compli.ai
From the blog

POA&M Template and How to Actually Manage One

What a POA&M is, what belongs in one, the fields that matter, closure discipline, and the CMMC Level 2 conditional-status rules on open POA&Ms.

A POA&M (Plan of Action and Milestones) is the document that lists the security requirements you have not yet met, with a concrete plan and dates to close each one. In the NIST 800-171 and CMMC world, it is the other half of your System Security Plan: the SSP says what you have done, the POA&M says what you still owe. Managed well, a POA&M is a credible remediation roadmap an assessor respects. Managed badly, it is a list of promises you keep rolling forward — and under CMMC, a stale POA&M can cost you an award.

This guide covers what belongs in a POA&M versus what does not, the fields that actually matter, the closure discipline that separates real programs from theater, and the CMMC Level 2 rules on open POA&Ms that most contractors get wrong.

What a POA&M is for

Every security program has gaps. The POA&M is how you manage them honestly instead of pretending they do not exist. It does three things:

  • Records each unmet requirement — which of your NIST 800-171 requirements are not fully implemented.
  • Commits to a fix — the specific actions, the owner, and the milestone dates to close each gap.
  • Feeds your SPRS score and assessment — open POA&M items are reflected in your self-assessment score, and a CMMC assessor uses the POA&M to understand what is deferred and why.

A POA&M is a living document. The point is not to have zero open items forever — it is to show that every open item has a plan, an owner, and a deadline, and that items actually close.

What belongs in a POA&M — and what does not

This is where Department of War (DoW) guidance and the CMMC rule get specific, and where contractors get burned. Not every requirement can sit on a POA&M.

Under CMMC, certain requirements are not POA&M-eligible, so you must fully meet them at assessment. Under 32 CFR 170.21, only 1-point requirements can go on a CMMC POA&M, with one exception: 3.13.11 when encryption is employed but not FIPS-validated. Six requirements are excluded outright, including the System Security Plan requirement (3.12.4). The rule also sets a minimum score threshold of at least 88 out of 110 for Level 2, so you cannot POA&M your way to Conditional status from a low score. In practice, the highest-weighted and most fundamental requirements have to be met. Trying to park a critical requirement on the POA&M is a fast way to fail.

Belongs on a POA&M:

  • 1-point requirements (and 3.13.11 under its non-FIPS condition) that you have a real, near-term plan to close.
  • Gaps that are POA&M-eligible under the CMMC rule and keep you above the minimum score threshold.
  • Items with a genuine owner, defined actions, and a realistic date.

Does NOT belong on a POA&M:

  • Requirements the CMMC rule marks as ineligible for deferral — these must be met.
  • Enough gaps to drop you below the minimum score threshold for conditional status (88 of 110 for Level 2).
  • Placeholder entries with no owner, no actions, and a date you have already blown past twice.
  • Anything you are using the POA&M to avoid doing rather than schedule doing.

Practitioner rule: A POA&M is a schedule, not a hiding place. If an item has been "in progress, target next quarter" for a year, an assessor reads it as a program that does not close things — which is worse than the gap itself.

The fields that actually matter

Templates vary, but a POA&M that holds up has these fields, and each one earns its place:

FieldWhy it matters
Requirement / control IDTies the gap to a specific NIST 800-171 requirement (e.g., 3.5.3). No orphan entries.
Weakness / gap descriptionWhat specifically is not met — in plain terms, not a restatement of the control.
Point value / score impactThe weighted deduction (1, 3, or 5) this gap costs your SPRS score. Drives prioritization.
Responsible party / ownerA named role or person accountable for closing it. "IT" is not an owner.
Planned remediation / milestonesThe concrete steps to close the gap, broken into checkpoints if it is large.
Scheduled completion dateA real date. This is the field assessors and the Department watch.
StatusOpen / in progress / completed — updated as work happens, not once a year.
Actual completion date + evidenceWhen it closed and the proof it closed. This is what turns "planned" into "done."

The two fields people fill in worst are owner and scheduled completion date — and those are exactly the two an assessor scrutinizes, because a gap with no owner and no date is not a plan.

Closure discipline: the part everyone skips

Writing a POA&M is easy. Closing items is where programs succeed or fail. Closure discipline means:

  1. Every open item gets worked, not just tracked. Review the POA&M on a fixed cadence (monthly is sensible), and every review either advances an item or explains why it slipped.
  2. Closure requires evidence. An item is not closed because someone says so. It is closed when the control is implemented and you have the artifact proving it — then you update the SSP to reflect that the requirement is now met.
  3. The SSP and POA&M stay in sync. When a POA&M item closes, the corresponding SSP entry moves from "planned" to "implemented." When a new gap appears, it opens on the POA&M. They are two views of one truth. Assessors cross-check them immediately.
  4. Dates are honest. If a date slips, change it deliberately and note why — do not let items silently blow past their deadline. A POA&M full of overdue items with untouched dates tells an assessor the program is not being run.

