Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.12

End of Life Technology Components

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

The current HHS policy states “Operating systems, software and applications are considered end-of-life (EOL) when they are no longer supported by the vendor/provider and do not receive product

updates and security patches.” Standard HHS contract language requires that vendor software needs

“to be within one major version of the current version”. To address both the HHS policy and the

HHS contract language, and to document how the business partner has implemented the EOL

control, business partners need to implement MAC ARS control SA-22, which restricts the use of

unsupported information system components. For business partners, components are defined as any

hardware or software used by the FISMA system.

While paying for extended support to receive security updates for all levels of severity (with a

component vendor or a third-party vendor) is acceptable for meeting the HHS policy regarding

EOL, business partners are expected to plan for and remove components that the vendor plans to, or

currently no longer supplies security updates. If vendors can only provide updates or fixes for

certain levels of security flaws (e.g. critical only), this could leave security threats and risks present

in the environment and would not be acceptable for meeting the HHS policy regarding EOL.

Business partners shall demonstrate their efforts to remove these components, with documentation

that can include, but is not limited to, vendor notifications, project plans and identified issues. If

the components cannot be removed before security updates end because the vendor provided

limited notice or because removal requires a long-term project, then the business partner shall work

with CMS to implement controls to mitigate risk to an acceptable level until the component can be

replaced. If the risk cannot be sufficiently reduced, the business partner shall work with CMS to

open a POA&M, if necessary, prior to the end of support. In addition, business partners are

required to be on either the current or the one prior major version of the component. For those

situations where the business partner wants to use previous versions, and the component is

supported by the vendor, then the business partner shall perform a risk analysis and document the

results in the ISRA.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
326fc66de363f8104a20d169338018e5fa859dc643543c4a3b44af0921d64244
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.