Plan of Action and Milestones

A POA&M is the document that turns your unmet security requirements into a dated, owned, budgeted plan. Under CMMC it is also the difference between a Conditional certification and no certification at all. Here is what belongs in one, what the rules forbid you from deferring, and how to close it inside 180 days.

CyberAB RPO #1449/ CMMC-RP Certified Team/ Raleigh, NC/ Since 2002
Key Takeaways
  • A POA&M is a remediation register, not an excuse memo. Every open item carries an owner, a resource estimate, a milestone, and a completion date.
  • CMMC Level 2 sets a hard floor of 80 percent. Your assessment score divided by 110 must be 0.8 or better, which works out to a minimum of 88 points, before a POA&M is permitted at all.
  • You get 180 days. A POA&M closeout assessment must confirm every deferred item within 180 days of the Conditional CMMC Status Date, or the conditional status expires.
  • Most requirements cannot be deferred. Only 1-point requirements are eligible, with one narrow exception, and six specific requirements are barred outright.
  • The System Security Plan can never go on a POA&M. CA.L2-3.12.4 is on the barred list, so an incomplete System Security Plan fails you on day one.

Definition

What Is a POA&M?

A Plan of Action and Milestones, abbreviated POA&M and often written POAM, is a formal document that lists every security requirement an organization has not yet implemented, together with the corrective action planned for each one, the resources required, the person accountable, and the date the work will be finished. It is the companion document to the System Security Plan: the plan describes what is in place, and the POA&M describes what is not, along with how and when that will change.

The term comes from federal information security practice, where agencies have used POA&Ms for decades to track known weaknesses through to closure. Defense contractors encounter it through NIST SP 800-171 and the CMMC program, healthcare organizations through HIPAA risk management, and technology companies through SOC 2 and FedRAMP. The format varies. The purpose does not. A POA&M exists so that an unmet requirement is a scheduled piece of work rather than an unmanaged risk that everybody has quietly agreed to stop mentioning.

The distinction that matters most in practice is between a POA&M and a risk register. A risk register catalogs things that could go wrong. A POA&M catalogs specific control requirements that are currently failing, with a commitment attached to each. An assessor reading your POA&M is not evaluating your understanding of risk. They are checking whether you have an executable plan, whether the dates are credible, and whether the items on the list are ones you were permitted to defer in the first place.

That last point catches more organizations than any other. Teams arrive at assessment believing a POA&M is a general-purpose safety net, and discover that the majority of their gaps were never eligible for deferral. Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, has watched that assumption end assessments before lunch. The rules are specific, they are published, and they reward organizations that read them before scheduling a C3PAO.


The Document Pair

The POA&M and the System Security Plan

These two documents are read together, and inconsistency between them is one of the fastest ways to lose assessor confidence. The System Security Plan defines the system boundary, describes the environment, and explains how each of the 110 NIST SP 800-171 requirements is implemented. Where a requirement is not implemented, the plan should say so plainly and the POA&M should pick that thread up with a remediation commitment.

Problems appear when the two drift. A System Security Plan that claims multifactor authentication is fully deployed, sitting next to a POA&M with an open item for multifactor authentication on the administrative tier, tells the assessor that nobody is maintaining either document. So does a POA&M item referencing a system component that the plan never included in the boundary. Our practice is to treat them as one artifact with two views, generated from a single control set, which is how the ComplianceArmor® platform handles it: the implementation status field drives both outputs, so a control cannot be marked implemented in one document and deferred in the other.

There is also a hard regulatory reason to get the plan finished first. CA.L2-3.12.4, the requirement to develop and update a System Security Plan, is explicitly barred from appearing on a Level 2 POA&M. You cannot defer the document that describes your deferrals. If the plan is incomplete on assessment day, no POA&M can rescue the outcome. Organizations that have not started should begin with the System Security Plan and treat the POA&M as the output of that work rather than a parallel exercise.

Not sure which of your gaps are actually deferrable?

