What is a Plan of Action and Milestones?

A Plan of Action and Milestones (POA&M) is the record of a security requirement that is not yet implemented: what the gap is, what will be done to close it, who owns the work, and the date it will be finished.

Its whole purpose is to say "this one is not done yet," in writing, with a commitment attached.

Open requirement → Corrective action → Evidence of closure
Open requirement → Corrective action → Evidence of closure

What a POA&M entry contains

Field What it records
The requirement The specific control or requirement not met, by its identifier
The weakness What is actually missing or inadequate, in plain terms
Planned remediation The work that will close it
Resources required What it will take
Owner A named person or role accountable for the work
Scheduled completion date When it will be finished
Milestones Interim checkpoints, with dates
Status Open, in progress, or completed, with the date

A POA&M entry with no owner and no date is a list item, not a plan, and an assessor will read it that way.

POA&M in the NIST SP 800-171 self-assessment

Under the NIST SP 800-171 DoD Assessment Methodology, a requirement that is not implemented costs points against a starting score of 110. A POA&M is how you document the gap you just scored against yourself.

The methodology is binary on implementation. A requirement is implemented or it is not. "In progress" scores as not implemented, and the POA&M is where the progress is recorded instead. See the NIST SP 800-171 self-assessment and your Supplier Performance Risk System (SPRS) score.

POA&M in CMMC

CMMC allows a Conditional status when specific requirements are on a POA&M, subject to limits set in the rule: only certain requirements are eligible, the overall score must meet a minimum, and the gaps must be closed and verified within 180 days. Closing them produces a Final status. Failing to close them within the window means the Conditional status lapses.

This is why a Conditional CMMC Status carries a 180-day currency period while a Final Level 2 status is current for three years. See DFARS 252.204-7021 and CMMC Level 2.

What a POA&M is not

It is not a way to defer indefinitely. A date that moves every quarter is evidence of a process that is not working, and it reads worse than the original gap.

It is not a substitute for the control. The requirement is still unmet while the entry is open. Nothing about writing it down changes that.

It is not cover for a false statement. A score posted to SPRS is a representation to the government. An open POA&M that records the gap accurately supports that representation. One used to make an unimplemented requirement look implemented does the opposite, and the Department of Justice Civil Cyber-Fraud Initiative has pursued cases on exactly that fact pattern.

What the kit does

Item

  • Current State Compliance, a ledger of control findings with rescan, so an open item has a current state rather than a remembered one
  • Assessment Binder, a living evidence package shared by the assessor, the Managed Service Provider, and the Customer
  • Check workstations and servers against baselines, repair known settings with Fix-It, and flag what needs IT, so a finding has a route to closure
  • Assign documents to named people and collect a signed attestation
  • Decide remediation priority, assign owners, commit to dates, and accept the risk of what stays open

Common questions

Does a POA&M lower our SPRS score?

The unimplemented requirement lowers the score. The POA&M records what you intend to do about it. Writing one does not change the arithmetic.

How long can an item stay open?

Under CMMC, eligible POA&M items tied to a Conditional status must be closed and verified within 180 days. Outside that, the limit is what your contract and your own policy allow, and an item that is years old invites questions.

Who should own an entry?

A named person with the authority to get the work done. A team name is not an owner.

Can every requirement go on a POA&M?

No. CMMC limits which requirements are eligible, and some must be implemented outright. Check the rule for the requirement in question.

Related pages

Sources