US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.5.2.2
POA&M Components/Submission Format
The CFACTS shall be populated and maintained with security and privacy related findings and
action plans from any audit or review, whether internal or external. Corrective actions are to be
established in the CFACTS to address all resulting weaknesses entered therein, and those corrective
actions shall be maintained current in the CFACTS to support reporting requirements. In addition to
the initial POA&M reporting that follows each audit/review, ongoing milestones for all corrective
action plans will be updated on the 1st business day of each month.
Initial Reporting. Within 30 calendar days (or as otherwise directed by CMS) of the final results
for every internal/external audit/review, an initial POA&M is due to CMS that describes the
findings of the audit/review and initial corrective actions planned for implementation.
Monthly Reporting. On a monthly basis, business partners shall provide updates in the CFACTS
on progress towards completion of remediation efforts for weaknesses identified from all known
sources. Milestones that have a status of Completed or Not Started do not need to be updated
monthly.
Delayed Resolution. If the contractor needs additional time to complete a POA&M beyond 90
days, then the following process should be followed:
• A milestone describing the mitigating/compensating controls in place shall be documented
in CFACTS.
• For audits or evaluations that are initiated by CMS, the contractor shall email the
DMSSOO and the appropriate COR(s) to request approval to extend the completion
date. Included with the request, the contractor shall document the circumstances
surrounding the extension and the new estimated completion date. The DMSSOO will
respond documenting whether the extension is granted.
• For all other internal audits or evaluations conducted by the contractor, the contractor
shall notify DMSSOO and the appropriate COR(s) via email the need and reason to extend
the scheduled completion date along with the new scheduled completion date. The
DMSSOO will respond documenting the acknowledgement.
History
(Rev. 11, Issued: 09-30-11, Effective: 10-31-11, Implementation: 10-31-11)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
d7bd09bd3740ed36a150352954029c6bc8b541cc08c763d4fa7c07e945b282cc
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.