A scoping conversation maps your current gaps against the eligibility rules before you spend money on a C3PAO date. Call 919-348-4912 or request a review.


Structure

What Belongs in a POA&M

There is no single mandated template across every framework, but assessors consistently look for the same fields. A POA&M missing any of these reads as aspirational rather than operational.

FieldWhat it capturesWhy assessors check it
Requirement identifierThe specific control, cited by its framework number, such as AC.L2-3.1.1Ties the item to an assessable requirement rather than a vague theme
Weakness descriptionWhat is actually failing, in concrete terms, including affected componentsVague entries cannot be verified as closed
Point valueThe CMMC scoring weight of the requirement: 1, 3, or 5Determines whether the item was eligible for deferral at all
Responsible partyA named individual, not a departmentDepartments do not close items; people do
Resources requiredBudget, licensing, headcount, or vendor engagement neededAn item with no funded resource is not a plan
MilestonesIntermediate checkpoints with datesShows the work is sequenced, not a single distant promise
Scheduled completion dateThe date the requirement will be fully metMust fall inside the 180-day window for CMMC conditional status
Status and evidenceCurrent state plus the artifact that will prove closureCloseout assessment verifies evidence, not assertions

The evidence field is the one most often left blank, and it is the one that determines whether closeout goes smoothly. Deciding at the outset what artifact will demonstrate that a requirement is met, whether that is a configuration export, a signed policy, a training completion report, or a scan result, means the closeout assessment becomes a document review rather than a scramble.


CMMC Rules

What You Can and Cannot Defer

This is the section worth reading twice. The CMMC Program rule at 32 CFR 170.21 sets narrow conditions on POA&M use for Level 2 assessments, and organizations that plan around a looser reading of it lose both the assessment fee and the schedule.

The 80 percent floor

A POA&M is only permitted if your assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8. With 110 requirements in play, that puts the minimum passing score at 88 points. Below that threshold there is no conditional status and no POA&M: the assessment result is a failure, and you start again. Running your score before booking an assessment is the single cheapest risk reduction available, and our SPRS score calculator exists for exactly that purpose.

The 1-point rule

Only requirements carrying a point value of 1 may appear on a Level 2 POA&M. The 3-point and 5-point requirements, which are the heavily weighted controls the scoring methodology treats as most consequential, must be fully implemented before the assessment. There is one carve-out: SC.L2-3.13.11, the requirement to use FIPS-validated cryptography to protect CUI, is permitted on a POA&M despite its higher weighting. That exception exists because FIPS-validated module procurement and deployment can legitimately run on a vendor timeline outside the organization's direct control.

The barred requirements

Six requirements cannot be placed on a Level 2 POA&M under any circumstances:

  • AC.L2-3.1.20 - Verify and control connections to external systems
  • AC.L2-3.1.22 - Control CUI posted or processed on publicly accessible systems
  • CA.L2-3.12.4 - Develop, document, and periodically update System Security Plans
  • PE.L2-3.10.3 - Escort visitors and monitor visitor activity
  • PE.L2-3.10.4 - Maintain audit logs of physical access
  • PE.L2-3.10.5 - Control and manage physical access devices

Notice the pattern. Four of the six are low-cost, low-technology requirements: escort your visitors, keep a visitor log, control your badges and keys, know what is connected to your network. They are barred precisely because there is no credible argument that an organization needs six additional months to start a visitor log. The other two, controlling CUI on public systems and maintaining a System Security Plan, are barred because deferring them would undermine the assessment itself.

The 180-day clock

Closing a POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out in that window, the Conditional CMMC Status expires. The clock starts at the conditional status date, not at the point you finish remediation, and the closeout assessment itself takes scheduling. Treating day 180 as the deadline for finishing the work rather than the deadline for having the work verified is a common and expensive misreading. Work backward from the closeout date, not forward from the assessment.


