CMMC POA&M Management Guide for Contractors

CMMC POA&M requirements

A CMMC Plan of Action and Milestones is not a blanket permission to postpone security work. For CMMC Level 2, only certain NOT MET requirements may be placed on an assessment POA&M, the assessment must still meet the conditional-status threshold, and every eligible item must be closed within 180 days of the Conditional CMMC Status Date.

The first action is therefore not to build a giant remediation spreadsheet. Identify your assessment level, calculate whether the unmet requirements are actually POA&M-eligible, and separate CMMC assessment POA&Ms from your ordinary security remediation backlog. A contractor that gets this distinction wrong can spend months fixing the right technical problems through the wrong compliance process.

There is also a significant 2026 update. As of August 2026, the Department of War has suspended the planned CMMC Phase II rollout, which had been scheduled for November 10, 2026. Phase I self-assessment requirements remain in place. Contractors should therefore manage current Level 2 self-assessment POA&Ms rigorously without assuming that an old Phase II certification timetable still applies.

CMMC POA&M requirements

What a CMMC POA&M Actually Does

A CMMC assessment POA&M provides a limited path from an assessment containing eligible NOT MET requirements to a Conditional CMMC Status. It does not change a NOT MET requirement into MET, waive the security requirement, or permanently reduce the required Level 2 score.

The governing rule defines a POA&M as a document identifying tasks to be accomplished, required resources, milestones, and scheduled completion dates. Under the current CMMC framework, contractors should use the 32 CFR 170.21 POA&M requirements as the eligibility gate rather than assuming every security deficiency can be deferred.

This creates an important distinction between two documents that may both be called a POA&M.

DocumentPurpose180-Day CMMC Deadline?
Operational plan of actionTracks weaknesses, vulnerabilities, corrective actions, and ongoing remediation under normal security operationsNo automatic CMMC 180-day rule
CMMC assessment POA&MTracks specifically eligible NOT MET assessment requirements while the organization holds Conditional CMMC StatusYes

The Department’s CMMC Level 2 Assessment Guide explicitly distinguishes the operational plan of action associated with CA.L2-3.12.2 from the assessment POA&M created under 32 CFR 170.21. Keeping them in separate registers is usually cleaner than trying to make one spreadsheet serve both purposes.

Which Level 2 Findings Can Go on a POA&M?

Level 2 does permit conditional status, but only after several gates are passed. The most useful way to manage this is to test eligibility before assigning owners or buying remediation tools.

Eligibility CheckWhat It MeansManagement Action
Assessment scoreScore divided by the 110 Level 2 requirements must be at least 0.8, which means a score of at least 88Recalculate the score before treating conditional status as available
Point valueRequirements worth more than 1 point generally cannot be deferredCheck the CMMC scoring value of every NOT MET item
Encryption exceptionSC.L2-3.13.11 may be eligible when encryption exists but is not FIPS-validated, despite the applicable 3-point deductionDocument the actual encryption implementation and validation gap precisely
Prohibited requirementsSix specifically identified Level 2 requirements cannot be placed on the conditional-status POA&MRemediate them before relying on conditional status
CloseoutAll assessment POA&M findings must be closed within 180 daysWork backward from the Conditional CMMC Status Date

The weighted score deserves attention. Level 2 does not simply count how many controls are missing. NOT MET requirements can deduct 1, 3, or 5 points under the CMMC scoring methodology. A short list containing high-value requirements can therefore destroy POA&M eligibility faster than a longer list of 1-point findings.

The six Level 2 requirements that cannot be deferred

Regardless of the overall score, an assessment POA&M for Conditional Level 2 cannot include the following requirements:

  • AC.L2-3.1.20 External Connections (CUI Data)
  • AC.L2-3.1.22 Control Public Information (CUI Data)
  • CA.L2-3.12.4 System Security Plan
  • PE.L2-3.10.3 Escort Visitors (CUI Data)
  • PE.L2-3.10.4 Physical Access Logs (CUI Data)
  • PE.L2-3.10.5 Manage Physical Access (CUI Data)

The System Security Plan requirement deserves particular care. An outdated or missing SSP is not a harmless documentation item that can simply be parked for later. The Level 2 scoring methodology treats an up-to-date SSP as necessary for completing the assessment.

