Build my kit
HIPAA guide

CMMC POA&M: what a Plan of Action and Milestones actually needs

The POA&M is the document that turns a list of gaps into a plan. It is also the one most template packs ship empty, which is why so many contractors have a polished System Security Plan and no record of what is missing.

Free preview before you pay. Editable Word files. 14 day refund.

What each entry needs

Not every control may sit on a POA&M

Under the CMMC programme rule at 32 CFR Part 170, only certain requirements may remain open on a POA&M at the time of an assessment, there is a minimum score you must already meet, and open items carry a deadline to close. The heavily weighted requirements are generally not eligible.

The practical consequence: you cannot POA&M your way past the 5 point items. Confirm the current rule before you rely on an open entry to get through an assessment.

Write honest dates

A plan full of dates that have already slipped is worse evidence than a plan with fewer, realistic ones. Assessors read the review history, and a POA&M that has been revised openly reads as a live programme. One that has not been touched in a year reads as an abandoned document.

Closing an entry

An item closes when the control is implemented and there is evidence a third party could inspect: a screenshot of the enforced setting, a training record, a scan report, a destruction certificate. Keep that evidence after closing, because the question at assessment is not whether the row says closed, but what was done.

Where the entries should come from

Ideally from an assessment of all 110 requirements against NIST SP 800-171A. In practice most small contractors start from a shorter self review, then extend it. Either way the gaps belong in one document with owners and dates, not in an email thread.

Questions

Is a POA&M required?

A plan to correct deficiencies is expected, and CMMC sets conditions on what may remain open at assessment time. Practically, if you have gaps and no POA&M, you have nowhere to record them.

How many open items is too many?

There is no fixed number, but the programme rule limits which controls may be open and for how long, and sets a minimum score. Weight matters more than count.

Can I keep the POA&M in a spreadsheet?

Yes. The format is not prescribed. What matters is that every entry has a control reference, an owner, a date, and a status, and that it is kept current.

Who signs it?

The senior official who accepts the risk, usually alongside whoever runs security day to day.

More guides

Templates, not legal advice. Eaglizer IT is not a C3PAO, a Registered Provider Organization, or a law firm, and does not certify compliance with CMMC or NIST SP 800-171. Documentation is a prerequisite for an assessment, not a substitute for one.