What Is a POA&M? Plan of Action and Milestones Explained
A POA&M (Plan of Action and Milestones) is a formal document that lists each unmet security requirement or weakness in a system, the tasks and resources needed to fix it, interim milestones, and a scheduled completion date. It is required under NIST SP 800-171, NIST SP 800-53, FedRAMP, and CMMC, where strict rules limit which gaps can be deferred and for how long.
- A POA&M is a remediation tracker required by federal frameworks: NIST SP 800-171 (requirement 03.12.02), NIST SP 800-53 (control CA-5), FedRAMP, and CMMC all mandate one.
- Under CMMC, POA&Ms are never allowed at Level 1, and at Level 2 only if you score at least 88 of 110, defer only one-point requirements, and close every item within 180 days.
- Six Level 2 requirements, including the System Security Plan (CA.L2-3.12.4), can never be placed on a CMMC POA&M under 32 CFR 170.21.
- As of August 2026, DoD has suspended CMMC Phase 2 third-party assessment requirements pending a reform review, but Phase 1 self-assessments and the POA&M rules in 32 CFR part 170 remain in force.
- FedRAMP’s 2026 consolidated rules replace POA&Ms with an ‘accepted weaknesses’ list, with enforcement phasing in from January 1, 2027; Rev5 providers still run POA&M-based continuous monitoring today.
What Does POA&M Mean?
POA&M stands for Plan of Action and Milestones (often written POAM). The NIST glossary defines it as “a document that identifies tasks that need to be accomplished. It details resources required to accomplish the elements of the plan, milestones for meeting the tasks, and the scheduled completion dates for the milestones.”
In plain terms: your System Security Plan (SSP) describes how your controls are implemented today, and your POA&M describes how you will fix the ones that are not. The two documents travel together. Federal agencies have used POA&Ms since FISMA and OMB Circular A-130 made them a standard artifact of the authorization process, and NIST SP 800-53 carries the requirement as control CA-5 in the Risk Management Framework.
For defense contractors, the obligation comes from NIST SP 800-171. Requirement 03.12.02 of SP 800-171 Revision 3 (May 2024) requires organizations to “develop a plan of action and milestones for the system” to document planned remediation of weaknesses found in assessments, and to update it based on assessments, audits, and continuous monitoring. Revision 2, which DoD still assesses against, carries the same duty as requirement 3.12.2. If you are sorting out which catalog applies to you, see our comparison of NIST 800-53 vs. 800-171.
What Goes in a POA&M?
There is no single mandated format outside of FedRAMP’s template, but assessors across NIST, CMMC, and FedRAMP contexts expect the same core fields. The FedRAMP POA&M template is the most prescriptive model, with roughly 26 columns, and it is a useful benchmark even outside FedRAMP.
| Field | What it captures | Example |
|---|---|---|
| Weakness ID and name | Unique identifier and short label for each deficiency | V-014: MFA not enforced for remote admin access |
| Affected control or requirement | The specific control that is unmet | IA.L2-3.5.3 (multifactor authentication) |
| Source of the finding | How the weakness was identified | Self-assessment, C3PAO assessment, vulnerability scan |
| Risk or severity rating | Original (and, in FedRAMP, adjusted) risk level | Moderate |
| Point of contact | The named owner accountable for remediation | IT Director |
| Resources required | Budget, tooling, and staff hours needed | $12,000 license cost, 40 staff hours |
| Remediation plan | High-level summary of corrective actions | Deploy FIPS-validated MFA to all remote access paths |
| Milestones with dates | Interim, verifiable steps toward closure | Pilot group live by Oct 15; full rollout by Nov 30 |
| Scheduled completion date | The committed closure date | December 12, 2026 |
| Status and status date | Open, in progress, or completed, with last update | In progress as of Aug 1, 2026 |
Two habits separate a defensible POA&M from a wish list: every item has a named owner and a real date, and every milestone is specific enough that an assessor can verify it was done. A POA&M without dates is, in an assessor’s eyes, just an admission of noncompliance.
When Are POA&Ms Allowed Under CMMC?
CMMC changed the POA&M from an open-ended IOU into a tightly constrained, time-boxed exception. The rules are codified at 32 CFR 170.21, and they are strict.
Level 1: no POA&Ms, ever
The regulation states plainly that “a POA&M is not permitted at any time for Level 1 self-assessments.” All 15 basic safeguarding requirements must be fully met.
Level 2: allowed only within narrow limits
At Level 2, a POA&M is permitted only if all of the following are true at the time of assessment:
- Minimum score of 88 out of 110. Your assessment score divided by the 110 Level 2 requirements must be at least 0.8.
- Only one-point requirements can be deferred. Items weighted 3 or 5 points under the DoD scoring methodology cannot go on a POA&M, with one exception: SC.L2-3.13.11 (FIPS-validated cryptography) may be deferred if encryption is in place but not yet FIPS-validated.
- Six requirements are excluded entirely: AC.L2-3.1.20 (external connections), AC.L2-3.1.22 (control of publicly posted CUI), CA.L2-3.12.4 (the SSP itself), and PE.L2-3.10.3, 3.10.4, and 3.10.5 (physical access controls).
The 180-day rule
Passing with an open POA&M earns a Conditional CMMC Status. Per 170.21(b), “the closing of a POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date.” Miss the window and the conditional status expires, which can make you ineligible for award and trigger contractual consequences. The closeout is performed by the organization itself for self-assessments, by a C3PAO for Level 2 certifications, and by DCMA DIBCAC for Level 3, per the DoD CIO’s Level 2 Assessment Guide. Level 3 has its own list of requirements that can never be deferred.
