Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.5.2

Plan of Action and Milestones (POA&M)

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

Business partners are required to prepare a monthly POA&M update which is due by the

1st of each month. The POA&M update consists of updating all active POA&Ms in the

CFACTS and, if required by CMS, uploading any additional supporting documentation.

All security and privacy related findings shall be entered into CFACTS. Security and

privacy findings include findings from Section 912, FISMA, CFO, security control

assessments, penetration tests, Statement on Standards for Attestation Engagement No.

18 (SSAE-18) and all other reviews and audits.

3.5.2.1 - Background

FISMA requires that federal agencies provide annual reporting of the state of security programs for

all IT systems associated with the agency. Additionally, periodic POA&Ms reporting the status of

known security weaknesses for all federal agency systems are also submitted to the OMB. This

reporting requirement applies to a broader scope of security weaknesses, as it is not limited to

weaknesses identified by specific audits and reviews (such as those covered under FMFIA). In the

case of FISMA, any security weakness identified for any covered system shall be recorded in

CFACTS.

Section 912 of the MMA implemented requirements for annual evaluation, testing, and reporting on

security programs for MAC business partners (to include their respective data centers). These

Section 912 evaluations and reports necessitate an annual on-site review of business partner

security programs to ensure that they meet the information security requirements imposed by

FISMA and CMS. CMS, as part of its overall FISMA reporting obligations, requires that corrective

actions for identified deficiencies (i.e., weaknesses) be addressed in a report to be submitted shortly

after the evaluation results are finalized, as well as periodically thereafter to track updated progress

towards completion of the identified action plans.

CFACTS enables contractors to satisfy reporting requirements for security and privacy related

findings. Security and privacy related findings and approved action plan data is promptly entered

into the CFACTS following all audits/reviews.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
3052c355828705d11308479e4150a3afe563e5a7a8364f278856a6e25700b57e
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.