CMMC POA&M requirements

What the 2026 Phase II Suspension Changes

As of August 2026, contractors should not plan around the previously announced November 10, 2026 transition to broad Level 2 C3PAO certification requirements. The Department states that CMMC implementation is paused in Phase I while the program is reviewed.

Current Phase I implementation focuses on Level 1 and Level 2 self-assessments. For CUI environments subject to a Level 2 self-assessment requirement, the organization conducts the assessment, submits the applicable results into SPRS, and completes the required affirmation. Eligible deficiencies may support Conditional Level 2 (Self) status, but the POA&M must still be closed within 180 days.

The suspension does not erase underlying obligations to protect CUI under applicable DFARS requirements. It also does not turn CMMC POA&Ms into indefinite exception records. The Department’s current CMMC program guidance states that Phase I self-assessment requirements remain in place and that Level 2 self-assessment POA&Ms remain subject to the 180-day closeout rule.

For procurement planning, read the actual solicitation and contract rather than relying on an old rollout chart. For compliance planning, keep remediating NIST SP 800-171 Revision 2 requirements. A policy pause is not a security-control pause.

Build a POA&M Tracker That Can Survive Closeout

A useful POA&M tracker should do more than show that someone intends to fix something. It should connect each finding to the remediation work, the evidence required to prove completion, and the person who can verify that the requirement is now MET.

The regulation does not require contractors to use a particular spreadsheet or compliance platform. The following fields are therefore a practical management model, not a claim that every column is independently mandated by CMMC.

FieldWhy It Matters
CMMC requirement IDPrevents a finding from becoming disconnected from the assessed requirement
Assessment findingRecords exactly what was NOT MET rather than a vague summary such as “access control issue”
Eligibility statusShows that the requirement passed the 32 CFR 170.21 POA&M eligibility test
Remediation ownerCreates one accountable owner rather than a department-sized cloud of responsibility
Corrective actionDefines the technical or procedural change required
Dependencies and resourcesExposes purchases, engineering work, vendor dependencies, or approvals that can delay remediation
MilestonesBreaks multi-week work into reviewable checkpoints
Internal target dateProvides a deadline earlier than the regulatory maximum
Evidence requiredIdentifies what will demonstrate implementation after remediation
Validation methodDefines how the team will test whether the corrected requirement is genuinely MET
SSP impactFlags whether diagrams, system boundaries, control descriptions, or other SSP content must change
Closeout statusSeparates remediation completed from evidence reviewed and formally closed

One column is deliberately missing: “percentage complete.” A control can be 90 percent deployed operationally and still fail an assessment objective. Track milestones for project management, but determine closeout by evidence against the applicable assessment objectives.

Manage the 180 Days as a Closeout Window, Not a Project Estimate

The regulation gives conditional status a maximum life of 180 days. Treating day 180 as the internal remediation deadline leaves no room for failed testing, evidence corrections, executive review, submission problems, or a closeout assessment.

A safer management sequence is to reserve the final portion of the window for validation and administrative closeout.

  1. Confirm the status date. Record the actual Conditional CMMC Status Date rather than calculating from an internal kickoff meeting.
  2. Freeze the authoritative finding list. Every assessment POA&M item should map to an actual NOT MET requirement from the assessment.
  3. Check eligibility again. Confirm the score, point values, prohibited requirements, and encryption exception before building the remediation schedule.
  4. Fix prerequisites first. Prioritize changes that unblock several findings, such as identity architecture, logging configuration, policy approval, or system-boundary corrections.
  5. Collect evidence while implementing. Do not wait until the work is finished to discover that screenshots, policies, configuration exports, logs, or interviews cannot demonstrate the required objectives.
  6. Perform internal validation. Reassess the previously NOT MET objectives rather than merely confirming that a ticket was closed.
  7. Complete formal closeout. Use the closeout process that applies to the assessment type and submit the required results before the 180-day window expires.

