US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.12
End of Life Technology Components
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
The current HHS policy states “Operating systems, software and applications are considered end-of-life (EOL) when they are no longer supported by the vendor/provider and do not receive product
updates and security patches.” Standard HHS contract language requires that vendor software needs
“to be within one major version of the current version”. To address both the HHS policy and the
HHS contract language, and to document how the business partner has implemented the EOL
control, business partners need to implement MAC ARS control SA-22, which restricts the use of
unsupported information system components. For business partners, components are defined as any
hardware or software used by the FISMA system.
While paying for extended support to receive security updates for all levels of severity (with a
component vendor or a third-party vendor) is acceptable for meeting the HHS policy regarding
EOL, business partners are expected to plan for and remove components that the vendor plans to, or
currently no longer supplies security updates. If vendors can only provide updates or fixes for
certain levels of security flaws (e.g. critical only), this could leave security threats and risks present
in the environment and would not be acceptable for meeting the HHS policy regarding EOL.
Business partners shall demonstrate their efforts to remove these components, with documentation
that can include, but is not limited to, vendor notifications, project plans and identified issues. If
the components cannot be removed before security updates end because the vendor provided
limited notice or because removal requires a long-term project, then the business partner shall work
with CMS to implement controls to mitigate risk to an acceptable level until the component can be
replaced. If the risk cannot be sufficiently reduced, the business partner shall work with CMS to
open a POA&M, if necessary, prior to the end of support. In addition, business partners are
required to be on either the current or the one prior major version of the component. For those
situations where the business partner wants to use previous versions, and the component is
supported by the vendor, then the business partner shall perform a risk analysis and document the
results in the ISRA.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
326fc66de363f8104a20d169338018e5fa859dc643543c4a3b44af0921d64244
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.