Agent Registry·Assessment·POA&M Advisor
Assessmentclaude-sonnet-4-6Open source · Free to copy

POA&M Advisor

Reviews POA&M items, scores remediation priority, flags certification blockers.

Reads your Plan of Action and Milestones, evaluates each open item against SPRS impact weights and framework POA&M eligibility rules, and produces a prioritized remediation schedule with milestone dates and owner assignments.

Tools:readgrep
Frameworks:CMMC L2FedRAMPNIST 800-171RMF
Use case 1
Inherited a POA&M from a prior assessor and need to know what is actually open vs noise
Cleaned register with duplicates merged, completed items closed, and remaining items ranked by certification-blocker risk
Use case 2
Pre-submission POA&M eligibility check before sending to your assessor
Flag of non-POAMable items per framework guidance (CMMC, FedRAMP, RMF) that cannot ship as POA&M items and must be closed first
Use case 3
Quarterly POA&M review for FedRAMP ConMon submission
Items past due date highlighted, milestone re-baselines proposed with risk memos, and SPRS-equivalent score deltas calculated

Try a sample prompt:

poam-advisor · live demo · gemini-flash
◇ Curated sample output (real format)

POA&M Triage · 2026-05-09

Input: 47 open items · FedRAMP Moderate baseline

Output: 6 blockers · 14 high-risk · 22 routine · 5 closable today


Certification Blockers (cannot ship as POA&M)

Three items are POA&M-INELIGIBLE per FedRAMP PMO guidance. Must close before re-assessment.

POAM-0023 · IA-2(1) Multi-Factor Authentication

Why ineligible: FedRAMP PMO explicitly prohibits POA&M for IA-2(1) at Moderate baseline.

Days open: 142 · Severity: Critical

Required action: Implement MFA for ALL privileged network access before next ConMon submission. Provide updated SSP §IA-2(1) narrative and evidence (Okta/Duo/Yubikey config screenshots + test).

POAM-0031 · CP-9 Information System Backup

Why ineligible: Foundational availability control. PMO requires implementation before authorization.

Days open: 89 · Severity: High

Required action: Implement backup process with documented procedure, schedule, and recent test. SSP §CP-9 narrative + AWS Backup config + last successful test record.

POAM-0042 · IR-4 Incident Handling

Why ineligible: IR plan is a precondition for authorization, not POA&Mable.

Days open: 167 · Severity: High


High-Risk Items (POA&M-eligible, past milestone)

IDControlDays Past DueSPRS ImpactRecommended Action
POAM-0008AU-6(1)28−3Re-baseline to 90 days; assign new owner
POAM-0015SC-7(8)41−5Architectural change required; convert to project
POAM-0019CM-8(3)12−2Vendor delay — request 30-day extension with risk memo
POAM-0028RA-567−5Replace scanner contract; escalate to CISO

Closable Today (evidence already exists)

Five items show implementation complete in evidence but milestone never updated.

- POAM-0003 (AC-7) · Account lockout config present in /evidence/m365-conditional-access.png

- POAM-0011 (AU-2(3)) · Log review automation in place; needs procedure doc

- POAM-0017 (CM-6) · Baseline now via AWS Config Conformance Pack

- POAM-0025 (PE-3) · Badge system fully deployed Q4 last year

- POAM-0044 (SI-4) · GuardDuty + Sentinel both live

Action: Update milestone status to "Closed — Implementation Verified" with linked evidence artifact in each.

Duplicates Detected

POAM-0006, POAM-0009, POAM-0014 all map to AC-2(1). Reviewed against control text:

- POAM-0006 addresses [a] account establishment — KEEP

- POAM-0009 addresses [c] account modification — MERGE INTO POAM-0006 (subset)

- POAM-0014 addresses [d] account disablement — KEEP DISTINCT (different process owner)

Submission Readiness

After closure of 5 + merge of 1 + remediation of 3 critical blockers, POA&M count would drop from 47 → 38. SPRS-equivalent would move from 71 → 84.

Cmd+Enter to send