DMEPOS Supplier Medicare Enrollment in 2026: CMS-855S, High-Risk Screening, and the Lifted Moratorium
DMEPOS suppliers use CMS-855S and remain a High categorical risk category, but the six-month temporary nationwide DMEPOS enrollment moratorium that began February 27, 2026 expired August 27, 2026. Verify current CMS restrictions before treating an initial supplier application as blocked.

A DMEPOS supplier should not be routed through the same Medicare application workflow as a physician group. DMEPOS enrollment uses CMS-855S, and newly enrolling DMEPOS suppliers are a High categorical risk category under 42 CFR 424.518. That can trigger onsite screening and fingerprint-based FBI criminal history checks for individuals with at least a 5% direct or indirect ownership interest. There is also an important timing update for 2026: CMS imposed a temporary nationwide DMEPOS supplier enrollment moratorium effective February 27, 2026, but CMS reports that the six-month moratorium expired August 27, 2026 and National Provider Enrollment contractors resumed accepting initial DMEPOS enrollments. A current project therefore needs both High-risk readiness and a fresh check for any remaining CMS restrictions, including market- or program-specific rules that are separate from the expired nationwide moratorium.
DMEPOS suppliers use CMS-855S
CMS-855S is the Medicare enrollment application designed for DMEPOS suppliers. Do not route a new DME supplier through CMS-855B simply because the business is organized as a corporation or group. Form selection follows the supplier type and Medicare enrollment role, not the entity’s everyday business label.
At intake, verify that the organization actually intends to enroll as a DMEPOS supplier, identify the locations and supplier information that belong in that record, and download or use the current CMS application workflow. Keeping the 855S case separate from clinician enrollment prevents staff from importing physician-group assumptions into supplier standards.
New DMEPOS suppliers are High categorical risk
The current screening regulation includes newly enrolling DMEPOS suppliers at the High categorical risk level. High risk incorporates the lower screening layers and adds fingerprint-based FBI criminal history checks for individuals with a 5% or greater direct or indirect ownership interest. The enrollment team therefore needs a reliable ownership chart in addition to normal entity and location data.
Do not send every employee for fingerprints. Identify the people who meet the ownership threshold, then follow the contractor’s case-specific screening instructions. Keep completion status in the enrollment tracker while protecting any sensitive background information under appropriate compliance controls.
The temporary nationwide moratorium expired August 27, 2026
CMS’s temporary nationwide moratorium on new DMEPOS supplier enrollments began February 27, 2026 and expired August 27, 2026. CMS states that the National Provider Enrollment contractors resumed accepting initial DMEPOS enrollment applications after expiration. That means a September 2026 project should not automatically be labeled blocked merely because an earlier 2026 memo described the moratorium.
However, expiration of the temporary nationwide moratorium does not erase every DMEPOS restriction. Check the current CMS moratoria and competitive-bidding information for the supplier’s market and product situation. The correct operational lesson is to verify the current gate, not to replace an old 'blocked' rule with an equally broad 'everything is open' rule.
Coordinate site, ownership, and supplier-standard readiness
Because DMEPOS enrollment is a supplier workflow, physical-location and supplier-standard issues deserve early attention. The information in the enrollment application should describe a real operating business, and the location should be ready for the screening activity applicable to the case. The ownership record used for fingerprinting must also match the entity data submitted to CMS.
Create one pre-submit file that ties the legal entity, TIN, NPI as applicable, location, ownership chain, responsible officials, and CMS-855S transaction together. If those elements live in different spreadsheets, a contractor development request can expose contradictions that the practice could have resolved before filing.
Do not treat enrollment acceptance as billing readiness
Acceptance of an initial application after the moratorium does not mean the supplier is approved or ready to bill. Track submission, screening, site activity, development requests, determination, supplier number or billing information, EFT, and EDI as separate milestones. The supplier should not ship or bill on the assumption that an intake confirmation equals Medicare authorization.
For acquisitions or new locations, also determine whether the transaction requires a new enrollment, ownership reporting, or other supplier action. The 855S is the correct DMEPOS form family, but the exact transaction still matters.
After the August 27 expiration, update old intake templates immediately. A checkbox that still says 'DMEPOS applications paused nationwide' can stop legitimate September cases before anyone looks at the current CMS page. Keep the historical moratorium date in the SOP for context but make the current status and last verification date visible at the top.
Common 2026 DMEPOS enrollment errors
The first error is using CMS-855B instead of CMS-855S. The second is failing to recognize High-risk ownership fingerprinting. The third is relying on a March 2026 article that still describes the DMEPOS moratorium as active after its August 27 expiration. The fourth is assuming the expired moratorium eliminated all other DMEPOS program restrictions.
Use date-stamped source checks in the project file. DMEPOS rules interact with screening, supplier standards, geographic or bidding restrictions, and ownership structures. A provider enrollment desk adds value by keeping those separate controls visible instead of collapsing them into one yes/no field labeled 'Medicare credentialed.'
For organizations entering a competitive bidding area or adding product categories, assign a separate program-policy review. The expiration of a temporary enrollment moratorium addresses whether NPE contractors accept initial applications; it does not decide every product, accreditation, surety, supplier-standard, or bidding question that may apply to the business model.
Add an 'as-of' date to every DMEPOS market-entry recommendation. The temporary nationwide moratorium changed twice within 2026—implementation in February and expiration in August—showing why undated advice becomes dangerous quickly. A credentialing manager reviewing the file later should be able to see which CMS status was checked, on what date, and whether a fresh moratorium or competitive-bidding review is required before the supplier acts on the recommendation.
Keep a dated copy or note of the CMS moratorium status used for the filing decision. DMEPOS policy can change faster than a credentialing template, and a future reviewer should be able to tell why the organization accepted, paused, or rechecked an initial application at that point in 2026 without relying on staff memory.
Operational checklist
- Use CMS-855S for the DMEPOS supplier transaction.
- Confirm current CMS moratorium/restriction status as of the filing date.
- Map owners at or above 5% direct or indirect ownership.
- Prepare the supplier location and ownership file for High-risk screening.
- Track application acceptance separately from final billing readiness.
Frequently asked questions
Which Medicare enrollment form does a DMEPOS supplier use?
DMEPOS suppliers use CMS-855S.
Are newly enrolling DMEPOS suppliers High categorical risk?
Yes. They are included in the High-risk categories under 42 CFR 424.518.
Is the February 2026 nationwide DMEPOS enrollment moratorium still active in September 2026?
CMS reports that the six-month temporary moratorium expired August 27, 2026 and initial DMEPOS applications resumed.
Does expiration of the moratorium mean every DMEPOS application can be approved?
No. High-risk screening, supplier standards, and other current CMS program restrictions still need to be satisfied.
Who is fingerprinted in a High-risk DMEPOS enrollment?
The High-risk rule ties fingerprint-based FBI checks to individuals with at least a 5% direct or indirect ownership interest.