NAIFA's Advocacy in Action (AIA) Blog

CMS Announces New Security Requirement for EDE Logins

Written by NAIFA | 8/29/25 9:29 PM

The Centers for Medicare & Medicaid Services (CMS) has implemented a new security procedure on Friday, August 29, that will require agents and brokers to reconnect their CMS Enterprise Portal Federally-facilitated Marketplace (FFM) account credentials after 30 minutes of inactivity.

What’s changing: When using an EDE website, you connect your FFM account by being redirected to the CMS Enterprise Portal where you enter your personal FFM credentials and password. After this connection is established, a 30-minute inactivity timer begins. If CMS systems detect there is no relevant FFM activity within that timeframe, your connection will time out and you will need to reauthenticate to reconnect your FFM account to the EDE website.

Important to know: The CMS system determines “activity” based on specific actions that connect to the FFM. Since these connections happen behind the scenes, you may be prompted to reconnect even if you’ve been actively using an EDE website. These security controls are in addition to existing “time-out” protections that may already be in place on EDE partner websites.

To minimize disruptions, we recommend you:

  1. Complete applications and enrollments in a single session when possible.
  2. Be prepared to sign in to your CMS FFM account again if prompted during your EDE session.
  3. Save your work frequently, especially before stepping away from your computer.

Have additional questions? For additional assistance, contact the Agent/Broker Email Help Desk at FFMProducer-AssisterHelpDesk@cms.hhs.gov.