POA and M Rules Under 32 CFR 170.21: The Controls You Can Never Defer
A Plan of Action and Milestones is not a general purpose extension. Under 32 CFR 170.21, a POA&M is a narrow, conditional allowance that covers only a small slice of the NIST SP 800-171 requirement set, and the most consequential controls in your environment are categorically ineligible for it.
In This Article
- What Does 32 CFR 170.21 Actually Say About POA&Ms?
- Which Controls Can Never Go on a POA&M at Level 2?
- Why Do 5 Point Requirements Dominate the Ineligible List?
- What Happens After a POA&M Is Issued, and How Long Do You Actually Have?
- Does the Phase 2 Suspension Change Any of This?
- How Should You Use POA&M Rules in Your Readiness Planning?
- Frequently Asked Questions
If you are planning to walk into an assessment with twelve open gaps and a tidy remediation schedule, the rule may not let you convert that into a passing outcome. What matters is not how many gaps you have. It is which ones.
What Does 32 CFR 170.21 Actually Say About POA&Ms?
Section 170.21 establishes when a POA&M is permitted and what happens after one is issued. The structure is straightforward once you separate it by level.
At Level 1 self-assessment, a POA&M is not permitted at all. Every one of the fifteen basic safeguarding requirements derived from FAR 52.204-21 must be MET at the time you affirm. There is no conditional status at Level 1. You either meet all of them or you do not have a Level 1 status.
At Level 2, whether self-assessment or certification assessment by a C3PAO, a POA&M is permitted only if three conditions are satisfied simultaneously. Fail any one and the result is not a conditional pass, it is a failed assessment.
At Level 3, a POA&M is likewise permitted only within limits, and it sits on top of an already achieved Final Level 2 certification status. Level 3 also carries its own set of requirements that cannot be deferred.
The operative concept in all cases is Conditional CMMC Status. A POA&M does not give you a certification. It gives you a time boxed conditional status that must be converted into a Final CMMC Status through a closeout assessment.
Which Controls Can Never Go on a POA&M at Level 2?
This is the part that catches organizations off guard. The eligibility test at Level 2 keys off the point values in the DoD Assessment Methodology, the same scoring model behind your SPRS score.
Three filters apply:
1. Point value. Requirements weighted at 5 points and 3 points in the DoD Assessment Methodology must be MET. They cannot be carried on a POA&M. Because the majority of the 110 Level 2 requirements are 5 point requirements, this filter alone removes most of the requirement set from POA&M eligibility. Practically, only 1 point requirements are candidates.
2. Specific 1 point exclusions. Being a 1 point requirement is necessary but not sufficient. The rule names a set of 1 point requirements that are still ineligible:
- AC.L2-3.1.20, External Connections
- AC.L2-3.1.22, Control Public Information
- PE.L2-3.10.3, Escort Visitors
- PE.L2-3.10.4, Physical Access Logs
- PE.L2-3.10.5, Manage Physical Access
Note the pattern. Three of the five are physical protection controls. These are cheap to implement and hard to justify deferring, which is likely why they were carved out. If your visitor escort procedure is undocumented on assessment day, that is a failure, not a POA&M item.
3. The 80 percent floor. The number of requirements assessed as MET, divided by the total number of requirements in scope, must be at least 0.8. For a full Level 2 scope of 110 requirements, that arithmetic means at least 88 MET. Sitting at 87 with a beautiful remediation plan does not produce a conditional status.
Read those three filters together and the honest summary is this: a POA&M at Level 2 is for a handful of low weight, non excluded gaps. It is not a bridge across a materially incomplete program.
Why Do 5 Point Requirements Dominate the Ineligible List?
The DoD Assessment Methodology assigns weights based on the impact of non implementation on the confidentiality of CUI. A 5 point weighting signals that the absence of the control creates broad exposure rather than a localized one.
Consider the categories that tend to carry heavy weight: access enforcement and least privilege under AC.L2-3.1.1 and AC.L2-3.1.2, multifactor authentication under IA.L2-3.5.3, boundary protection under SC.L2-3.13.1, and cryptographic protection of CUI under SC.L2-3.13.11. These are the load bearing walls of a CUI enclave. A remediation plan for a load bearing wall is not a compensating position, it is an admission that the enclave does not yet exist as designed.
SC.L2-3.13.11 deserves a specific mention because it generates more assessment disputes than almost any other control. FIPS validated cryptography means validated, with a certificate, in the approved operating configuration. Encryption that is strong but not validated does not satisfy the requirement as written. Confirm module validation status before assessment, not during it.
If you are uncertain about the exact point value of a given requirement in your scope, pull the current DoD Assessment Methodology and check it directly rather than relying on a summary. Point values are the input to the eligibility test, so getting them wrong changes your entire risk picture.
What Happens After a POA&M Is Issued, and How Long Do You Actually Have?
You receive a Conditional CMMC Status. Under 32 CFR 170.21, the POA&M must be closed out through a POA&M closeout assessment within 180 days of the Conditional CMMC Status date. That is a hard boundary, not a target.
Three consequences follow that organizations consistently underestimate:
The clock starts at conditional status, not at closeout. The three year validity period of the CMMC Status runs from the Conditional CMMC Status date. Spending 170 of your 180 days remediating does not buy you extra time on the back end. It burns roughly six months of a three year status.
Failure to close out means you have no status. If the closeout assessment is not successfully completed inside the window, the Conditional CMMC Status expires. You do not fall back to a lesser status. You return to having none, with whatever contractual consequences that carries under your DFARS clauses.
