Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.5.2.2

POA&M Components/Submission Format

activein force · 2026-08-25 – presentas-observed

The CFACTS shall be populated and maintained with security and privacy related findings and

action plans from any audit or review, whether internal or external. Corrective actions are to be

established in the CFACTS to address all resulting weaknesses entered therein, and those corrective

actions shall be maintained current in the CFACTS to support reporting requirements. In addition to

the initial POA&M reporting that follows each audit/review, ongoing milestones for all corrective

action plans will be updated on the 1st business day of each month.

Initial Reporting. Within 30 calendar days (or as otherwise directed by CMS) of the final results

for every internal/external audit/review, an initial POA&M is due to CMS that describes the

findings of the audit/review and initial corrective actions planned for implementation.

Monthly Reporting. On a monthly basis, business partners shall provide updates in the CFACTS

on progress towards completion of remediation efforts for weaknesses identified from all known

sources. Milestones that have a status of Completed or Not Started do not need to be updated

monthly.

Delayed Resolution. If the contractor needs additional time to complete a POA&M beyond 90

days, then the following process should be followed:

• A milestone describing the mitigating/compensating controls in place shall be documented

in CFACTS.

• For audits or evaluations that are initiated by CMS, the contractor shall email the

DMSSOO and the appropriate COR(s) to request approval to extend the completion

date. Included with the request, the contractor shall document the circumstances

surrounding the extension and the new estimated completion date. The DMSSOO will

respond documenting whether the extension is granted.

• For all other internal audits or evaluations conducted by the contractor, the contractor

shall notify DMSSOO and the appropriate COR(s) via email the need and reason to extend

the scheduled completion date along with the new scheduled completion date. The

DMSSOO will respond documenting the acknowledgement.

History

(Rev. 11, Issued: 09-30-11, Effective: 10-31-11, Implementation: 10-31-11)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
d7bd09bd3740ed36a150352954029c6bc8b541cc08c763d4fa7c07e945b282cc
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.