Plan of Action and Milestones
A POA&M is the document that turns your unmet security requirements into a dated, owned, budgeted plan. Under CMMC it is also the difference between a Conditional certification and no certification at all. Here is what belongs in one, what the rules forbid you from deferring, and how to close it inside 180 days.
- A POA&M is a remediation register, not an excuse memo. Every open item carries an owner, a resource estimate, a milestone, and a completion date.
- CMMC Level 2 sets a hard floor of 80 percent. Your assessment score divided by 110 must be 0.8 or better, which works out to a minimum of 88 points, before a POA&M is permitted at all.
- You get 180 days. A POA&M closeout assessment must confirm every deferred item within 180 days of the Conditional CMMC Status Date, or the conditional status expires.
- Most requirements cannot be deferred. Only 1-point requirements are eligible, with one narrow exception, and six specific requirements are barred outright.
- The System Security Plan can never go on a POA&M. CA.L2-3.12.4 is on the barred list, so an incomplete System Security Plan fails you on day one.
What Is a POA&M?
A Plan of Action and Milestones, abbreviated POA&M and often written POAM, is a formal document that lists every security requirement an organization has not yet implemented, together with the corrective action planned for each one, the resources required, the person accountable, and the date the work will be finished. It is the companion document to the System Security Plan: the plan describes what is in place, and the POA&M describes what is not, along with how and when that will change.
The term comes from federal information security practice, where agencies have used POA&Ms for decades to track known weaknesses through to closure. Defense contractors encounter it through NIST SP 800-171 and the CMMC program, healthcare organizations through HIPAA risk management, and technology companies through SOC 2 and FedRAMP. The format varies. The purpose does not. A POA&M exists so that an unmet requirement is a scheduled piece of work rather than an unmanaged risk that everybody has quietly agreed to stop mentioning.
The distinction that matters most in practice is between a POA&M and a risk register. A risk register catalogs things that could go wrong. A POA&M catalogs specific control requirements that are currently failing, with a commitment attached to each. An assessor reading your POA&M is not evaluating your understanding of risk. They are checking whether you have an executable plan, whether the dates are credible, and whether the items on the list are ones you were permitted to defer in the first place.
That last point catches more organizations than any other. Teams arrive at assessment believing a POA&M is a general-purpose safety net, and discover that the majority of their gaps were never eligible for deferral. Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, has watched that assumption end assessments before lunch. The rules are specific, they are published, and they reward organizations that read them before scheduling a C3PAO.
The POA&M and the System Security Plan
These two documents are read together, and inconsistency between them is one of the fastest ways to lose assessor confidence. The System Security Plan defines the system boundary, describes the environment, and explains how each of the 110 NIST SP 800-171 requirements is implemented. Where a requirement is not implemented, the plan should say so plainly and the POA&M should pick that thread up with a remediation commitment.
Problems appear when the two drift. A System Security Plan that claims multifactor authentication is fully deployed, sitting next to a POA&M with an open item for multifactor authentication on the administrative tier, tells the assessor that nobody is maintaining either document. So does a POA&M item referencing a system component that the plan never included in the boundary. Our practice is to treat them as one artifact with two views, generated from a single control set, which is how the ComplianceArmor® platform handles it: the implementation status field drives both outputs, so a control cannot be marked implemented in one document and deferred in the other.
There is also a hard regulatory reason to get the plan finished first. CA.L2-3.12.4, the requirement to develop and update a System Security Plan, is explicitly barred from appearing on a Level 2 POA&M. You cannot defer the document that describes your deferrals. If the plan is incomplete on assessment day, no POA&M can rescue the outcome. Organizations that have not started should begin with the System Security Plan and treat the POA&M as the output of that work rather than a parallel exercise.
Not sure which of your gaps are actually deferrable?
A scoping conversation maps your current gaps against the eligibility rules before you spend money on a C3PAO date. Call 919-348-4912 or request a review.
