CMMC Ready Now
Compliance Guide

The Five-Point Controls You Cannot POA&M

A Level 2 assessment can be scored well above the minimum and still fail. That happens when a requirement weighted at five points in the DoD Assessment Methodology comes back NOT MET, because the CMMC Program rule at 32 CFR 170.21 does not allow those requirements onto a Plan of Action and Milestones.

Most contractors budget remediation around the score. The score is only half of the gate. The other half is a categorical list of requirements that have to be MET on assessment day, and the heaviest weighted ones sit at the center of it.

Diagram showing an assessment result splitting into two branches: POA&M eligible one-point gaps leading to Conditional status, versus a five-point NOT MET result leading to assessment failure.
A single five-point NOT MET result blocks Conditional CMMC Status, regardless of overall score.

What Does “Five-Point Control” Actually Mean?

The NIST SP 800-171 DoD Assessment Methodology assigns each of the 110 security requirements a weight of 5, 3, or 1. You start at 110 and subtract the weight of every requirement that is not implemented. A five-point weight means DoD judged that the absence of that requirement is likely to result in significant exploitation of the network or exfiltration of CUI. It is a severity ranking, not a difficulty ranking, which is why some five-point requirements are cheap to satisfy and easy to overlook.

Two scoring facts follow from this. First, five-point requirements dominate the arithmetic, so a handful of them can drop you below the floor by themselves. Second, and more important, weight determines POA&M eligibility. That is the part people miss.

Why Can a Five-Point Gap Fail an Assessment That Scores Above 88?

Conditional CMMC Status under 32 CFR 170.21 has two conditions, not one. The assessment score must meet the minimum threshold, which for Level 2 is 88 of 110, and every requirement that the rule declares POA&M ineligible must be MET. Fail the second condition and the score does not rescue you.

The rule builds POA&M eligibility off the point values. One-point requirements are the POA&M-eligible population. Requirements weighted above one point are, with narrow carve outs described below, ineligible. So a company at 96 of 110 with a NOT MET on a five-point requirement such as SC.L2-3.13.1 (boundary protection) does not receive Conditional status, while a company at 88 of 110 built entirely from one-point gaps does. Same assessment window, different outcomes, driven by which requirements failed rather than how many.

If you do reach Conditional status, the POA&M closeout assessment has to be completed within 180 days of the Conditional status date. Nothing on that plan can be a five-point item, which means the 180-day runway is not available to you for your most serious gaps.

Which Requirements Carry Five Points?

Verify every point value against Annex A of the DoD Assessment Methodology before you plan around it. Do not rely on a secondhand list, including this one. What is useful here is the pattern, because the five-point requirements cluster in predictable places:

  • Access control and identification. AC.L2-3.1.1 and AC.L2-3.1.2, the two foundational authorization requirements, plus the remote access and wireless requirements in the 3.1 family. IA.L2-3.5.1 and IA.L2-3.5.2, identify and authenticate users.
  • Boundary and network defense. SC.L2-3.13.1 (monitor and control communications at boundaries), SC.L2-3.13.5 (subnetworks for publicly accessible components).
  • Configuration management. CM.L2-3.4.1 and CM.L2-3.4.2 (baseline configurations and security configuration settings), CM.L2-3.4.6 (least functionality), CM.L2-3.4.7 (restrict nonessential programs, ports and services).
  • Malicious code and flaw remediation. SI.L2-3.14.1 (identify, report and correct flaws), SI.L2-3.14.2 and SI.L2-3.14.4 (malicious code protection and its updates).
  • Incident response. IR.L2-3.6.1 and IR.L2-3.6.2 (operational incident handling, and tracking and reporting).
  • Media protection. MP.L2-3.8.3 (sanitize or destroy media containing CUI).
  • Vulnerability and control assessment. RA.L2-3.11.2 (scan for vulnerabilities), CA.L2-3.12.1 and CA.L2-3.12.3 (assess and monitor controls).

Read that list as a description of a functioning security program rather than a checklist. Boundary defined, users identified and authenticated, systems configured to a baseline, malware handled, flaws patched, incidents reported, media destroyed properly. If any one of those is missing on assessment day, no amount of documentation elsewhere compensates.

What About Multifactor Authentication and FIPS Validated Cryptography?

These two are the exception worth understanding precisely, and they are also the two most commonly misread.

IA.L2-3.5.3 (multifactor authentication) and SC.L2-3.13.11 (FIPS validated cryptography for CUI) are five-point requirements that carry a partial credit provision in the DoD Assessment Methodology. Partial implementation, for example MFA on remote and privileged accounts but not general users, or encryption deployed but not FIPS validated, results in a partial deduction rather than the full five. The CMMC Program rule treats these specific partial situations differently from a flat NOT MET.

