CMMC POA&M: what a Plan of Action and Milestones actually needs
The POA&M is the document that turns a list of gaps into a plan. It is also the one most template packs ship empty, which is why so many contractors have a polished System Security Plan and no record of what is missing.
Free preview before you pay. Editable Word files. 14 day refund.
What each entry needs
- An identifier, so the entry can be referenced in a meeting or an assessment.
- The control or controls the gap relates to, by their NIST SP 800-171 number.
- The weakness, stated plainly. "Multifactor authentication is not enforced for remote access" beats "authentication improvements required".
- The planned action, concrete enough that someone could start it tomorrow.
- A named owner. Not a department. A person.
- A target date the organization can actually meet.
- Status, and the date it changed.
Not every control may sit on a POA&M
Under the CMMC programme rule at 32 CFR Part 170, only certain requirements may remain open on a POA&M at the time of an assessment, there is a minimum score you must already meet, and open items carry a deadline to close. The heavily weighted requirements are generally not eligible.
The practical consequence: you cannot POA&M your way past the 5 point items. Confirm the current rule before you rely on an open entry to get through an assessment.
Write honest dates
A plan full of dates that have already slipped is worse evidence than a plan with fewer, realistic ones. Assessors read the review history, and a POA&M that has been revised openly reads as a live programme. One that has not been touched in a year reads as an abandoned document.
Closing an entry
An item closes when the control is implemented and there is evidence a third party could inspect: a screenshot of the enforced setting, a training record, a scan report, a destruction certificate. Keep that evidence after closing, because the question at assessment is not whether the row says closed, but what was done.
Where the entries should come from
Ideally from an assessment of all 110 requirements against NIST SP 800-171A. In practice most small contractors start from a shorter self review, then extend it. Either way the gaps belong in one document with owners and dates, not in an email thread.
Questions
Is a POA&M required?
A plan to correct deficiencies is expected, and CMMC sets conditions on what may remain open at assessment time. Practically, if you have gaps and no POA&M, you have nowhere to record them.
How many open items is too many?
There is no fixed number, but the programme rule limits which controls may be open and for how long, and sets a minimum score. Weight matters more than count.
Can I keep the POA&M in a spreadsheet?
Yes. The format is not prescribed. What matters is that every entry has a control reference, an owner, a date, and a status, and that it is kept current.
Who signs it?
The senior official who accepts the risk, usually alongside whoever runs security day to day.
Full CMMC Level 2 Documentation Kit, $249
- System Security Plan, written around your answers, with your boundary and roles
- SPRS Score Worksheet showing your estimated score and every deduction
- Plan of Action and Milestones, already filled in with your gaps
- CUI Security Policy Manual covering all 14 NIST SP 800-171 control families
- START HERE guide with the deadlines that catch people out
More guides
Templates, not legal advice. Eaglizer IT is not a C3PAO, a Registered Provider Organization, or a law firm, and does not certify compliance with CMMC or NIST SP 800-171. Documentation is a prerequisite for an assessment, not a substitute for one.