Learn CMMC

POA&M management for CMMC: the plan of action and milestones

Not every requirement is met on day one. A plan of action and milestones records what is open, who owns it, and by when, and it is the artifact assessors read to judge whether a program is alive or on paper.

Key takeaways

  • The POA&M is a requirement in its own right (3.12.2) and the document assessors read to judge whether a program is alive.
  • Not everything can go on it. Five-point requirements cannot be deferred at assessment, and most three-point requirements cannot either.
  • A conditional certification gives 180 days to close every open item. There are no extensions.
  • Vague milestones are the most common failure. "Implement MFA on the VPN by 15 June" is a milestone; "improve access control" is not.

What a POA&M is

A plan of action and milestones is the formal record of identified weaknesses and how you will fix them. Requirement 3.12.2 asks for it. Each entry ties a specific gap to the requirement it fails, sets milestones with dates and owners, and estimates the cost to close it. It is your security improvement roadmap, and assessors read it closely.

POA&Ms in the assessment

Not every requirement has to be met to receive a certification. A limited number of eligible requirements may be open on a POA&M for a conditional result. The rules are strict:

  • 180 days. Every open item must be closed within 180 days of the conditional certification.
  • Eligibility. Requirements weighted five points cannot be deferred, and most three-point requirements cannot either. The weight of each requirement is on its page in the guide.
  • Count. Only a limited number of items may be open at once.

Miss the 180-day window and the conditional certification can be revoked, which means scheduling and paying for a full reassessment. Treat the window as a hard deadline, because it is one.

Anatomy of an entry

  • Weakness. The specific deficiency, tied to the requirement it fails. Be precise about what is missing.
  • Priority. By the risk the gap poses to CUI. Higher first.
  • Milestones. Discrete, measurable steps, each with a date and an owner.
  • Due date and cost. Completion inside the window, and a budget that covers tools, labour and services.
  • Status. Open, in progress, closed, and reopened if a later review finds the fix incomplete.
  • History. Comments and decisions. Assessors look for signs the document is managed, not filed.

In Bedrock CMMC

Every entry is linked to its requirement, with milestones, priority, owner, cost and full history. Closing an item updates the SPRS score and the dashboard on the spot. See the tracker.

Creating one that works

  1. Start from the self-assessment

    Every not-met finding from your self-assessment is a candidate entry.

  2. Tie each gap to its requirement

    "MFA not implemented for remote access" belongs to 3.5.3. Name it.

  3. Write milestones you can miss

    Evaluate solutions by 1 April. Deploy to the VPN by 15 April. Enable for all remote users by 1 May. If a milestone cannot be missed, it is not specific enough.

  4. Assign owners and budget

    Without a name nothing gets done. Without a budget remediation stalls at procurement.

  5. Order by risk

    Gaps that expose the most CUI get the earliest milestones.

  6. Review it monthly

    A POA&M is a living record. Update statuses and add comments as part of continuous monitoring.

The lifecycle

Open, then in progress, then closed. Closed items can be reopened when a later review or assessment finds the remediation incomplete, and the history of every change stays with the entry.

Common mistakes

  • Vague milestones. Assessors want measurable steps with dates.
  • Starting late. Organizations that do not begin remediation immediately after a conditional result run out of window.
  • Create and forget. An unmanaged POA&M signals an immature program.
  • Deferring ineligible requirements. Putting a five-point requirement on the POA&M produces a failed assessment, not a conditional one.
  • No budget. Tools, services and infrastructure cost money; unfunded milestones slip.

Questions people ask

What is a POA&M in CMMC?

The formal record of identified weaknesses and the plan to fix them, required by 3.12.2, with each gap tied to a requirement, milestones with dates, owners and cost estimates.

How long do I have to close items after a conditional certification?

180 days, with no extensions. Items still open after that can cost you the conditional certification and require a full reassessment.

Can every requirement go on a POA&M?

No. Five-point requirements cannot be deferred at assessment, and most three-point requirements cannot either. Check the weight on each requirement's page in the guide.

How does the POA&M affect my SPRS score?

Open items are not-met requirements, so each subtracts its weight of one, three or five points. Closing them and marking the requirements met raises the score.

Keep the proof, not just the plan.

Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.