The CMMC Level 2 open-POA&M rules you cannot ignore

This is the highest-stakes section, and it is time-sensitive, so here is the current state. The Department's suspension of CMMC Phase 2 does not change these rules. They apply to Level 2 self-assessments as well as C3PAO assessments, and Phase 1 self-assessment requirements remain in effect.

Under the CMMC program rule (32 CFR 170.21), CMMC Levels 2 and 3 allow a conditional status when you have open, POA&M-eligible items — but with hard limits:

  • You can receive a contract award with a Conditional CMMC Status. An open POA&M does not automatically disqualify you, if the remaining gaps are POA&M-eligible and you meet the minimum score threshold (88 of 110 for Level 2).
  • You have 180 days to close everything on the POA&M. All requirements scored NOT MET and placed on the POA&M must be remediated within 180 days of your Conditional CMMC Status Date.
  • A POA&M closeout assessment verifies the fixes. A second, focused assessment confirms the open items are now met. Pass it, and your status converts to Final Level 2 (Self) or Final Level 2 (C3PAO).
  • Miss the 180 days and conditional status expires. If the items are not closed and verified in time, you lose the conditional status and become ineligible for contracts requiring that level.

Source: 32 CFR 170.21; DFARS 252.204-7021; Federal Register final rule (DFARS Case 2019-D041). The 180-day closeout and conditional-to-final mechanics are set in the CMMC rule.

The takeaway: a POA&M under CMMC is a 180-day clock, not an open-ended to-do list. Anything you defer, you have committed to closing, with proof, inside six months. That reality should shape what you are willing to put on the POA&M in the first place. For how the levels and assessment types differ, see our CMMC levels guide.

FAQ

What is a POA&M? A POA&M (Plan of Action and Milestones) is a document listing the security requirements an organization has not yet met, along with the specific actions, owners, and dates to close each gap. In NIST 800-171 and CMMC, it works alongside the SSP: the SSP records what is implemented, the POA&M records what is planned.

What does POA&M stand for? Plan of Action and Milestones. It is sometimes written "POAM" or "POA&M" and pronounced "po-am." In government and cybersecurity contexts it always refers to the remediation-tracking document for unmet security requirements.

How do I write a POA&M? Start from your assessment results: for each requirement scored NOT MET, create an entry with the control ID, a plain description of the gap, the point value, a named owner, concrete remediation steps with milestone dates, and a status. Then work the items on a fixed cadence and close each one with evidence. Using a POA&M template keeps the fields consistent so nothing gets dropped.

What is a POA&M in cyber security? It is the standard artifact for managing known security gaps under frameworks like NIST 800-171, CMMC, FedRAMP, and NIST 800-53. Rather than ignoring gaps, you document each one with a remediation plan and track it to closure. Assessors and authorizing officials use it to see what is deferred and to hold you to your commitments.

Can I get a contract with an open POA&M under CMMC? For CMMC Levels 2 and 3, yes. You can be awarded a contract with a Conditional CMMC Status if your open items are POA&M-eligible and you meet the minimum score threshold (88 of 110 for Level 2). But you must close every POA&M item and pass a closeout assessment within 180 days, or the conditional status expires. Some critical requirements cannot be placed on a POA&M at all and must be met before award.

What is the difference between an SSP and a POA&M? The SSP describes what you have implemented; the POA&M lists what you have not yet implemented, with a plan to fix it. They are two views of the same system and must agree with each other. When a POA&M item closes, the SSP is updated to show the requirement is now met.

Turn your POA&M into a closing machine

A POA&M is only as good as the closures behind it. The programs that pass are the ones where every open item has an owner, a real date, and a paper trail when it closes — and where the SSP and POA&M never drift apart. Under CMMC, that discipline is not optional: the 180-day clock makes closure a contractual deadline, not a good intention.

Book a demo and we will show you how Compli.ai checks 32 CFR 170.21 eligibility when you create each POA&M item, tracks milestones, owners, and vendor check-ins, records the actual completion date when an item closes, and runs the 180-day closeout countdown on the dashboard, all inside your own Microsoft 365 tenant. It is built by people who have managed these to closure under a live 180-day clock. For the fuller picture first, see our NIST 800-171 compliance guide, our SPRS score walkthrough, and weigh your options with CMMC compliance software.