Scoring

How a POA&M Moves Your SPRS Score

The Supplier Performance Risk System score is the number your prime contractors and contracting officers can see, and it is derived directly from the same assessment that produces your POA&M. The methodology begins at 110 and subtracts the weighted value of each unimplemented requirement. A single 5-point requirement left open costs five times what a 1-point requirement costs, which is why the eligibility rules and the scoring math point in the same direction: fix the heavy controls, defer only the light ones.

Because POA&M items are by definition unimplemented, they are already reflected as deductions in the score you carry into conditional status. As each item closes and is verified, the corresponding points return. Organizations tracking this well can forecast their post-closeout score on day one, which turns the POA&M into a project plan with a visible finish line rather than a compliance obligation. Our SPRS score guidance walks through the arithmetic in more detail, and the free calculator lets you model the effect of closing specific items before you commit to a sequence.

One practical note: the order in which you close items should be driven by evidence availability and dependency, not by point value alone. A 1-point requirement that unblocks three others is worth doing first even though its individual contribution is small. Sequencing is where most of the recoverable time in a 180-day window actually lives.


Lifecycle

The POA&M Lifecycle: Six Stages

1

Assess and score

Run a full assessment against all 110 requirements and record a MET or NOT MET determination for each, with the evidence that supports it. This is the input to everything downstream. A self-assessment that was optimistic about partial implementations produces a POA&M that collapses under C3PAO scrutiny, so score the way an assessor would: partially implemented is not implemented.

2

Triage by eligibility

Split the NOT MET list into three buckets: barred requirements that must be fixed before assessment, 3-point and 5-point requirements that must be fixed before assessment, and 1-point requirements plus SC.L2-3.13.11 that may be deferred. The first two buckets are your pre-assessment work plan. Only the third bucket becomes the POA&M.

3

Cost and sequence

Attach a resource estimate to every deferred item and lay them out across the 180-day window in dependency order, leaving room at the end for the closeout assessment itself. Items requiring procurement, vendor engagement, or FIPS-validated module deployment go first because their timelines are the least controllable.

4

Assign and commit

Name an individual for each item and confirm they have both the authority and the budget to close it. An item assigned to a role that is currently vacant, or to a person who cannot approve the spend, is not assigned. This is also the point to secure executive sign-off on the dates, because the dates become a commitment visible to your assessor.

5

Execute and evidence

Close items and capture the proving artifact at the moment of closure rather than reconstructing it later. Configuration exports, policy approvals with signature dates, training completion records, and scan results all age badly when gathered retroactively. Update the System Security Plan in the same pass so the two documents never diverge.

6

Close out and monitor

The closeout assessment verifies every deferred item. Once conditional status converts to full status, the POA&M does not disappear: it becomes the intake for ongoing findings from continuous monitoring, internal audits, and vulnerability scans. Organizations that keep the register live between assessment cycles arrive at reassessment with far less to do.


Other Frameworks

POA&M Beyond CMMC

The document travels across frameworks, though the rules attached to it change considerably. Understanding which set of constraints applies to you prevents importing CMMC's strictness where it is not required, and importing CMMC's flexibility where it does not exist.

NIST SP 800-53 and FedRAMP. This is the POA&M's origin. FedRAMP requires a POA&M maintained on a defined cadence with remediation timelines keyed to finding severity, typically 30, 90, or 180 days by risk level. The format is prescribed and the review is continuous rather than event-driven.

HIPAA. The Security Rule does not use the term POA&M, but its risk management standard requires covered entities and business associates to implement measures sufficient to reduce risks to a reasonable level. In practice, a documented remediation plan coming out of the risk analysis is what Office for Civil Rights investigators ask to see, and it looks exactly like a POA&M. Craig Petronella, author of How HIPAA Can Crush Your Medical Practice, has seen the absence of that document turn a manageable finding into a systemic one.

SOC 2. There is no POA&M requirement, but a remediation tracker is how organizations manage the gap between a readiness assessment and the Type II observation window. Auditors do not assess the tracker itself; they assess whether controls operated effectively over the period, and a disciplined remediation plan is how you get there.

