CMS SMC Evidence Automation: What State Medicaid Agencies Need to Know in 2026
- Vexdata

- 6 hours ago
- 10 min read

CMS deferred over $91 million in federal Medicaid funding from one state in 2026 — not because of fraud, and not because of intentional misreporting. Because when CMS requested the data to support the state's claims, the state could not provide it in time. The deferral calculation was based on "significant growth" in the state's claiming relative to other states. Without timely, verifiable data to respond, the state lost access to nearly $100 million in federal funding while the investigation proceeded.
This is the high-stakes reality of CMS Streamlined Modular Certification (SMC) in 2026. The evidence you submit to CMS is not a paperwork exercise — it is the data-backed proof that your Medicaid Enterprise Systems are performing as required, your outcomes are measurable and accurate, and your federal funding is justified. The quality of that evidence directly determines whether your certification proceeds on schedule, whether your funding is released, and whether your state avoids the kind of deferral that can cost tens or hundreds of millions of dollars.
This guide is written for state Medicaid agency IT directors, data leads, and health IT teams preparing for SMC submissions under CMS's 2026 requirements. It covers what SMC evidence automation means in practice, why manual evidence collection introduces unacceptable risk, and how automated data validation changes the certification process.
"CMS deferred $91M+ in federal Medicaid funding from a state in 2026 after it failed to provide timely data to support its claims." — KFF Federal Medicaid Policy Analysis, June 2026
What Is CMS SMC and Why Evidence Quality Matters More Than Ever
The CMS Streamlined Modular Certification (SMC) process replaced the Medicaid Enterprise Certification Toolkit (MECT) and the Medicaid Eligibility and Enrollment Toolkit (MEET) in April 2022. Introduced via State Medicaid Directors Letter SMDL #22-001, SMC was designed to modernise how CMS certifies state Medicaid Enterprise Systems — shifting from a checklist-based compliance model to an outcomes-based, metric-driven framework.
In August 2025, CMS issued State Health Official letter SHO #25-003, which incorporated Electronic Visit Verification (EVV) into the SMC framework and announced further process improvements. Then in December 2025, CMS mandated standardised MES templates — effective July 1, 2026 — covering every aspect of the MES lifecycle, from Advance Planning Documents (APDs) through operational reporting and certification submissions.
What this means for state agencies: every Medicaid IT module — MMIS, Eligibility & Enrollment, EVV, and all other MES components — is now subject to a unified certification process that emphasises measurable outcomes, metric data, and operational reporting over documentation checklists.
What the SMC Evidence Package Actually Contains
The evidence a state must submit for SMC certification is substantial. According to CMS guidance, a complete SMC submission includes:
Evidence Component | What It Requires | Data Quality Risk |
SMC Intake Form | Outcomes, metrics, and evidence artifacts for all MES modules including EVV | Metrics must be accurate and verifiable — incorrect figures can trigger CMS scrutiny |
MES Advance Planning Document (APD) | Measurable outcomes and metrics aligned to Medicaid program goals | APD milestones must match actual operational data — discrepancies delay funding approval |
Operational Report Workbook | Monthly project status against APD milestones | Manual compilation introduces errors that contradict other submitted evidence |
Privacy & Security Documentation | Evidence of compliance with federal security requirements | Incomplete or inconsistent data across submissions flags for additional review |
Outcome Achievement Evidence | Metric data proving outcomes were achieved | The most scrutinised component — inaccurate outcome data is the primary cause of certification delays |
Project Status Reports | Monthly updates confirming alignment with SMC guidelines | Must align with operational data — manual reporting creates version control and accuracy risks |
⚠ Effective July 1, 2026, all of these templates are mandatory for every state Medicaid IT project. States that have not yet transitioned to standardised SMC templates are operating under a compliance risk that increases with every passing month.
The Evidence Problem: Why Manual SMC Submission Is a Risk State Agencies Can No Longer Afford
Most state Medicaid agencies currently compile SMC evidence manually. A team of analysts pulls data from multiple systems — the MMIS, the eligibility platform, the EVV system, the data warehouse — formats it to meet CMS template requirements, reconciles discrepancies between systems, and submits the package to CMS. When CMS has questions, the state pulls more data, manually verifies it, and responds within the required window.
This process works — until it doesn't. And the consequences of it failing have grown materially in 2026.
Problem 1: Data Pulled from Multiple Disconnected Systems
State Medicaid data lives across dozens of systems: the MMIS processes claims, the eligibility and enrollment system manages beneficiary data, the EVV platform tracks home care visits, the data warehouse consolidates reporting, and each has its own data model, update cadence, and quality characteristics. When an analyst manually pulls outcome metrics from each system to compile an SMC evidence package, she is assuming that the data across these systems is consistent, current, and correct.
