That is correct.
You can avoid the 4% cut with a quality measure which has no security analysis requirement.
An alternative is the "advancing care information" path which has 4 requirements; three of them are pretty easy, but the fourth is the security risk analysis which is either a hassle or an expense. That is why I think the quality measure is the easiest way to go.