3.12 Security Assessment3 pts

3.12.2 — Plan to fix deficiencies (POA&M)

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

You build POA&Ms to correct deficiencies you find.

What it actually means

For the gaps your assessment finds, you develop and implement Plans of Action & Milestones (POA&Ms) to fix them. This is the control behind the POA&M document. (See our POA&M guide for the CMMC rules on what's eligible.)

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Security Assessment (3.12)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.