CMMC Ready Now
Back to Knowledge Center
Documentation5 min read

Plan of Action & Milestones (POA&M): Structure and Rules

The POA&M documents gaps that remain open after assessment and tracks their remediation. CMMC 2.0 allows POA&Ms for conditional certification, but limits which controls qualify.

The Plan of Action and Milestones (POA&M) is required by NIST SP 800-171 control 3.12.2. It documents security weaknesses in organizational systems and tracks the resources, responsible parties, and scheduled dates for remediation.

Required elements of a POA&M entry

  • Control identifier (e.g., AC.L2-3.1.2)
  • Description of the weakness or gap
  • Responsible party (person or team accountable for remediation)
  • Resources required (budget, technology, staff time)
  • Planned completion date (milestone date)
  • Current status and progress notes

CMMC 2.0 POA&M rules

  • Must not be in the categories designated as “must be satisfied” (MFA, encryption, incident response)
  • Must be closed within 180 days of the conditional certification date
  • Must have a point value below the DoD-specified threshold

POA&M vs. SPRS score

Open POA&M items do NOT mean your SPRS score is 110. Your SPRS score reflects your current implementation state. The POA&M tracks the path to closure; the SPRS score tracks your actual posture.

Managing your POA&M effectively

A POA&M that no one updates is a liability. Assessors look at whether POA&M items are making progress, whether dates are realistic, and whether closure evidence exists. GRC platforms or a well-structured spreadsheet can help manage POA&M tracking for smaller organizations.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.