It frequently isn't. A beneficiary count pulled from the eligibility system may not match the count derived from claims data because of timing differences, duplicate records, or data model divergence. An EVV visit count may differ between the EVV platform and the data warehouse because of a lag in the nightly ETL job. These discrepancies are invisible in a manual process — they only surface when CMS compares figures across submissions and asks for an explanation.
Problem 2: No Audit Trail for Submitted Figures
When CMS receives an SMC evidence package and questions a specific metric, the state must be able to trace that number back to its source — which system it came from, what data was included or excluded, what transformation was applied to arrive at the figure, and when it was pulled. In a manual evidence compilation process, this traceability often does not exist. The analyst who compiled the figure may have documented the query, or may not. The results may have been pasted into a spreadsheet, or may not. The version submitted may be the first draft or the fifth revision.
Without an automated, logged process, states cannot produce the audit trail that CMS increasingly requires — particularly in the current environment where CMS is actively scrutinising claims growth and requesting supporting documentation under tighter timelines.
Problem 3: Inaccurate Outcome Metrics Delay Certification
SMC emphasises measurable outcomes. States must define specific metrics in their APDs — beneficiary outcomes, system performance indicators, program efficiency measures — and then provide evidence that those outcomes were achieved. If the evidence submitted shows outcomes that are inconsistent with the APD commitments, or if the metrics are calculated differently between the APD and the certification submission, CMS will request clarification.
Clarification requests delay certification. Certification delays mean enhanced federal funding — which requires certification — is not released. For states with significant Medicaid IT investments pending certification, the financial cost of a delayed submission due to avoidable data quality issues in the evidence package is substantial.
"CMS calculated a $501M deferral amount based on 'significant growth' in a state's claiming because the state did not timely provide the requested data." — KFF, June 2026
What CMS SMC Evidence Automation Actually Means
Evidence automation does not mean replacing human judgment in the certification process. CMS SMC is an outcomes-based framework — the qualitative assessments, the programmatic justifications, and the strategic alignment narratives require human expertise that no automation replaces.
What automation addresses is the data layer underneath the evidence — the extraction, validation, reconciliation, and documentation of the metric data that supports every claim in the
SMC submission. Specifically, evidence automation covers four components:
Component 1: Automated Data Extraction Across MES Systems
Rather than analysts manually querying each system to pull metric data, automated pipelines extract the relevant data from the MMIS, eligibility platform, EVV system, and data warehouse on a defined schedule. Each extraction is timestamped, logged, and associated with the specific metric it supports. The data is available on demand for any reporting period — not just the most recent pull.
Component 2: Cross-System Data Validation
Before any metric is compiled into an evidence package, automated validation confirms that the data is consistent across systems. Beneficiary counts in the eligibility system match beneficiary counts in claims data for the same period. EVV visit volumes in the EVV platform match the warehouse. Claims totals reconcile between the MMIS and the reporting layer. Discrepancies are flagged and must be resolved before the evidence package is assembled — not discovered by CMS after submission.
This is exactly what Vexdata's data validation platform provides — automated source-to-target comparison across all Medicaid data systems, with field-level reconciliation and a structured discrepancy report that the evidence team can investigate and resolve before submission. See vexdata.io/data-validation.
Component 3: Immutable Audit Trail
Every data extraction, every validation run, every reconciliation result, and every approved figure is logged with a timestamp and stored immutably. When CMS requests documentation supporting a specific metric — the beneficiary count on a specific date, the EVV visit volume for a specific quarter — the state can produce the complete data provenance in minutes rather than days: the source system, the extraction date, the validation result, and the approval record.
This audit trail is not just a convenience — it is the difference between a state that can respond to a CMS data request within the required window and a state that cannot. As the $91 million deferral demonstrates, the inability to provide timely, verifiable data in response to a CMS inquiry has direct and immediate financial consequences.
Component 4: Continuous Monitoring for Metric Integrity
Outcome metrics for SMC submissions are not static — they reflect system performance over time. Automated monitoring tracks the key metrics in APD commitments on an ongoing basis: beneficiary processing times, eligibility determination accuracy, EVV visit verification rates, system uptime, and claims processing volumes. When a metric deviates significantly from its expected trajectory — which might indicate a data quality issue, a system performance problem, or a pipeline failure — the monitoring system alerts the relevant team.
This allows states to identify and investigate potential evidence integrity issues months before the certification submission is due — rather than discovering discrepancies during CMS review. See Vexdata's Data Observability platform at vexdata.io/data-observability.
What Changes Under Mandatory SMC Templates — July 2026
The CMS-mandated standardised templates effective July 1, 2026 represent a significant operational change for state Medicaid agencies. According to CMS guidance, the templates are designed to expedite funding reviews, promote evaluation of alternative solutions, standardise reporting against APD milestones, and support a unified certification process across all MES modules.
