Regulated IT Delivery Brief logoRegulated IT Delivery Brief

Edition

Issue #1: Compliance Is Arriving as Work, Not Capacity

5 min read

The Signal

Three developments from September 21–27 will reach delivery teams before they reach most roadmaps.

1. CMS wants Medicaid quality measured by outcomes, in near-real time. On September 25, CMS launched Investing in Health Outcomes, a voluntary pledge signed by 37 states covering about 56 million Medicaid and CHIP beneficiaries. States commit to outcome-focused measures, slimmer measure inventories, digital quality measurement with near-real-time data where possible, and payment tied to outcomes. They will apply these principles to their quality strategies and upcoming procurements.

2. FIPS 140-2 is now historical. September 21 was the last day FIPS 140-2 certificates sat on NIST's active list. They are now on the CMVP Historical List: still usable in existing systems, but no longer acceptable for new federal systems. Only FIPS 140-3 validations count for new work.

3. Attackers went after identity and edge infrastructure. CISA added nine actively exploited vulnerabilities to its KEV catalog in one week. The list includes F5 BIG-IP APM (exploited as a zero-day when APM acts as an OAuth authorization server), WSO2 API Manager and gateways (an authentication bypass in JWT handling, per WSO2's advisory), on-premises SharePoint, Check Point gateways, Arista VeloCloud Orchestrator, MikroTik RouterOS, Zyxel switches, and Adobe Commerce. Federal agencies got as little as three days to remediate under BOD 26-04.

Why It Matters

None of these looks like a delivery story in the headline. Each one becomes delivery work.

Near-real-time measurement is an integration program, not a dashboard. Moving from retrospective claims and chart abstraction to live measurement means reliable clinical and claims feeds, patient and provider identity matching, agreed measure definitions, and auditable calculation logic. CMS found about 450 reporting requirements covering roughly 260 distinct measures across 42 states' managed care programs. Consolidating that is data engineering, interface work, and governance, all at once. And because states will carry these principles into procurements, vendors may soon be evaluated on data latency and outcome attribution, not just report production.

"Existing system" just became a question with schedule consequences. A historical FIPS 140-2 module can stay in a system that is already running. The moment a change counts as a new system or a material replacement, it needs a FIPS 140-3 module. That decision touches VPNs, HSMs, identity platforms, databases, cloud services, and integration gateways. If nobody owns the call, it surfaces at authorization time, when it is most expensive.

The exploited systems sit on the trust boundary. F5 APM, WSO2, SharePoint, and network gateways mediate who and what can reach regulated data. When they are hit, the fix is rarely just a patch: BOD 26-04 expects compromise triage too. That work competes directly with planned sprint capacity. BOD 26-04 binds only federal civilian agencies, but its exposure-plus-exploitation model is a sound benchmark for healthcare, defense, and financial programs.

Delivery Impact

The same three signals land differently depending on who is accountable for the work.

AudienceMedicaid outcome measurementFIPS 140-3 transitionExploited identity and edge systems
Project and Scrum leadersDeliver each measure as one end-to-end slice, source to validated result, not split across data, interface, and reporting backlogs.Make the CMVP certificate number, module version, and operating environment part of the definition of done.Run an expedite lane that tracks exposure, fix, compromise review, testing, and closure evidence.
Program and portfolio leadersExpect new dependencies on identity resolution, terminology, and data-quality controls across teams.Get a written ruling on what counts as a new system versus a modification before design freezes.Rank shared gateways and identity platforms by downstream blast radius, not owning team's backlog.
ExecutivesMeasurement capability may become a procurement differentiator. Fund the data foundation, not just the reporting layer.Legacy crypto in a "new" system is now an authorization and contract risk.Emergency security work consumes real capacity. Show its forecast impact instead of absorbing it silently.

My Take

The common thread this week is that compliance keeps arriving as work without arriving as capacity. A pledge, a certificate status change, and a KEV entry each look small on their own. Each one quietly adds acceptance criteria, dependencies, or unplanned sprints to teams that were already fully committed. The programs that handle this well will be the ones that make the work visible: on the board, in the forecast, and in front of the people who own the trade-offs.

Look closer and identity sits at the center of all three. Outcome measurement only works if patients and providers are matched correctly across systems. The FIPS 140-3 question lands hardest on identity platforms, HSMs, and token-signing services. And this week's most dangerous exploits hit an OAuth authorization server and an API identity gateway. For delivery leaders, IAM is no longer a security team's backlog item. It is a shared dependency that every regulated program should map, staff, and schedule explicitly.

Watch Next

  • The CMMC Reform Task Force report. DoW suspended CMMC Phase II on July 13 and gave a task force 60 days to review the program. That window closed around September 11, and as of September 28 I could not find a published report or restart date. Until it lands, Phase I self-assessments, SPRS scores, and DFARS 252.204-7012 obligations stay in force. Suspended is not repealed.
  • The first state procurements under the Medicaid pledge. Watch for RFPs that score vendors on data latency, digital measurement, or outcome attribution. That will show whether the pledge changes buying behavior or stays a statement of intent.

Sources