What Belongs in a POA&M
There is no single mandated template across every framework, but assessors consistently look for the same fields. A POA&M missing any of these reads as aspirational rather than operational.
| Field | What it captures | Why assessors check it |
|---|---|---|
| Requirement identifier | The specific control, cited by its framework number, such as AC.L2-3.1.1 | Ties the item to an assessable requirement rather than a vague theme |
| Weakness description | What is actually failing, in concrete terms, including affected components | Vague entries cannot be verified as closed |
| Point value | The CMMC scoring weight of the requirement: 1, 3, or 5 | Determines whether the item was eligible for deferral at all |
| Responsible party | A named individual, not a department | Departments do not close items; people do |
| Resources required | Budget, licensing, headcount, or vendor engagement needed | An item with no funded resource is not a plan |
| Milestones | Intermediate checkpoints with dates | Shows the work is sequenced, not a single distant promise |
| Scheduled completion date | The date the requirement will be fully met | Must fall inside the 180-day window for CMMC conditional status |
| Status and evidence | Current state plus the artifact that will prove closure | Closeout assessment verifies evidence, not assertions |
The evidence field is the one most often left blank, and it is the one that determines whether closeout goes smoothly. Deciding at the outset what artifact will demonstrate that a requirement is met, whether that is a configuration export, a signed policy, a training completion report, or a scan result, means the closeout assessment becomes a document review rather than a scramble.
What You Can and Cannot Defer
This is the section worth reading twice. The CMMC Program rule at 32 CFR 170.21 sets narrow conditions on POA&M use for Level 2 assessments, and organizations that plan around a looser reading of it lose both the assessment fee and the schedule.
The 80 percent floor
A POA&M is only permitted if your assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8. With 110 requirements in play, that puts the minimum passing score at 88 points. Below that threshold there is no conditional status and no POA&M: the assessment result is a failure, and you start again. Running your score before booking an assessment is the single cheapest risk reduction available, and our SPRS score calculator exists for exactly that purpose.
The 1-point rule
Only requirements carrying a point value of 1 may appear on a Level 2 POA&M. The 3-point and 5-point requirements, which are the heavily weighted controls the scoring methodology treats as most consequential, must be fully implemented before the assessment. There is one carve-out: SC.L2-3.13.11, the requirement to use FIPS-validated cryptography to protect CUI, is permitted on a POA&M despite its higher weighting. That exception exists because FIPS-validated module procurement and deployment can legitimately run on a vendor timeline outside the organization's direct control.
The barred requirements
Six requirements cannot be placed on a Level 2 POA&M under any circumstances:
- AC.L2-3.1.20 - Verify and control connections to external systems
- AC.L2-3.1.22 - Control CUI posted or processed on publicly accessible systems
- CA.L2-3.12.4 - Develop, document, and periodically update System Security Plans
- PE.L2-3.10.3 - Escort visitors and monitor visitor activity
- PE.L2-3.10.4 - Maintain audit logs of physical access
- PE.L2-3.10.5 - Control and manage physical access devices
Notice the pattern. Four of the six are low-cost, low-technology requirements: escort your visitors, keep a visitor log, control your badges and keys, know what is connected to your network. They are barred precisely because there is no credible argument that an organization needs six additional months to start a visitor log. The other two, controlling CUI on public systems and maintaining a System Security Plan, are barred because deferring them would undermine the assessment itself.
The 180-day clock
Closing a POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out in that window, the Conditional CMMC Status expires. The clock starts at the conditional status date, not at the point you finish remediation, and the closeout assessment itself takes scheduling. Treating day 180 as the deadline for finishing the work rather than the deadline for having the work verified is a common and expensive misreading. Work backward from the closeout date, not forward from the assessment.
How a POA&M Moves Your SPRS Score
The Supplier Performance Risk System score is the number your prime contractors and contracting officers can see, and it is derived directly from the same assessment that produces your POA&M. The methodology begins at 110 and subtracts the weighted value of each unimplemented requirement. A single 5-point requirement left open costs five times what a 1-point requirement costs, which is why the eligibility rules and the scoring math point in the same direction: fix the heavy controls, defer only the light ones.
Because POA&M items are by definition unimplemented, they are already reflected as deductions in the score you carry into conditional status. As each item closes and is verified, the corresponding points return. Organizations tracking this well can forecast their post-closeout score on day one, which turns the POA&M into a project plan with a visible finish line rather than a compliance obligation. Our SPRS score guidance walks through the arithmetic in more detail, and the free calculator lets you model the effect of closing specific items before you commit to a sequence.
