US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.5.2
Plan of Action and Milestones (POA&M)
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Business partners are required to prepare a monthly POA&M update which is due by the
1st of each month. The POA&M update consists of updating all active POA&Ms in the
CFACTS and, if required by CMS, uploading any additional supporting documentation.
All security and privacy related findings shall be entered into CFACTS. Security and
privacy findings include findings from Section 912, FISMA, CFO, security control
assessments, penetration tests, Statement on Standards for Attestation Engagement No.
18 (SSAE-18) and all other reviews and audits.
3.5.2.1 - Background
FISMA requires that federal agencies provide annual reporting of the state of security programs for
all IT systems associated with the agency. Additionally, periodic POA&Ms reporting the status of
known security weaknesses for all federal agency systems are also submitted to the OMB. This
reporting requirement applies to a broader scope of security weaknesses, as it is not limited to
weaknesses identified by specific audits and reviews (such as those covered under FMFIA). In the
case of FISMA, any security weakness identified for any covered system shall be recorded in
CFACTS.
Section 912 of the MMA implemented requirements for annual evaluation, testing, and reporting on
security programs for MAC business partners (to include their respective data centers). These
Section 912 evaluations and reports necessitate an annual on-site review of business partner
security programs to ensure that they meet the information security requirements imposed by
FISMA and CMS. CMS, as part of its overall FISMA reporting obligations, requires that corrective
actions for identified deficiencies (i.e., weaknesses) be addressed in a report to be submitted shortly
after the evaluation results are finalized, as well as periodically thereafter to track updated progress
towards completion of the identified action plans.
CFACTS enables contractors to satisfy reporting requirements for security and privacy related
findings. Security and privacy related findings and approved action plan data is promptly entered
into the CFACTS following all audits/reviews.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
3052c355828705d11308479e4150a3afe563e5a7a8364f278856a6e25700b57e
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.