CMMC Plan of Action and Milestones
A CMMC POA&M is the document that lets you certify with open gaps, but only if those gaps are POA&M-eligible and the milestones are credible. Here is how to build one that holds up.
What a POA&M Is For
A Plan of Action and Milestones (POA&M) is the document that captures every NIST 800-171 practice you have not fully implemented, along with the plan to close each gap. Under CMMC Level 2, a properly structured POA&M unlocks conditional certification: you can pass the assessment with open items, as long as those items are eligible and the plan is credible.
The POA&M is not optional. Even companies at full implementation maintain one to track configuration drift and new gaps. It is a living document, not a one-time deliverable.
Read the CMMC framework reference for the full conditional certification rules. Some practices cannot be deferred and must be met before the C3PAO assessment.
Which Practices Can Go on a POA&M
Not every gap can be deferred. Under the conditional certification rules, only certain lower-weight practices are eligible. The DoD specifically excludes the highest-weight practices from POA&M deferral.
Practices that cannot be on a POA&M for conditional certification:
- 3.1.20: External system connections (verified and authorized)
- 3.1.22: Public information posting controls
- 3.5.3: Multi-factor authentication
- 3.13.11: FIPS-validated cryptography for CUI
Practices that can be on a POA&M include most of the 1-point and 3-point practices, plus a small number of 5-point practices in audit, configuration management, and risk assessment families.
Even POA&M-eligible practices have a 180-day clock. If you do not close them within 180 days of conditional certification, the certificate is revoked. Plan accordingly.
Building Credible Milestones
A POA&M item assessors accept has these fields, every time:
- Practice ID: The exact NIST 800-171 practice (e.g., 3.3.1)
- Gap description: What is missing, in concrete terms
- Resources required: Tooling, headcount, or budget needed
- Scheduled completion date: Specific date, not "Q4 2025"
- Milestones: At least three intermediate steps with dates
- Owner: A named individual, not "IT team"
- Status: Open, in progress, or closed
- Verification method: How you will prove closure
Vague milestones fail assessment. "Implement audit logging" is not a milestone. "Deploy SIEM agent to all 47 in-scope hosts by 2026-03-15" is.
Each milestone should be verifiable in evidence. If the milestone says "deploy MFA to admin accounts," the verification is a screenshot of the IdP showing MFA enforced for that group.
Review Cadence and Closure
Review the POA&M monthly. The review covers three things:
- Closed items: Verify the closure with evidence. Update the SSP narrative for the practice. Move the item to a closed log.
- Slipping items: If a milestone date passes without closure, document why and reset the date once. Repeated slips are a red flag for the next assessment.
- New items: Configuration drift, new systems, and acquisitions create new gaps. Add them to the POA&M as soon as they are identified.
Keep a closed-items log separate from the active POA&M. Assessors review the closed log to see how you handle remediation over time. A closed log with consistent closure within stated dates tells a strong story.
Pair the POA&M review with your monthly SPRS score recalculation. Closed POA&M items move from the POA&M state to the met state, which lifts your current score.
Common POA&M Mistakes
The same mistakes show up in pre-assessments across most companies. Avoid these and you will be in the top 20% of POA&M quality:
- Dates in the past: An item with a 2024-12-01 completion date that is still open in May 2025 fails immediately.
- Owner is a team, not a person: "Security team" is not accountable. "Priya Sharma, Director of Security" is.
- No milestones, just one date: A nine-month POA&M item with no intermediate milestones is not a plan. It is a wish.
- POA&M items not in the SSP: Every open POA&M item should be reflected in the SSP narrative for that practice. Inconsistency is what assessors hunt for.
- Including ineligible practices: Putting MFA or FIPS on a POA&M and submitting for conditional certification is an automatic fail.
Run the POA&M past a Registered Practitioner Organization before the C3PAO sees it.
Frequently Asked Questions
Related Articles
How to Calculate Your SPRS Score
The SPRS score starts at 110 and deducts weighted points for every practice you have not implemented. Here is how to calculate it correctly and what counts as fully implemented.
CMMC Level 2 Requirements
CMMC Level 2 covers 110 practices across 14 families, all aligned to NIST 800-171. Here is what your environment needs to satisfy and what assessors actually verify.
CMMC Conditional Certification Explained
Conditional certification lets you certify with open POA&M items, but only for 180 days. Here is what is eligible, how the closure process works, and the consequences of missing the deadline.