The Signal
Three developments from September 21–27 will reach delivery teams before they reach most roadmaps.
1. CMS wants Medicaid quality measured by outcomes, in near-real time. On September 25, CMS launched Investing in Health Outcomes, a voluntary pledge signed by 37 states covering about 56 million Medicaid and CHIP beneficiaries. States commit to outcome-focused measures, slimmer measure inventories, digital quality measurement with near-real-time data where possible, and payment tied to outcomes. They will apply these principles to their quality strategies and upcoming procurements.
2. FIPS 140-2 is now historical. September 21 was the last day FIPS 140-2 certificates sat on NIST's active list. They are now on the CMVP Historical List: still usable in existing systems, but no longer acceptable for new federal systems. Only FIPS 140-3 validations count for new work.
3. Attackers went after identity and edge infrastructure. CISA added nine actively exploited vulnerabilities to its KEV catalog in one week. The list includes F5 BIG-IP APM (exploited as a zero-day when APM acts as an OAuth authorization server), WSO2 API Manager and gateways (an authentication bypass in JWT handling, per WSO2's advisory), on-premises SharePoint, Check Point gateways, Arista VeloCloud Orchestrator, MikroTik RouterOS, Zyxel switches, and Adobe Commerce. Federal agencies got as little as three days to remediate under BOD 26-04.
Why It Matters
None of these looks like a delivery story in the headline. Each one becomes delivery work.
Near-real-time measurement is an integration program, not a dashboard. Moving from retrospective claims and chart abstraction to live measurement means reliable clinical and claims feeds, patient and provider identity matching, agreed measure definitions, and auditable calculation logic. CMS found about 450 reporting requirements covering roughly 260 distinct measures across 42 states' managed care programs. Consolidating that is data engineering, interface work, and governance, all at once. And because states will carry these principles into procurements, vendors may soon be evaluated on data latency and outcome attribution, not just report production.
"Existing system" just became a question with schedule consequences. A historical FIPS 140-2 module can stay in a system that is already running. The moment a change counts as a new system or a material replacement, it needs a FIPS 140-3 module. That decision touches VPNs, HSMs, identity platforms, databases, cloud services, and integration gateways. If nobody owns the call, it surfaces at authorization time, when it is most expensive.
The exploited systems sit on the trust boundary. F5 APM, WSO2, SharePoint, and network gateways mediate who and what can reach regulated data. When they are hit, the fix is rarely just a patch: BOD 26-04 expects compromise triage too. That work competes directly with planned sprint capacity. BOD 26-04 binds only federal civilian agencies, but its exposure-plus-exploitation model is a sound benchmark for healthcare, defense, and financial programs.
Delivery Impact
The same three signals land differently depending on who is accountable for the work.
| Audience | Medicaid outcome measurement | FIPS 140-3 transition | Exploited identity and edge systems |
|---|---|---|---|
| Project and Scrum leaders | Deliver each measure as one end-to-end slice, source to validated result, not split across data, interface, and reporting backlogs. | Make the CMVP certificate number, module version, and operating environment part of the definition of done. | Run an expedite lane that tracks exposure, fix, compromise review, testing, and closure evidence. |
| Program and portfolio leaders | Expect new dependencies on identity resolution, terminology, and data-quality controls across teams. | Get a written ruling on what counts as a new system versus a modification before design freezes. | Rank shared gateways and identity platforms by downstream blast radius, not owning team's backlog. |
| Executives | Measurement capability may become a procurement differentiator. Fund the data foundation, not just the reporting layer. | Legacy crypto in a "new" system is now an authorization and contract risk. | Emergency security work consumes real capacity. Show its forecast impact instead of absorbing it silently. |
My Take
The common thread this week is that compliance keeps arriving as work without arriving as capacity. A pledge, a certificate status change, and a KEV entry each look small on their own. Each one quietly adds acceptance criteria, dependencies, or unplanned sprints to teams that were already fully committed. The programs that handle this well will be the ones that make the work visible: on the board, in the forecast, and in front of the people who own the trade-offs.
Look closer and identity sits at the center of all three. Outcome measurement only works if patients and providers are matched correctly across systems. The FIPS 140-3 question lands hardest on identity platforms, HSMs, and token-signing services. And this week's most dangerous exploits hit an OAuth authorization server and an API identity gateway. For delivery leaders, IAM is no longer a security team's backlog item. It is a shared dependency that every regulated program should map, staff, and schedule explicitly.
Watch Next
- The CMMC Reform Task Force report. DoW suspended CMMC Phase II on July 13 and gave a task force 60 days to review the program. That window closed around September 11, and as of September 28 I could not find a published report or restart date. Until it lands, Phase I self-assessments, SPRS scores, and DFARS 252.204-7012 obligations stay in force. Suspended is not repealed.
- The first state procurements under the Medicaid pledge. Watch for RFPs that score vendors on data latency, digital measurement, or outcome attribution. That will show whether the pledge changes buying behavior or stays a statement of intent.
Sources
- CMS Refocuses Medicaid Quality on Health Outcomes, Launches Innovative Partnership With 37 States — CMS, Sept. 25, 2026
- Investing in Health Outcomes — Medicaid.gov
- Cryptographic Module Validation Program — NIST CSRC
- FIPS 140-3 Transition Effort — NIST CSRC
- Department of War Suspends CMMC Phase II Requirements — U.S. Department of War, July 13, 2026
- CISA Adds Four Known Exploited Vulnerabilities to Catalog, Sept. 22 — CISA (Check Point, Arista, F5)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog, Sept. 24 — CISA (WSO2, Adobe)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog, Sept. 25 — CISA (SharePoint, MikroTik)
- K000162605: BIG-IP APM vulnerability CVE-2026-94127 — F5 security advisory
- WSO2-2026-5328 / CVE-2026-5430 — WSO2 security advisory