Read the exact language at 32 CFR 170.21 before you rely on this, and have your C3PAO confirm how they will score it. The direction of travel is unambiguous regardless: a partial credit path is not a plan, and non FIPS validated encryption of CUI is a finding you should close before an assessor arrives, not one you should be negotiating during it.

How Do You Prove a Five-Point Control Is MET Rather Than Mostly Met?

CMMC assessments are conducted against the assessment objectives in NIST SP 800-171A, not against the one-sentence requirement text. CM.L2-3.4.1 is not “we have a baseline.” It decomposes into objectives covering baseline establishment, the inventory it rests on, and its maintenance throughout the system development life cycle. Every objective must be MET for the requirement to be MET. One unmet objective makes the whole requirement NOT MET, and on a five-point requirement that is a disqualifying result rather than a five-point deduction.

Practical consequence for your self-assessment: score at the objective level and be honest about evidence. For each five-point requirement, ask what artifact an assessor would examine, who they would interview, and what they would test. If the answer for any objective is a policy document and nothing else, treat that requirement as NOT MET today.

The other prerequisite is the system security plan, CA.L2-3.12.4. An assessment against an incomplete or inaccurate SSP tends to unravel quickly, because the SSP defines the scope and the implementation statements the assessor is validating. Get the boundary and the CUI data flow right in the SSP first, then work the five-point list inside that boundary.

Does Any of This Apply at CMMC Level 1?

Yes, and more strictly in one respect. Level 1 covers the 15 basic safeguarding requirements from FAR 52.204-21 applied to Federal Contract Information, and POA&Ms are not permitted at Level 1 at all. Every requirement must be MET for a passing Level 1 self-assessment, with an annual affirmation in SPRS by a senior official.

There is no point weighting at Level 1 because there is nothing to weigh. The Level 1 population is effectively an all-or-nothing set, which is the same discipline the five-point requirements impose on Level 2, applied to the entire list.

If you have not settled the scoring basics yet, start with our breakdown of POA&M rules under 32 CFR 170.21, and our guide to what your SSP needs to contain, before you plan your remediation around the score alone.

Want to Know Which of Your Five-Point Requirements Would Fail Today?

Bring your current requirement by requirement scoring to CMMC Ready Now. Book a free 30-minute call with Rick and get a clear read on which gaps are POA&M eligible and which are hard stops under 32 CFR 170.21.

Book a Free Call with Rick

Frequently Asked Questions

What is a five-point control in CMMC?

It is a NIST SP 800-171 requirement assigned a weight of five in the DoD Assessment Methodology, meaning its absence is judged likely to lead to significant exploitation of the network or exfiltration of CUI. Scoring starts at 110 and subtracts the weight of each unimplemented requirement. Requirements weighted above one point are generally not eligible for a POA&M under 32 CFR 170.21.

Can a five-point requirement go on a POA&M?

No, other than the narrow partial credit provisions the rule recognizes for IA.L2-3.5.3 and SC.L2-3.13.11. POA&M eligibility under 32 CFR 170.21 is built around one-point requirements. A NOT MET result on a five-point requirement prevents Conditional CMMC Status regardless of the total score.

What score do I need for Conditional Level 2 status?

A minimum of 88 out of 110, and every POA&M ineligible requirement must be MET. Both conditions apply together. Scoring 100 does not help if a POA&M ineligible requirement failed.

How long do I have to close a POA&M?

The closeout assessment must be completed within 180 days of the Conditional CMMC Status date. Since five-point requirements cannot be on the plan, that window applies only to lower weighted gaps. Missing the window means the Conditional status expires.

Does partial implementation count as MET?

No. Assessment is conducted against the objectives in NIST SP 800-171A, and every objective within a requirement must be MET for the requirement to be MET. Partial implementation produces a NOT MET result, with the limited partial credit scoring exceptions noted in the DoD Assessment Methodology.

When will my contracts actually require a Level 2 certification?

The phase in schedule is not settled and should not be treated as fixed while Phase 2 remains suspended. What is stable is the technical standard: the requirements, the scoring methodology and the POA&M rules are published and are what an assessment will measure. Build to the standard rather than to a date.

Sources

  • 32 CFR Part 170, CMMC Program final rule, specifically § 170.21 (Plan of Action and Milestones requirements) and § 170.24 (CMMC status definitions) (ecfr.gov)
  • NIST SP 800-171 DoD Assessment Methodology, Annex A (requirement point values and partial credit provisions) (dodcio.defense.gov)
  • NIST SP 800-171 Rev. 2, security requirements for protecting CUI in nonfederal systems (csrc.nist.gov)
  • NIST SP 800-171A, assessment objectives and procedures
  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (Level 1 requirements) (acquisition.gov)
  • CMMC Assessment Guide, Level 2