Plan of Action & Milestones (POA&M): Structure and Rules
The POA&M documents gaps that remain open after assessment and tracks their remediation. CMMC 2.0 allows POA&Ms for conditional certification, but limits which controls qualify.
The Plan of Action and Milestones (POA&M) is required by NIST SP 800-171 control 3.12.2. It documents security weaknesses in organizational systems and tracks the resources, responsible parties, and scheduled dates for remediation.
Required elements of a POA&M entry
- ✓Control identifier (e.g., AC.L2-3.1.2)
- ✓Description of the weakness or gap
- ✓Responsible party (person or team accountable for remediation)
- ✓Resources required (budget, technology, staff time)
- ✓Planned completion date (milestone date)
- ✓Current status and progress notes
CMMC 2.0 POA&M rules
- ✓Must not be in the categories designated as “must be satisfied” (MFA, encryption, incident response)
- ✓Must be closed within 180 days of the conditional certification date
- ✓Must have a point value below the DoD-specified threshold
POA&M vs. SPRS score
Managing your POA&M effectively
A POA&M that no one updates is a liability. Assessors look at whether POA&M items are making progress, whether dates are realistic, and whether closure evidence exists. GRC platforms or a well-structured spreadsheet can help manage POA&M tracking for smaller organizations.
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in Documentation
