension controls.

Implementation reference: broker validation and revalidation services
Evidence required

Live licensing and RCL responses; valid, expired, and unavailable-service scenarios; access-denial and periodic revalidation records.

05

DMI, SVI, DSRS & documents

Document operations
CMS production-entry requirement

Display DMI/SVI status, support documentary evidence, submit through Document Upload, and retrieve Marketplace notices using DSRS metadata and document identifiers.

MarketLink capability

Document Capture / OCR · Implemented plus Document Upload, Metadata Search, Notice Retrieval, Get DMI, and Get SVI service modules.

Implementation reference: document capture and CMS Hub document services
Evidence required

DMI/SVI status scenarios; upload receipts and DSRS IDs; retrieved notice display; document-processing accuracy, exception handling, and end-to-end traceability.

06

Security, audit & evidence

Traceable control plane
CMS production-entry requirement

Protect PII, maintain unique user and API interaction records, retain required records for ten years, test controls, and maintain the CMS privacy/security package.

MarketLink capability

Correlation-linked evidence, tamper-evident SHA-256 audit chain, access and change events, retention workflows, security test controls, and reviewable evidence packaging.

Implementation reference: audit logging and evidence schema
Evidence required

Hash-chain verification; retention and retrieval samples; vulnerability and penetration-test results with retest closure; SSPP, SAR, POA&M, ISA, and control evidence.

07

Production-entry governance

Decision framework
CMS production-entry requirement

Complete independent business and privacy/security audits, execute the EDE agreements and ISA, demonstrate production-like parity, and receive CMS authorization before public use.

MarketLink capability

Requirement-to-backlog traceability, 13-case FIT packaging, evidence-vault controls, change disposition, review ownership, and release-gate structure.

Implementation reference: traceability matrix and current audit package
Evidence required

Independent audit reports; auditor disposition; complete FIT packages; production-equivalence record; agreements and CMS decision record; controlled change history.