For state IT and data teams, the practical implications are:
Standardised evidence format —
Evidence must now be submitted in CMS-specified templates. States can no longer use their own formats, which means any current manual processes built around custom formats must be rebuilt to conform to the new templates. This is the moment to automate the data layer — rebuilding the evidence collection process around the new templates is the ideal time to add validation and audit trail capabilities.
Unified certification for all MES modules —
MMIS, E&E, EVV, and all other MES components now go through the same SMC process. Evidence requirements are consistent across modules, which means states with multiple MES certifications in flight simultaneously need a systematic approach to evidence management — not a separate manual process for each module.
Metric-driven outcomes emphasis —
The SMC framework explicitly emphasises metric data and operational reporting over checklist compliance. States must demonstrate measurable outcomes, not just document activities. This raises the bar for evidence quality — the data behind the metrics must be verifiable, consistent, and defensible under CMS scrutiny.
Accelerated review expectations —
CMS's stated goal for the standardised templates is to expedite funding reviews. Accelerated review means faster identification of discrepancies — states with weak data foundations will face faster scrutiny, not slower.
Practical Steps for State Agencies Before July 2026
If your state is not yet using automated data validation and evidence management for SMC submissions, the following sequence addresses the most urgent gaps first:
Audit your current evidence sources. For each metric in your current or upcoming APD, document: which system is the source of record, how the data is currently extracted, whether the figure is reconciled against any other system, and what audit trail exists for each submission. This audit surfaces the highest-risk evidence gaps before CMS does.
Map your MES data flows. Identify every data pipeline that feeds your SMC metrics: MMIS to data warehouse, eligibility system to reporting layer, EVV platform to operational reports. These are the pipelines that need validation before evidence is compiled from them.
Add cross-system reconciliation for your top 5 metrics. Identify the five metrics that appear in the most CMS submissions or that have the highest financial stakes. Implement automated cross-system validation for each: confirm the figure is consistent across source systems before it is included in any evidence package.
Establish an audit-ready logging process. Every data extraction, every validation run, and every figure that enters an SMC submission should be logged with a timestamp, a source system reference, and a validation result. This log is your response to any CMS data request.
Set up ongoing monitoring for APD outcome metrics. Don't wait for the certification submission to check your metrics. Monitor them continuously against the commitments in your APD. Deviations that are caught six months before the submission are investigation opportunities. Deviations caught by CMS after submission are deferral risks.
💡 The highest-risk moment for state agencies in 2026 is the first SMC submission under the mandatory templates. Agencies that have automated their evidence collection will adapt the template format quickly. Agencies that are still compiling evidence manually will face both the format change and the data integrity risk simultaneously.
How Vexdata Supports State Medicaid Agencies With SMC Evidence
Vexdata's data quality and validation platform is deployed at state and local health departments for exactly this use case — automating the validation layer underneath evidence, metrics, and federal reporting submissions.
For CMS SMC evidence specifically, Vexdata provides:
✓ Cross-system data validation — reconciling metrics across MMIS, eligibility, EVV, and data warehouse automatically before evidence compilation
✓ Source-to-target testing — confirming that figures in reporting layers match source system data with field-level accuracy
✓ Immutable audit trail — timestamped logs of every validation run, every discrepancy, and every resolved issue — produced automatically as a byproduct of normal operations
✓ Continuous outcome metric monitoring — tracking APD-committed metrics against actual data on an ongoing basis, alerting when deviations occur
✓ Federal reporting readiness — the same automated validation that supports SMC evidence supports CDC, CMS, and other federal data submissions across the agency
The Massachusetts Department of Public Health implemented Vexdata's platform for automated ETL testing and pipeline validation. ETL testing time dropped from one week to two hours. Testing effort was reduced by 73%. The result was 100% data confidence across reporting pipelines — the same confidence that SMC evidence submissions require. See vexdata.io/health-department for details on how Vexdata works in a public health data environment.
The Bottom Line
The CMS SMC framework has always emphasised outcomes over paperwork. The mandatory standardised templates effective July 2026 make that emphasis operational — states must now submit evidence in a format that CMS can consistently evaluate, compare, and scrutinise across all MES modules simultaneously.
States that approach SMC evidence as a manual compilation exercise face a growing risk: that the data underlying their submissions is inconsistent, that discrepancies between systems will surface during CMS review rather than before, and that their ability to respond to CMS data requests within required windows is constrained by the absence of automated audit trails.
Evidence automation is not about replacing the programmatic expertise that CMS values in SMC submissions. It is about ensuring that the data foundation underneath the evidence is correct, consistent, and traceable — so that when CMS asks for the data behind a number, the answer is ready, and it is right.
→ Health Department Data Quality: vexdata.io/health-department
→ Data Validation Platform: vexdata.io/data-validation
→ Data Observability: vexdata.io/data-observability
→ Book a 20-min demo: vexdata.io/contact




Comments