Closeout requires an assessment, not an attestation. For a Level 2 certification assessment, the closeout is performed by a C3PAO against the specific open requirements. Coordinate scheduling at the time the POA&M is issued, not at day 150. Assessor availability is a real constraint, and the recent surge of C3PAO focused market commentary is a reasonable signal that capacity planning matters. Confirm closeout scheduling terms in your engagement letter before you sign it.
A new affirmation in SPRS is required once the POA&M is closed and Final CMMC Status is achieved. Track that as a distinct deliverable, because it is separate from the assessment itself.
Does the Phase 2 Suspension Change Any of This?
No, and this is the point most worth internalizing right now.
Reporting in the past week noted a survey of 273 defense contractors showing continued compliance activity despite the suspension of Phase 2 assessments. That mix of reported activity and reported unpreparedness is consistent with what we observe: organizations are working, but many are working on the wrong things.
The status of the phased rollout is a matter of implementation timing. It is not settled, and we will not predict when certification requirements resume or how the schedule will be adjusted. What is settled is the substance. The requirements in 32 CFR Part 170, including the POA&M eligibility rules in 170.21, remain the published standard. Separately, DFARS 252.204-7012 and the NIST SP 800-171 obligations attached to it have applied to contractors handling CUI for years, independent of the CMMC program's rollout phase.
The useful way to spend a suspension is closing the gaps that can never be deferred. Those are exactly the ones that no schedule change will help you with.
How Should You Use POA&M Rules in Your Readiness Planning?
Invert the usual approach. Do not build a gap list and then decide what to POA&M. Build the ineligible list first and treat it as your gate.
A workable sequence:
- Lock scope. Requirement counts and the 80 percent calculation depend on what is in scope. Scoping errors distort every number downstream.
- Score against the DoD Assessment Methodology. Identify every 5 point and 3 point requirement that is not fully MET. That is your must fix list, non negotiable.
- Add the five named 1 point exclusions. AC.L2-3.1.20, AC.L2-3.1.22, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5. Verify these with evidence, not with a policy document that describes an intention.
- Check the 80 percent floor. Count MET requirements against total in scope requirements. If you are below 0.8, a POA&M does not help you.
- Only then consider what remains. Whatever is left is your legitimate POA&M candidate pool, and it should be small.
- Pressure test the 180 days. For each candidate, ask whether it can genuinely be remediated, evidenced, and assessed inside the window given procurement lead times and assessor availability.
If step 6 produces an honest “probably not,” fix it before assessment rather than after. A POA&M you cannot close is worse than no assessment date at all, because it consumes six months of a three year status and ends with nothing.
If you have not settled the base categories yet, start with our guide to scoping CUI assets versus Security Protection Assets, and our breakdown of what your SSP needs to contain, before you build out your POA&M candidate list.
Not Sure Which of Your Gaps Are POA&M Eligible?
Bring your current requirement by requirement scoring to CMMC Ready Now. Book a free 30-minute call with Rick and get a clear read on which gaps are POA&M eligible and which are hard stops under 32 CFR 170.21.
Book a Free Call with RickFrequently Asked Questions
Can you use a POA&M for CMMC Level 1?
No. Under 32 CFR 170.21, POA&Ms are not permitted at Level 1. All fifteen basic safeguarding requirements derived from FAR 52.204-21 must be assessed as MET before you can affirm a Level 1 self-assessment status. There is no conditional status at Level 1.
Which specific CMMC Level 2 controls can never be on a POA&M?
Every requirement weighted at 5 points or 3 points in the DoD Assessment Methodology must be MET, plus five specifically named 1 point requirements: AC.L2-3.1.20 External Connections, AC.L2-3.1.22 Control Public Information, PE.L2-3.10.3 Escort Visitors, PE.L2-3.10.4 Physical Access Logs, and PE.L2-3.10.5 Manage Physical Access. Because most of the 110 Level 2 requirements are 5 point requirements, POA&M eligibility is limited to a narrow set of remaining 1 point items.
What is the 80 percent rule for CMMC POA&Ms?
For a POA&M to be permitted at Level 2, the number of requirements assessed as MET divided by the total number of in scope requirements must be at least 0.8. For a full 110 requirement scope, that means at least 88 requirements MET. Falling below that threshold results in a failed assessment rather than a Conditional CMMC Status.
How long do you have to close out a CMMC POA&M?
The POA&M closeout assessment must be completed within 180 days of the Conditional CMMC Status date. If it is not completed successfully within that window, the Conditional CMMC Status expires and the organization no longer holds a CMMC Status. The three year validity period also runs from the conditional date, not from the closeout date.
Does a POA&M count as being CMMC certified?
Not fully. A POA&M produces a Conditional CMMC Status, which is time limited and contingent on successful closeout. Final CMMC Status is only achieved after the closeout assessment confirms the open requirements are MET and a new affirmation is submitted in SPRS.
Does the suspension of Phase 2 assessments change the POA&M rules?
No. The eligibility rules in 32 CFR 170.21 are part of the published rule and are unaffected by rollout timing. Rollout timing itself is not settled, so treat any specific certification date you are given as an estimate. Meanwhile, obligations under DFARS 252.204-7012 and NIST SP 800-171 continue to apply to contractors handling CUI independent of the CMMC phase schedule.
Sources
- 32 CFR Part 170, § 170.21, Plan of Action and Milestones requirements. CMMC Program final rule published in the Federal Register on October 15, 2024 (ecfr.gov)
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)
- DoD Assessment Methodology, NIST SP 800-171, source for the 5, 3, and 1 point requirement weightings (dodcio.defense.gov)
- MeriTalk, “Report Finds Defense Contractors Unprepared for CMMC Compliance”, referenced for the reported survey of 273 defense contractors and the noted Phase 2 suspension (meritalk.com)