One practical note: the order in which you close items should be driven by evidence availability and dependency, not by point value alone. A 1-point requirement that unblocks three others is worth doing first even though its individual contribution is small. Sequencing is where most of the recoverable time in a 180-day window actually lives.
The POA&M Lifecycle: Six Stages
Assess and score
Run a full assessment against all 110 requirements and record a MET or NOT MET determination for each, with the evidence that supports it. This is the input to everything downstream. A self-assessment that was optimistic about partial implementations produces a POA&M that collapses under C3PAO scrutiny, so score the way an assessor would: partially implemented is not implemented.
Triage by eligibility
Split the NOT MET list into three buckets: barred requirements that must be fixed before assessment, 3-point and 5-point requirements that must be fixed before assessment, and 1-point requirements plus SC.L2-3.13.11 that may be deferred. The first two buckets are your pre-assessment work plan. Only the third bucket becomes the POA&M.
Cost and sequence
Attach a resource estimate to every deferred item and lay them out across the 180-day window in dependency order, leaving room at the end for the closeout assessment itself. Items requiring procurement, vendor engagement, or FIPS-validated module deployment go first because their timelines are the least controllable.
Assign and commit
Name an individual for each item and confirm they have both the authority and the budget to close it. An item assigned to a role that is currently vacant, or to a person who cannot approve the spend, is not assigned. This is also the point to secure executive sign-off on the dates, because the dates become a commitment visible to your assessor.
Execute and evidence
Close items and capture the proving artifact at the moment of closure rather than reconstructing it later. Configuration exports, policy approvals with signature dates, training completion records, and scan results all age badly when gathered retroactively. Update the System Security Plan in the same pass so the two documents never diverge.
Close out and monitor
The closeout assessment verifies every deferred item. Once conditional status converts to full status, the POA&M does not disappear: it becomes the intake for ongoing findings from continuous monitoring, internal audits, and vulnerability scans. Organizations that keep the register live between assessment cycles arrive at reassessment with far less to do.
POA&M Beyond CMMC
The document travels across frameworks, though the rules attached to it change considerably. Understanding which set of constraints applies to you prevents importing CMMC's strictness where it is not required, and importing CMMC's flexibility where it does not exist.
NIST SP 800-53 and FedRAMP. This is the POA&M's origin. FedRAMP requires a POA&M maintained on a defined cadence with remediation timelines keyed to finding severity, typically 30, 90, or 180 days by risk level. The format is prescribed and the review is continuous rather than event-driven.
HIPAA. The Security Rule does not use the term POA&M, but its risk management standard requires covered entities and business associates to implement measures sufficient to reduce risks to a reasonable level. In practice, a documented remediation plan coming out of the risk analysis is what Office for Civil Rights investigators ask to see, and it looks exactly like a POA&M. Craig Petronella, author of How HIPAA Can Crush Your Medical Practice, has seen the absence of that document turn a manageable finding into a systemic one.
SOC 2. There is no POA&M requirement, but a remediation tracker is how organizations manage the gap between a readiness assessment and the Type II observation window. Auditors do not assess the tracker itself; they assess whether controls operated effectively over the period, and a disciplined remediation plan is how you get there.
NIST SP 800-171 outside CMMC. Contractors carrying DFARS 252.204-7012 obligations without a CMMC assessment requirement still submit SPRS scores and still benefit from a POA&M, but the 180-day rule and the eligibility restrictions are CMMC constructs. Applying them voluntarily is good discipline. Assuming they are already binding on you can lead to spending money on a timeline nobody is enforcing.
Common POA&M Mistakes
Deferring ineligible requirements
The most expensive mistake. A POA&M containing a 3-point or 5-point requirement, or any of the six barred requirements, is not a partially acceptable POA&M. It signals that the eligibility rules were never read, and the assessment does not proceed on the assumption that the rest of the list is sound.
Dates chosen for comfort
Completion dates clustered at day 175 are a tell. They indicate the dates were derived from the deadline rather than from the work, and they leave no room for the closeout assessment itself. Credible dates are staggered and tied to identifiable dependencies.