NIST SP 800-171 outside CMMC. Contractors carrying DFARS 252.204-7012 obligations without a CMMC assessment requirement still submit SPRS scores and still benefit from a POA&M, but the 180-day rule and the eligibility restrictions are CMMC constructs. Applying them voluntarily is good discipline. Assuming they are already binding on you can lead to spending money on a timeline nobody is enforcing.


Pitfalls

Common POA&M Mistakes

Deferring ineligible requirements

The most expensive mistake. A POA&M containing a 3-point or 5-point requirement, or any of the six barred requirements, is not a partially acceptable POA&M. It signals that the eligibility rules were never read, and the assessment does not proceed on the assumption that the rest of the list is sound.

Dates chosen for comfort

Completion dates clustered at day 175 are a tell. They indicate the dates were derived from the deadline rather than from the work, and they leave no room for the closeout assessment itself. Credible dates are staggered and tied to identifiable dependencies.

Weakness descriptions that restate the control

"We do not fully meet AC.L2-3.1.1" is not a weakness description. It tells the assessor nothing about which systems, which accounts, or which gap. A closeout assessor cannot verify the closure of a weakness that was never specifically described.

No named owner

Assigning items to "IT" or "Security" rather than a person is how items reach day 170 untouched. Ownership needs a name, and that name needs the budget authority to act without a second approval cycle.

Divergence from the System Security Plan

When the plan and the POA&M contradict each other, both lose credibility. Maintaining them from a single control set, rather than as two separately edited documents, removes the failure mode entirely.

Treating closure as the end

A closed POA&M with no successor register means the next finding has nowhere to go. The organizations that reassess smoothly are the ones that kept the register live and fed it from monitoring and audit findings throughout the cycle.


Approaches

Spreadsheet, Platform, or Managed

Most organizations start with a spreadsheet and outgrow it somewhere between the assessment and the closeout. Here is an honest comparison of the three common approaches.

SpreadsheetSelf-serve GRC toolManaged with Petronella Technology Group
Setup effortImmediateWeeks of configurationScoping conversation, then handled
Eligibility checkingManual, easy to get wrongVaries by productReviewed by CMMC-RP certified staff
Link to System Security PlanTwo documents, manual syncSometimes integratedSingle control set, both outputs generated
Evidence captureWherever someone saved itStructured repositoryStructured, mapped to each item at closure
Score forecastingHand-calculatedOften availableModeled against closure sequence
Closeout preparationReconstruct evidence lateDepends on disciplineEvidence assembled as work completes
Best suited toVery small scopes, few gapsTeams with dedicated compliance staffOrganizations without a full-time compliance function

There is no wrong answer for an organization with three open 1-point items and a compliance manager who owns the file. The calculus changes when the register has twenty items, four owners, a FIPS-validated cryptography dependency on a vendor roadmap, and a 180-day clock that started before the paperwork was finished.


Our Approach

How Petronella Technology Group Builds POA&Ms

Petronella Technology Group has operated from Raleigh since April 2002 and holds CyberAB Registered Provider Organization status, RPO #1449, with a CMMC-RP certified team. Our POA&M work runs in the same engagement as the System Security Plan, because separating them creates the divergence problem described above.

We begin with boundary and scope, since a POA&M written against the wrong system boundary is wrong in every row. From there we score all 110 requirements the way a C3PAO would, triage the NOT MET list against the eligibility rules before anything reaches the register, and flag the items you must fix pre-assessment as a separate, funded work plan. That triage step is where the value is: it is far cheaper to discover a barred requirement in a scoping conversation than in an assessment.

Documentation is produced through ComplianceArmor®, our compliance documentation platform, which generates the System Security Plan and the POA&M from one control set with evidence collection and continuous monitoring built in. For organizations handling CUI, we also design and operate CMMC enclaves that narrow the assessment boundary, which is frequently the fastest route to a higher score and a shorter POA&M. Engagements are scoped to clear deliverables with no long-term contract required, and we promise a defined scope rather than a specific assessment outcome, because no honest advisor controls a C3PAO's determination.

"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals."

Daniel Lee, TrustIndex verified review. Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews.