For a current Level 2 self-assessment, the organization performs the POA&M closeout self-assessment in the same manner as the initial self-assessment and posts the compliance results to SPRS. Under the codified Level 2 C3PAO process, the closeout certification assessment is performed by an authorized or accredited C3PAO.

Do Not Confuse Remediation With Evidence

A security engineer can fix the technical cause of a finding while the organization remains unable to demonstrate that the applicable assessment objectives are satisfied. This gap is where many POA&M schedules quietly acquire teeth.

For each finding, manage three separate states:

  • Implemented: the corrective action has been deployed.
  • Verified: the team has tested the implementation and confirmed the expected security behavior.
  • Evidence-ready: final, approved evidence exists that can support the applicable assessment objectives.

Only marking the first box creates a fragile closeout. The CMMC scoring methodology expects evidence to support a MET determination. Draft policies and unfinished working documents should not be treated as completed evidence.

This also means documentation updates belong inside the remediation task. If an identity change alters privileged-access architecture, for example, the technical deployment may require corresponding changes to system descriptions, diagrams, policies, procedures, or evidence references. The paperwork is not a decorative tail attached to the technical dog. It is part of demonstrating what the system now does.

Use an Internal Deadline Earlier Than Day 180

The statutory closeout limit should be treated as a hard boundary, not as the target completion date. Contractors should create internal deadlines based on remediation risk and the type of closeout required.

Finding TypeScheduling ApproachReason
Configuration change with existing toolingFront-loadUsually easier to implement and verify early
Policy or procedure gapStart early despite apparent simplicityApproval, implementation, communication, and evidence may take longer than drafting
Architecture dependencyCritical pathMay block several downstream findings
Vendor-dependent remediationCritical path with contingencyContracting, licensing, integration, and support delays are partly outside your control
Finding requiring new evidence over timeImplement earlyYou may need operating evidence rather than a one-day configuration snapshot

The practical principle is simple: spend the early part of the window creating security change and the later part proving that the change works.

Common POA&M Management Failures

The most expensive POA&M mistakes are often classification and workflow errors rather than exotic technical failures.

  • Putting every gap on the CMMC assessment POA&M. Some Level 2 requirements are expressly ineligible, and requirements worth more than one point generally cannot be deferred.
  • Assuming a ticket equals a POA&M. A ticket may describe work but omit required resources, milestones, dates, or sufficient connection to the assessment finding.
  • Using day 180 as the engineering deadline. Formal validation still has to happen before expiration.
  • Closing the remediation task before validating evidence. Technical completion and assessment readiness are different states.
  • Leaving the SSP unchanged. Remediation that changes the assessed environment may make old system documentation inaccurate.
  • Buying software for a governance problem. No compliance platform can supply missing ownership, engineering decisions, approval authority, or evidence quality by itself.
  • Planning against the old November 2026 Phase II date. That rollout step was suspended in July 2026.

When a Spreadsheet Is Enough and When Software Helps

POA&M management does not inherently require a compliance platform. The spending decision should depend on coordination complexity, not on the existence of a CMMC acronym.

ApproachBest FitMain Limitation
Spreadsheet or ticketing systemSmall scope, few findings, clear ownership, experienced internal security staffEvidence relationships, approvals, version control, and cross-requirement dependencies can become manual
Compliance softwareMultiple systems, many evidence owners, recurring assessments, complex evidence mapping, or several compliance frameworksImplementation and maintenance work can exceed the value if the organization has a small scope
External consultant or CMMC specialistUnclear scope, uncertain scoring, weak internal CMMC expertise, material contract exposure, or difficult remediation architectureOutside advice does not transfer responsibility for implementing or maintaining the controls

Before purchasing software, ask whether the actual bottleneck is tracking. If five findings are waiting for one IT administrator to configure systems, another dashboard merely gives the queue better lighting.

Software becomes more defensible when the real problem is evidence coordination, recurring control ownership, document versioning, approval workflows, cross-framework mapping, or maintaining assessment readiness across multiple information systems.

