Home / Article

What Is a POA&M and When Do I Need One?

October 07, 2026 · cmmc, poam, compliance, assessment, nist

Your assessor scored several controls as NOT MET, and you need to know whether those gaps can wait.

What a POA&M is

A POA&M is a Plan of Action and Milestones.

It is a documented plan that tracks each weakness found in an assessment through remediation.

NIST SP 800-18 Rev. 1 says assessment findings are used to develop a POA&M that tracks remedial actions.

Assessors record results in a Security Assessment Report, or SAR, which feeds the POA&M.

A POA&M does not erase a finding.

It shows the finding is owned, funded, and scheduled.

When CMMC allows a POA&M

CMMC is the Cybersecurity Maturity Model Certification, run by the Department of Defense under 32 CFR Part 170.

Under that rule, a POA&M only supports a Conditional CMMC Status.

At CMMC Level 1, POA&Ms are not permitted at any time, per 32 CFR 170.21(a)(1).

At CMMC Level 2, a POA&M is allowed only if the assessment score is at least 80 percent.

Under the DoD scoring method, that means scoring at least 88 of 110 requirements as MET.

Only requirements worth one point can sit on the POA&M.

Every 3-point and 5-point requirement must be MET on assessment day.

The single exception is SC.L2-3.13.11, the encryption requirement.

It can sit on a POA&M at a 3-point cost when encryption is in use.

Federal Information Processing Standards validation, or FIPS validation, is the missing piece.

If no encryption exists at all, the same gap costs 5 points and is not POA&M-eligible.

Six requirements can never sit on a Level 2 POA&M.

They include the System Security Plan, or SSP, plus five 1-point access and physical controls.

The six are AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5.

Every POA&M item must be closed within 180 days of the Conditional status date.

A closeout assessment confirms the fixes, and the status expires if the deadline passes.

For a Level 2 C3PAO path, the closeout assessment is done by a C3PAO, a Certified Third-Party Assessment Organization.

For a Level 2 self-assessment path, the organization performs its own closeout self-assessment.

What goes into each entry

Every POA&M entry should name the practice ID, describe the weakness, and assign a named owner.

It should state the planned fix, the completion date, the resources needed, and the current status.

It should also break the fix into dated milestones.

A milestone is actionable when it names a verifiable outcome and a date.

Example: turn on multifactor authentication for all remote access within 60 days of the Conditional status date.

Not actionable: improve access controls.

Example: replace the unvalidated encryption module with a FIPS-validated one before the deadline.

A POA&M is acceptable for a 1-point Level 2 gap that closes within 180 days.

It is not acceptable for Level 1 gaps or for 3-point and 5-point gaps.

It is not acceptable for any of the six excluded requirements, including the SSP.

A POA&M is never a place to park a gap indefinitely.

Work the gaps in this order:

  1. Finish your self-assessment and record each requirement as MET or NOT MET.
  2. Check each NOT MET item against the eligibility rules in 32 CFR 170.21.
  3. Confirm your score is at least 88 before writing any POA&M.
  4. Draft one entry per gap with an owner, milestones, and a completion date inside 180 days.
  5. Start procurement early for items that need hardware or new licenses.
  6. Close each item, gather evidence, and complete the closeout assessment before day 180.

Practical next steps

Pull your latest self-assessment scores and list every NOT MET requirement.

Mark each one as POA&M-eligible or not, using the point value and the excluded list.

Assign an owner to each eligible item and set dated milestones that land inside the 180-day window.

Put the SSP in place first, because without it there is no valid assessment.

PolicyCortex delivers SSP, SAR, and POA&M output produced from collected evidence at https://policycortex.com.

Sources

  • NIST SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems, National Institute of Standards and Technology, February 2006. https://www.nist.gov/publications/guide-developing-security-plans-information-technology-systems?pub_id=150601
  • 32 CFR 170.21, Plan of Action and Milestones requirements, CMMC rule. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.21
  • 32 CFR 170.24, CMMC Scoring Methodology. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.24