FAQ

Plan of Action and Milestones Questions

What does POA&M stand for?
POA&M stands for Plan of Action and Milestones. It is frequently written without the ampersand as POAM, and both refer to the same document: a formal register of unmet security requirements, each with a corrective action, a responsible party, required resources, intermediate milestones, and a scheduled completion date. The term originates in federal information security practice and is now used across NIST SP 800-171, CMMC, FedRAMP, and NIST SP 800-53 programs.
What is the minimum score needed to use a POA&M under CMMC Level 2?
Your assessment score divided by the total number of CMMC Level 2 security requirements must be greater than or equal to 0.8. Because there are 110 requirements, the minimum passing score is 88 points. Score below that and no POA&M is permitted: the assessment does not produce a Conditional CMMC Status. Modeling your score before booking an assessment is worth doing, and our free SPRS calculator handles the arithmetic.
How long do I have to close a CMMC POA&M?
Closure must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within that window, the Conditional CMMC Status expires. The important nuance is that 180 days is the deadline for verified closure, not for finishing the remediation work. The closeout assessment has to be scheduled and performed inside the window, so plan backward from that date.
Which requirements cannot go on a CMMC Level 2 POA&M?
Only requirements with a point value of 1 are eligible, with a single exception for SC.L2-3.13.11, the FIPS-validated cryptography requirement, which is permitted despite its higher weighting. Beyond the point-value rule, six requirements are barred outright: AC.L2-3.1.20 and AC.L2-3.1.22, CA.L2-3.12.4, and PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. All 3-point and 5-point requirements other than SC.L2-3.13.11 must be fully implemented before your assessment.
What is the difference between a POA&M and a System Security Plan?
The System Security Plan describes the system, its boundary, and how each security requirement is implemented. The POA&M describes the requirements that are not implemented and how they will be. They are read together and must agree with each other. Note that CA.L2-3.12.4, the System Security Plan requirement itself, cannot be placed on a Level 2 POA&M, so the plan must be complete before assessment. Our System Security Plan page covers that document in depth.
Does a POA&M affect my SPRS score?
Yes, though indirectly. The SPRS score starts at 110 and subtracts the weighted value of each unimplemented requirement. Anything on your POA&M is unimplemented by definition, so it is already reflected as a deduction in the score you carry into conditional status. As items close and are verified at closeout, those points return. This means you can forecast your post-closeout score on day one and treat the POA&M as a project plan with a measurable finish line.
Do HIPAA or SOC 2 require a POA&M?
Neither uses the term. The HIPAA Security Rule requires covered entities and business associates to implement security measures sufficient to reduce risks to a reasonable and appropriate level, and a documented remediation plan flowing from the risk analysis is what investigators typically ask to see. SOC 2 has no POA&M requirement, but a remediation tracker is the practical mechanism for closing gaps between a readiness assessment and the Type II observation window. In both cases the document looks like a POA&M even though the framework does not name it.
Can Petronella Technology Group build and manage our POA&M?
Yes. We score all 110 requirements the way a C3PAO would, triage the results against the eligibility rules so ineligible items never reach the register, sequence the deferred items across the 180-day window, and assemble closeout evidence as the work completes. Documentation is generated through ComplianceArmor® so the System Security Plan and POA&M stay consistent. Petronella Technology Group is a CyberAB Registered Provider Organization, RPO #1449, with a CMMC-RP certified team, and has served regulated organizations and defense contractors from Raleigh since 2002. Call 919-348-4912 or request a scoping conversation.

Find Out Which Gaps You Can Actually Defer

A scoping conversation maps your current gaps against the CMMC eligibility rules, identifies what must be fixed before assessment, and turns the rest into a dated, owned POA&M. Call 919-348-4912 or request a review.

Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912 · info@petronellatech.com
CyberAB Registered Provider Organization RPO #1449 · BBB A+ rated since 2003 · Serving Raleigh, Durham, Chapel Hill, Cary, Apex and nationwide
Last Updated: August 16, 2026