What Professional Help Should Actually Solve

Outside assistance is most useful when it removes a specific uncertainty that the internal team cannot resolve efficiently. That might be CMMC scoping, scoring interpretation, architecture remediation, evidence sufficiency, SPRS workflow, or preparation for a formal closeout process.

Before paying a consultant, ask for a deliverable-oriented scope. Useful questions include:

  • Will you validate which NOT MET requirements are eligible for a CMMC assessment POA&M?
  • Will you map each finding to the applicable assessment objectives?
  • Will you review evidence after remediation, or only identify gaps?
  • Will you review changes to the SSP and assessment scope?
  • What work remains the contractor’s responsibility?
  • Are remediation engineering, product licenses, configuration work, and closeout support included or separately priced?
  • What happens if an internal validation still finds an objective NOT MET?

If the unresolved question is budgeting rather than POA&M mechanics, the separate CMMC compliance cost guide is the more useful next step. Remediation costs, assessment costs, tooling costs, and internal labor should be separated rather than collapsed into one compliance figure.

Your 15-Minute POA&M Triage

If a Level 2 assessment just produced findings, do these checks before scheduling remediation meetings:

  1. Record the exact Conditional CMMC Status Date.
  2. List every requirement assessed NOT MET.
  3. Record the CMMC point value for each finding.
  4. Confirm none of the six prohibited Level 2 requirements is being treated as POA&M-eligible.
  5. Confirm the assessment score is at least 88.
  6. Separate assessment POA&M items from the ordinary operational remediation backlog.
  7. Assign one accountable owner to every eligible finding.
  8. Write down what evidence will demonstrate MET status before remediation begins.
  9. Set internal completion dates with room for validation before the 180-day limit.
  10. Check whether remediation changes the SSP, assessment scope, asset categorization, or other evidence.

If any of the first five checks fails, stop treating the issue as an ordinary POA&M scheduling exercise. You may have an eligibility or assessment-status problem that needs to be resolved before project management begins.

CMMC POA&M requirements

Frequently Asked Questions

Can a CMMC Level 1 contractor use a POA&M?

No. CMMC Level 1 does not permit assessment POA&Ms. The applicable Level 1 requirements must be satisfied to achieve Final Level 1 (Self) status.

Is every 1-point Level 2 requirement automatically POA&M-eligible?

No. Point value is only one eligibility test. The assessment must also meet the conditional-status scoring threshold, and the finding cannot be one of the specifically prohibited requirements listed in 32 CFR 170.21. SC.L2-3.13.11 has its own limited exception when encryption is used but is not FIPS-validated.

Does a POA&M make a NOT MET requirement temporarily compliant?

No. The requirement remains NOT MET. The assessment POA&M permits eligible deficiencies to support Conditional CMMC Status while remediation is completed under the rule’s conditions.

What happens if the CMMC POA&M is not closed within 180 days?

The Conditional CMMC Status for the information system expires. For Level 2 self-assessments, expiration during contract performance can also affect eligibility for additional awards requiring Level 2 (Self) or higher for that assessment scope until a new qualifying CMMC Status is achieved. Contractual consequences depend on the applicable contract terms.

Does the 2026 Phase II suspension mean contractors can stop preparing for CMMC?

No. The Department has kept Phase I self-assessment requirements in place, and the suspension does not remove applicable obligations to protect FCI or CUI. What changed is the planned expansion into Phase II, not the need to maintain the controls already required for the contracts and information in scope.

What to Do Before Your Next POA&M Meeting

Open the current tracker and look only at the CMMC assessment POA&M items. For each one, confirm four things: the requirement is legally eligible for conditional treatment, one person owns the remediation, the team knows what evidence will prove the requirement MET, and the internal completion date leaves enough time for closeout before day 180.

If you cannot answer one of those four questions, that is the next problem to solve. A POA&M should be a controlled route from a documented deficiency to verified implementation, not a parking lot where unresolved controls wait for the calendar to become dangerous.

Last reviewed: 2026-10

Stay Updated with Kioptrix

Get practical guides, useful resources, and new articles delivered to your inbox.

No spam. Unsubscribe anytime. Read our Privacy Policy.