ZF/blog/cmmc-poam-guide
CMMC7 min readMay 8, 2025

CMMC Plan of Action and Milestones

A CMMC POA&M is the document that lets you certify with open gaps, but only if those gaps are POA&M-eligible and the milestones are credible. Here is how to build one that holds up.


What a POA&M Is For

A Plan of Action and Milestones (POA&M) is the document that captures every NIST 800-171 practice you have not fully implemented, along with the plan to close each gap. Under CMMC Level 2, a properly structured POA&M unlocks conditional certification: you can pass the assessment with open items, as long as those items are eligible and the plan is credible.

The POA&M is not optional. Even companies at full implementation maintain one to track configuration drift and new gaps. It is a living document, not a one-time deliverable.

Read the CMMC framework reference for the full conditional certification rules. Some practices cannot be deferred and must be met before the C3PAO assessment.

Which Practices Can Go on a POA&M

Not every gap can be deferred. Under the conditional certification rules, only certain lower-weight practices are eligible. The DoD specifically excludes the highest-weight practices from POA&M deferral.

Practices that cannot be on a POA&M for conditional certification:

  • 3.1.20: External system connections (verified and authorized)
  • 3.1.22: Public information posting controls
  • 3.5.3: Multi-factor authentication
  • 3.13.11: FIPS-validated cryptography for CUI

Practices that can be on a POA&M include most of the 1-point and 3-point practices, plus a small number of 5-point practices in audit, configuration management, and risk assessment families.

Even POA&M-eligible practices have a 180-day clock. If you do not close them within 180 days of conditional certification, the certificate is revoked. Plan accordingly.

Building Credible Milestones

A POA&M item assessors accept has these fields, every time:

  • Practice ID: The exact NIST 800-171 practice (e.g., 3.3.1)
  • Gap description: What is missing, in concrete terms
  • Resources required: Tooling, headcount, or budget needed
  • Scheduled completion date: Specific date, not "Q4 2025"
  • Milestones: At least three intermediate steps with dates
  • Owner: A named individual, not "IT team"
  • Status: Open, in progress, or closed
  • Verification method: How you will prove closure

Vague milestones fail assessment. "Implement audit logging" is not a milestone. "Deploy SIEM agent to all 47 in-scope hosts by 2026-03-15" is.

Each milestone should be verifiable in evidence. If the milestone says "deploy MFA to admin accounts," the verification is a screenshot of the IdP showing MFA enforced for that group.

Review Cadence and Closure

Review the POA&M monthly. The review covers three things:

  1. Closed items: Verify the closure with evidence. Update the SSP narrative for the practice. Move the item to a closed log.
  2. Slipping items: If a milestone date passes without closure, document why and reset the date once. Repeated slips are a red flag for the next assessment.
  3. New items: Configuration drift, new systems, and acquisitions create new gaps. Add them to the POA&M as soon as they are identified.

Keep a closed-items log separate from the active POA&M. Assessors review the closed log to see how you handle remediation over time. A closed log with consistent closure within stated dates tells a strong story.

Pair the POA&M review with your monthly SPRS score recalculation. Closed POA&M items move from the POA&M state to the met state, which lifts your current score.

Common POA&M Mistakes

The same mistakes show up in pre-assessments across most companies. Avoid these and you will be in the top 20% of POA&M quality:

  • Dates in the past: An item with a 2024-12-01 completion date that is still open in May 2025 fails immediately.
  • Owner is a team, not a person: "Security team" is not accountable. "Priya Sharma, Director of Security" is.
  • No milestones, just one date: A nine-month POA&M item with no intermediate milestones is not a plan. It is a wish.
  • POA&M items not in the SSP: Every open POA&M item should be reflected in the SSP narrative for that practice. Inconsistency is what assessors hunt for.
  • Including ineligible practices: Putting MFA or FIPS on a POA&M and submitting for conditional certification is an automatic fail.

Run the POA&M past a Registered Practitioner Organization before the C3PAO sees it.

Frequently Asked Questions

CMMCPOA&MRemediationConditional Certification

Related Articles