HomeGuides › What Is a POA&M

What Is a POA&M — and How to Write One

The plan that closes your compliance gaps, explained — including the CMMC Level 2 rules for what you can and can't defer, plus a free generator that builds it from your SPRS gaps.

A POA&M is not a way to skip the hard controls. Under CMMC Level 2, only 1-point requirements can be deferred, you need at least 80% of the points to even qualify, and the clock to close everything is 180 days.

Once you've run a self-assessment, you'll have two lists: what you meet, and what you don't. The Plan of Action & Milestones (POA&M) is how you deal with the second list. This guide explains what a POA&M is, exactly what goes in one, the CMMC rules for which gaps you're even allowed to defer, and how to produce one without paying a consultant to format a spreadsheet.

What is a POA&M?

A Plan of Action & Milestones is the document that lists every security requirement you don't yet meet and, for each one, states what you'll do to fix it, what it will take, who owns it, and by when. It's the companion to your System Security Plan (SSP): the SSP says where you stand; the POA&M says how you'll close the gaps. NIST SP 800-171 requires it directly — requirement 3.12.2 tells you to "develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities."

80%Score to qualify for a POA&M
180Days to close every item
1 ptMax value you can defer
6Controls barred entirely

What actually goes in a POA&M

A POA&M is a structured table. Assessors and program offices expect the same core columns whether you build it in a spreadsheet or a tool:

ColumnWhat it captures
Control / requirementThe NIST 800-171 requirement ID (e.g., 3.5.3) the gap maps to.
Weakness / deficiencyA plain statement of what isn't yet implemented, tied to the requirement text.
Point valueThe SPRS deduction (5, 3, or 1) — this drives priority and eligibility.
Planned remediation & milestonesThe concrete steps to close the gap, broken into checkpoints.
Resources requiredTools, licenses, or people needed to finish.
Responsible ownerThe named role accountable for the fix.
Scheduled completion dateA realistic target — and under CMMC, within the 180-day window.
StatusOpen, in progress, or closed.

The CMMC rules: what you can and can't defer

Here's where most contractors get surprised. A POA&M under CMMC Level 2 is not a blank check to postpone whatever's hard. The CMMC Program rule (32 CFR 170.21) sets strict limits:

The expensive mistake: assuming you can assess now and POA&M the gaps later. Because 3- and 5-point requirements can't be deferred, a single unmet 5-pointer (say, MFA) can block certification no matter how good the rest of your score is. Find those first — the 5-point controls are where to start.

Build your POA&M from your actual gaps

Our free POA&M generator pulls the requirements you marked unmet in the SPRS calculator, orders them by point value, and lays them out as an assessor-ready POA&M you can edit, export to CSV, or print. No signup.

Build your POA&M free →

How to write your POA&M, step by step

Step 1 · Score

Find your gaps

Run a SPRS self-assessment so you know exactly which requirements are unmet, and what each one costs you in points.

Step 2 · Write the rows

One row per gap

For each unmet requirement, capture the weakness, milestones, owner, and a realistic completion date inside the 180-day window.

Step 3 · Work & close

Highest value first

Fix the ineligible 3- and 5-point gaps before your assessment, then drive the 1-point POA&M items to closure and update status.

  1. Start from a real assessment. Calculate your SPRS score so your POA&M reflects your actual environment, not guesses.
  2. Separate eligible from ineligible. Any 3- or 5-point gap (and the six barred controls) has to be fixed, not deferred — handle those before assessment.
  3. Write a milestone-based row for each remaining 1-point gap: weakness, concrete steps, owner, and a date within 180 days.
  4. Track it to closure. A POA&M is a living document — update status as you close items, because a closeout assessment will check them.

A note for 2026

SPRS scoring and CMMC assessment still run on NIST SP 800-171 Revision 2 — the Department of War has not moved scoring to Revision 3. Point values and POA&M eligibility in this guide reflect the Rev 2 requirements and the CMMC Program rule your assessment will actually use.

Frequently asked questions

Can I get CMMC Level 2 certified with open POA&M items?

Yes, conditionally. If your score divided by 110 is at least 0.8 (a minimum of 88), you can receive Conditional Level 2 with eligible gaps on a POA&M — then you must close them within 180 days to reach Final status.

How long do I have to close a POA&M?

180 days from the date of Conditional CMMC status. A POA&M closeout assessment confirms the items are done.

Which requirements can't go on a POA&M?

All 3-point and 5-point requirements must be met — only 1-point requirements are eligible. Even then, six are barred entirely (AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5). FIPS crypto (3.13.11) is the one narrow exception, deferrable only if encryption is in place but not yet FIPS-validated.

What's the difference between an SSP and a POA&M?

The SSP documents how you meet each requirement today; the POA&M documents how and when you'll close the ones you don't. NIST 800-171 requires the SSP under 3.12.4 and the POA&M under 3.12.2.

Score, document, plan — free

The fastest path: calculate your SPRS score, draft your SSP, then build your POA&M from the gaps. All three are free and run in your browser.

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.