What is a Plan of Action and Milestones?
A Plan of Action and Milestones (POA&M) is the record of a security requirement that is not yet implemented: what the gap is, what will be done to close it, who owns the work, and the date it will be finished.
Its whole purpose is to say "this one is not done yet," in writing, with a commitment attached.
What a POA&M entry contains
| Field | What it records |
|---|---|
| The requirement | The specific control or requirement not met, by its identifier |
| The weakness | What is actually missing or inadequate, in plain terms |
| Planned remediation | The work that will close it |
| Resources required | What it will take |
| Owner | A named person or role accountable for the work |
| Scheduled completion date | When it will be finished |
| Milestones | Interim checkpoints, with dates |
| Status | Open, in progress, or completed, with the date |
A POA&M entry with no owner and no date is a list item, not a plan, and an assessor will read it that way.
POA&M in the NIST SP 800-171 self-assessment
Under the NIST SP 800-171 DoD Assessment Methodology, a requirement that is not implemented costs points against a starting score of 110. A POA&M is how you document the gap you just scored against yourself.
The methodology is binary on implementation. A requirement is implemented or it is not. "In progress" scores as not implemented, and the POA&M is where the progress is recorded instead. See the NIST SP 800-171 self-assessment and your Supplier Performance Risk System (SPRS) score.
POA&M in CMMC
CMMC allows a Conditional status when specific requirements are on a POA&M, subject to limits set in the rule: only certain requirements are eligible, the overall score must meet a minimum, and the gaps must be closed and verified within 180 days. Closing them produces a Final status. Failing to close them within the window means the Conditional status lapses.
This is why a Conditional CMMC Status carries a 180-day currency period while a Final Level 2 status is current for three years. See DFARS 252.204-7021 and CMMC Level 2.
What a POA&M is not
It is not a way to defer indefinitely. A date that moves every quarter is evidence of a process that is not working, and it reads worse than the original gap.
It is not a substitute for the control. The requirement is still unmet while the entry is open. Nothing about writing it down changes that.
It is not cover for a false statement. A score posted to SPRS is a representation to the government. An open POA&M that records the gap accurately supports that representation. One used to make an unimplemented requirement look implemented does the opposite, and the Department of Justice Civil Cyber-Fraud Initiative has pursued cases on exactly that fact pattern.
What the kit does
Item
- Current State Compliance, a ledger of control findings with rescan, so an open item has a current state rather than a remembered one
- Assessment Binder, a living evidence package shared by the assessor, the Managed Service Provider, and the Customer
- Check workstations and servers against baselines, repair known settings with Fix-It, and flag what needs IT, so a finding has a route to closure
- Assign documents to named people and collect a signed attestation
- Decide remediation priority, assign owners, commit to dates, and accept the risk of what stays open
Common questions
Does a POA&M lower our SPRS score?
The unimplemented requirement lowers the score. The POA&M records what you intend to do about it. Writing one does not change the arithmetic.
How long can an item stay open?
Under CMMC, eligible POA&M items tied to a Conditional status must be closed and verified within 180 days. Outside that, the limit is what your contract and your own policy allow, and an item that is years old invites questions.
Who should own an entry?
A named person with the authority to get the work done. A team name is not an owner.
Can every requirement go on a POA&M?
No. CMMC limits which requirements are eligible, and some must be implemented outright. Check the rule for the requirement in question.
Related pages
- NIST SP 800-171 self-assessment
- Your SPRS score
- DFARS 252.204-7021
- CMMC Level 2 and CMMC Phase 2
- Continuous compliance
- What is Controlled Unclassified Information
- AIC CMMC Completeâ„¢ and pricing
- Glossary