Weakness descriptions that restate the control
"We do not fully meet AC.L2-3.1.1" is not a weakness description. It tells the assessor nothing about which systems, which accounts, or which gap. A closeout assessor cannot verify the closure of a weakness that was never specifically described.
No named owner
Assigning items to "IT" or "Security" rather than a person is how items reach day 170 untouched. Ownership needs a name, and that name needs the budget authority to act without a second approval cycle.
Divergence from the System Security Plan
When the plan and the POA&M contradict each other, both lose credibility. Maintaining them from a single control set, rather than as two separately edited documents, removes the failure mode entirely.
Treating closure as the end
A closed POA&M with no successor register means the next finding has nowhere to go. The organizations that reassess smoothly are the ones that kept the register live and fed it from monitoring and audit findings throughout the cycle.
Spreadsheet, Platform, or Managed
Most organizations start with a spreadsheet and outgrow it somewhere between the assessment and the closeout. Here is an honest comparison of the three common approaches.
| Spreadsheet | Self-serve GRC tool | Managed with Petronella Technology Group | |
|---|---|---|---|
| Setup effort | Immediate | Weeks of configuration | Scoping conversation, then handled |
| Eligibility checking | Manual, easy to get wrong | Varies by product | Reviewed by CMMC-RP certified staff |
| Link to System Security Plan | Two documents, manual sync | Sometimes integrated | Single control set, both outputs generated |
| Evidence capture | Wherever someone saved it | Structured repository | Structured, mapped to each item at closure |
| Score forecasting | Hand-calculated | Often available | Modeled against closure sequence |
| Closeout preparation | Reconstruct evidence late | Depends on discipline | Evidence assembled as work completes |
| Best suited to | Very small scopes, few gaps | Teams with dedicated compliance staff | Organizations without a full-time compliance function |
There is no wrong answer for an organization with three open 1-point items and a compliance manager who owns the file. The calculus changes when the register has twenty items, four owners, a FIPS-validated cryptography dependency on a vendor roadmap, and a 180-day clock that started before the paperwork was finished.
How Petronella Technology Group Builds POA&Ms
Petronella Technology Group has operated from Raleigh since April 2002 and holds CyberAB Registered Provider Organization status, RPO #1449, with a CMMC-RP certified team. Our POA&M work runs in the same engagement as the System Security Plan, because separating them creates the divergence problem described above.
We begin with boundary and scope, since a POA&M written against the wrong system boundary is wrong in every row. From there we score all 110 requirements the way a C3PAO would, triage the NOT MET list against the eligibility rules before anything reaches the register, and flag the items you must fix pre-assessment as a separate, funded work plan. That triage step is where the value is: it is far cheaper to discover a barred requirement in a scoping conversation than in an assessment.
Documentation is produced through ComplianceArmor®, our compliance documentation platform, which generates the System Security Plan and the POA&M from one control set with evidence collection and continuous monitoring built in. For organizations handling CUI, we also design and operate CMMC enclaves that narrow the assessment boundary, which is frequently the fastest route to a higher score and a shorter POA&M. Engagements are scoped to clear deliverables with no long-term contract required, and we promise a defined scope rather than a specific assessment outcome, because no honest advisor controls a C3PAO's determination.
"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals."
Daniel Lee, TrustIndex verified review. Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews.
Continue Your CMMC Preparation
Plan of Action and Milestones Questions
What does POA&M stand for?
What is the minimum score needed to use a POA&M under CMMC Level 2?
How long do I have to close a CMMC POA&M?
Which requirements cannot go on a CMMC Level 2 POA&M?
What is the difference between a POA&M and a System Security Plan?
Does a POA&M affect my SPRS score?
Do HIPAA or SOC 2 require a POA&M?
Can Petronella Technology Group build and manage our POA&M?
Find Out Which Gaps You Can Actually Defer
A scoping conversation maps your current gaps against the CMMC eligibility rules, identifies what must be fixed before assessment, and turns the rest into a dated, owned POA&M. Call 919-348-4912 or request a review.
Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912 · info@petronellatech.com
CyberAB Registered Provider Organization RPO #1449 · BBB A+ rated since 2003 · Serving Raleigh, Durham, Chapel Hill, Cary, Apex and nationwide
Last Updated: August 16, 2026