The practical takeaway: identify anything that is not POA&M-eligible early, because those gaps must be fixed before assessment day. A structured CMMC gap analysis against the Level 2 requirements is the fastest way to sort must-fix items from deferrable ones.
Where Does CMMC Stand in 2026, and How Do POA&Ms Affect Your SPRS Score?
CMMC enforcement began when the 48 CFR acquisition rule took effect on November 10, 2025, starting Phase 1: self-assessments for Levels 1 and 2 in applicable new contracts. Then, on July 13, 2026, DoD leadership suspended the Phase 2 requirements that would have mandated third-party C3PAO certifications starting November 10, 2026, and stood up a 60-day CMMC Reform Task Force, citing projected compliance costs of roughly $7 billion per year that fall hardest on small businesses.
What did not change matters more for POA&M planning. Phase 1 requirements remain in force: contractors handling CUI must still self-assess against NIST SP 800-171 Rev 2, post scores, and follow the POA&M and conditional-status rules in 32 CFR part 170. DFARS 252.204-7019 and 7020 still require a current assessment score in the Supplier Performance Risk System (SPRS) before award.
POA&Ms and SPRS scores are directly linked. Under the DoD Assessment Methodology, you start at 110 and subtract 1, 3, or 5 points for every requirement not fully implemented, so scores range from 110 down to -203. Every item sitting on your POA&M is deducted from your score until it is closed and the assessment is updated, and SPRS also records the date you project reaching 110. Keep both current: an aged POA&M with slipped dates is a visible risk signal to contracting officers. Our complete CMMC compliance checklist walks through the full sequence.
What Does FedRAMP Require in a POA&M?
For cloud service providers, the POA&M has long been a monthly deliverable, not a one-time artifact. Under FedRAMP’s Rev5 continuous monitoring model, every risk identified in the assessment, plus every new scanner finding, becomes a POA&M item, and the FedRAMP POA&M guidance sets hard remediation clocks: high findings within 30 days of discovery, moderate within 90, and low within 180. Vendor-dependent items require documented monthly vendor check-ins, and high-risk vendor dependencies must be mitigated to moderate within 30 days using compensating controls. False positives and risk adjustments must go through formal deviation requests.
2026 brought a structural change. FedRAMP’s Consolidated Rules for 2026 (CR26), part of the FedRAMP 20x modernization, state that “Plans of Action & Milestones (POA&Ms) have been eliminated entirely and replaced with a list of Accepted Weaknesses,” while continuous monitoring becomes “Ongoing Certification” built on machine-readable evidence and Key Security Indicators. CR26 applies to new 20x applications as of July 4, 2026, becomes mandatory for all providers on January 1, 2027, and Rev5 certifications sunset on a defined timeline (no new Rev5 applications after June 11, 2027).
In practice, most currently certified providers are still operating Rev5 POA&M processes in August 2026 while planning their CR26 transition. The direction of travel is clear, though, and it mirrors CMMC’s philosophy: less tolerance for long-lived deferred findings, more emphasis on continuously verified remediation.
POA&M Best Practices: How to Keep It From Becoming a Parking Lot
The most common POA&M failure mode is treating it as a place where findings go to die. These practices keep it a working remediation plan:
- Triage by eligibility first. In CMMC contexts, separate findings into “must fix before assessment” (3- and 5-point items and the six excluded requirements) and “POA&M-eligible” (one-point items) so the 180-day clock only ever covers achievable work.
- Write milestones an assessor can verify. “Improve access control” is not a milestone; “disable 14 stale admin accounts and enable quarterly access reviews by September 30” is.
- Assign one named owner per item with the authority and budget to close it. Shared ownership reliably produces missed dates.
- Review on a fixed cadence. FedRAMP forces monthly updates; adopting the same rhythm for CMMC and internal POA&Ms keeps status dates honest and surfaces slippage while there is still time to recover.
- Preserve closure evidence. Every closed item should link to artifacts (configurations, screenshots, tickets, policies) proving remediation, because CMMC closeout assessments and FedRAMP assessors will ask for them.
- Feed the POA&M from continuous monitoring, not just annual assessments. SP 800-171 explicitly requires updating it based on ongoing monitoring, audits, and reviews, not only formal assessments.
Contractors preparing for third-party assessment despite the Phase 2 pause, a sensible hedge given that suspended milestones can return, can follow our CMMC Phase 2 compliance guide to sequence remediation and evidence collection.
Frequently asked questions
What does POA&M stand for?
How long can an item stay on a POA&M under CMMC?
Which CMMC requirements can never be on a POA&M?
Are POA&Ms allowed at CMMC Level 1?
Does FedRAMP still require POA&Ms in 2026?
What is the difference between an SSP and a POA&M?
- NIST CSRC Glossary: Plan of Action and Milestones
- NIST SP 800-171 Rev. 3, Requirement 03.12.02
- 32 CFR 170.21 — Plan of Action and Milestones Requirements (eCFR)
- DoD CIO — CMMC Assessment Guide, Level 2 (v2.13)
- NIST SP 800-171 DoD Assessment Methodology, v1.2.1
- FedRAMP — Plan of Action and Milestones (CSP Playbook)
- FedRAMP — What’s Changing in 2026 (Consolidated Rules)
- DefenseScoop — DoD Halts CMMC Phase 2 Requirements (July 13, 2026)
- Federal News Network — Pentagon Suspends CMMC Phase Two, Launches Review (July 2026)
Manage POA&Ms and CMMC Readiness in One Place With Compyl
Compyl’s agentic GRC platform turns your gap analysis into a living POA&M, with owners, milestones, 180-day countdowns, and automated evidence collection mapped to NIST 800-171, CMMC, and FedRAMP, so nothing expires on the shelf.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.