What a POA&M is, what belongs in one, the fields that matter, closure discipline, and the CMMC Level 2 conditional-status rules on open POA&Ms.
A POA&M (Plan of Action and Milestones) is the document that lists the security requirements you have not yet met, with a concrete plan and dates to close each one. In the NIST 800-171 and CMMC world, it is the other half of your System Security Plan: the SSP says what you have done, the POA&M says what you still owe. Managed well, a POA&M is a credible remediation roadmap an assessor respects. Managed badly, it is a list of promises you keep rolling forward — and under CMMC, a stale POA&M can cost you an award.
This guide covers what belongs in a POA&M versus what does not, the fields that actually matter, the closure discipline that separates real programs from theater, and the CMMC Level 2 rules on open POA&Ms that most contractors get wrong.
Every security program has gaps. The POA&M is how you manage them honestly instead of pretending they do not exist. It does three things:
A POA&M is a living document. The point is not to have zero open items forever — it is to show that every open item has a plan, an owner, and a deadline, and that items actually close.
This is where Department of War (DoW) guidance and the CMMC rule get specific, and where contractors get burned. Not every requirement can sit on a POA&M.
Under CMMC, certain requirements are not POA&M-eligible, so you must fully meet them at assessment. Under 32 CFR 170.21, only 1-point requirements can go on a CMMC POA&M, with one exception: 3.13.11 when encryption is employed but not FIPS-validated. Six requirements are excluded outright, including the System Security Plan requirement (3.12.4). The rule also sets a minimum score threshold of at least 88 out of 110 for Level 2, so you cannot POA&M your way to Conditional status from a low score. In practice, the highest-weighted and most fundamental requirements have to be met. Trying to park a critical requirement on the POA&M is a fast way to fail.
Belongs on a POA&M:
Does NOT belong on a POA&M:
Practitioner rule: A POA&M is a schedule, not a hiding place. If an item has been "in progress, target next quarter" for a year, an assessor reads it as a program that does not close things — which is worse than the gap itself.
Templates vary, but a POA&M that holds up has these fields, and each one earns its place:
| Field | Why it matters |
|---|---|
| Requirement / control ID | Ties the gap to a specific NIST 800-171 requirement (e.g., 3.5.3). No orphan entries. |
| Weakness / gap description | What specifically is not met — in plain terms, not a restatement of the control. |
| Point value / score impact | The weighted deduction (1, 3, or 5) this gap costs your SPRS score. Drives prioritization. |
| Responsible party / owner | A named role or person accountable for closing it. "IT" is not an owner. |
| Planned remediation / milestones | The concrete steps to close the gap, broken into checkpoints if it is large. |
| Scheduled completion date | A real date. This is the field assessors and the Department watch. |
| Status | Open / in progress / completed — updated as work happens, not once a year. |
| Actual completion date + evidence | When it closed and the proof it closed. This is what turns "planned" into "done." |
The two fields people fill in worst are owner and scheduled completion date — and those are exactly the two an assessor scrutinizes, because a gap with no owner and no date is not a plan.
Writing a POA&M is easy. Closing items is where programs succeed or fail. Closure discipline means:
This is the highest-stakes section, and it is time-sensitive, so here is the current state. The Department's suspension of CMMC Phase 2 does not change these rules. They apply to Level 2 self-assessments as well as C3PAO assessments, and Phase 1 self-assessment requirements remain in effect.
Under the CMMC program rule (32 CFR 170.21), CMMC Levels 2 and 3 allow a conditional status when you have open, POA&M-eligible items — but with hard limits:
Source: 32 CFR 170.21; DFARS 252.204-7021; Federal Register final rule (DFARS Case 2019-D041). The 180-day closeout and conditional-to-final mechanics are set in the CMMC rule.
The takeaway: a POA&M under CMMC is a 180-day clock, not an open-ended to-do list. Anything you defer, you have committed to closing, with proof, inside six months. That reality should shape what you are willing to put on the POA&M in the first place. For how the levels and assessment types differ, see our CMMC levels guide.
What is a POA&M? A POA&M (Plan of Action and Milestones) is a document listing the security requirements an organization has not yet met, along with the specific actions, owners, and dates to close each gap. In NIST 800-171 and CMMC, it works alongside the SSP: the SSP records what is implemented, the POA&M records what is planned.
What does POA&M stand for? Plan of Action and Milestones. It is sometimes written "POAM" or "POA&M" and pronounced "po-am." In government and cybersecurity contexts it always refers to the remediation-tracking document for unmet security requirements.
How do I write a POA&M? Start from your assessment results: for each requirement scored NOT MET, create an entry with the control ID, a plain description of the gap, the point value, a named owner, concrete remediation steps with milestone dates, and a status. Then work the items on a fixed cadence and close each one with evidence. Using a POA&M template keeps the fields consistent so nothing gets dropped.
What is a POA&M in cyber security? It is the standard artifact for managing known security gaps under frameworks like NIST 800-171, CMMC, FedRAMP, and NIST 800-53. Rather than ignoring gaps, you document each one with a remediation plan and track it to closure. Assessors and authorizing officials use it to see what is deferred and to hold you to your commitments.
Can I get a contract with an open POA&M under CMMC? For CMMC Levels 2 and 3, yes. You can be awarded a contract with a Conditional CMMC Status if your open items are POA&M-eligible and you meet the minimum score threshold (88 of 110 for Level 2). But you must close every POA&M item and pass a closeout assessment within 180 days, or the conditional status expires. Some critical requirements cannot be placed on a POA&M at all and must be met before award.
What is the difference between an SSP and a POA&M? The SSP describes what you have implemented; the POA&M lists what you have not yet implemented, with a plan to fix it. They are two views of the same system and must agree with each other. When a POA&M item closes, the SSP is updated to show the requirement is now met.
A POA&M is only as good as the closures behind it. The programs that pass are the ones where every open item has an owner, a real date, and a paper trail when it closes — and where the SSP and POA&M never drift apart. Under CMMC, that discipline is not optional: the 180-day clock makes closure a contractual deadline, not a good intention.
Book a demo and we will show you how Compli.ai checks 32 CFR 170.21 eligibility when you create each POA&M item, tracks milestones, owners, and vendor check-ins, records the actual completion date when an item closes, and runs the 180-day closeout countdown on the dashboard, all inside your own Microsoft 365 tenant. It is built by people who have managed these to closure under a live 180-day clock. For the fuller picture first, see our NIST 800-171 compliance guide, our SPRS score walkthrough, and weigh your options with CMMC compliance software.