A POA&M is not a way to skip the hard controls. Under CMMC Level 2, only 1-point requirements can be deferred, you need at least 80% of the points to even qualify, and the clock to close everything is 180 days.
Once you've run a self-assessment, you'll have two lists: what you meet, and what you don't. The Plan of Action & Milestones (POA&M) is how you deal with the second list. This guide explains what a POA&M is, exactly what goes in one, the CMMC rules for which gaps you're even allowed to defer, and how to produce one without paying a consultant to format a spreadsheet.
What is a POA&M?
A Plan of Action & Milestones is the document that lists every security requirement you don't yet meet and, for each one, states what you'll do to fix it, what it will take, who owns it, and by when. It's the companion to your System Security Plan (SSP): the SSP says where you stand; the POA&M says how you'll close the gaps. NIST SP 800-171 requires it directly — requirement 3.12.2 tells you to "develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities."
What actually goes in a POA&M
A POA&M is a structured table. Assessors and program offices expect the same core columns whether you build it in a spreadsheet or a tool:
| Column | What it captures |
|---|---|
| Control / requirement | The NIST 800-171 requirement ID (e.g., 3.5.3) the gap maps to. |
| Weakness / deficiency | A plain statement of what isn't yet implemented, tied to the requirement text. |
| Point value | The SPRS deduction (5, 3, or 1) — this drives priority and eligibility. |
| Planned remediation & milestones | The concrete steps to close the gap, broken into checkpoints. |
| Resources required | Tools, licenses, or people needed to finish. |
| Responsible owner | The named role accountable for the fix. |
| Scheduled completion date | A realistic target — and under CMMC, within the 180-day window. |
| Status | Open, in progress, or closed. |
The CMMC rules: what you can and can't defer
Here's where most contractors get surprised. A POA&M under CMMC Level 2 is not a blank check to postpone whatever's hard. The CMMC Program rule (32 CFR 170.21) sets strict limits:
- You need at least 80% first. To earn Conditional Level 2, your assessment score divided by 110 must be ≥ 0.8 — a minimum score of 88 of 110. Below that, no POA&M is allowed and you don't pass.
- 180-day clock. Every POA&M item must be closed within 180 days of receiving Conditional status. A POA&M closeout assessment then confirms Final Level 2 status.
- Only 1-point requirements are eligible. Every 3-point and 5-point requirement must be fully met before your assessment — they cannot be deferred. That includes the high-value ones like multifactor authentication (3.5.3) and monitoring remote access (3.1.12).
- One narrow exception. FIPS-validated cryptography (SC.L2-3.13.11) — normally 5 points — may go on a POA&M only if you already encrypt CUI but the module isn't FIPS-validated yet (it then scores as a 3-point deduction). If you aren't encrypting at all, it can't be deferred.
- Six requirements are barred entirely, even though they're 1-point: AC.L2-3.1.20 (external system connections), AC.L2-3.1.22 (control publicly posted information), CA.L2-3.12.4 (the SSP itself), PE.L2-3.10.3 (escort visitors), PE.L2-3.10.4 (physical access logs), and PE.L2-3.10.5 (manage physical access devices). A "NOT MET" on any of these can't be POA&M'd — you simply don't pass until it's fixed.
Build your POA&M from your actual gaps
Our free POA&M generator pulls the requirements you marked unmet in the SPRS calculator, orders them by point value, and lays them out as an assessor-ready POA&M you can edit, export to CSV, or print. No signup.
Build your POA&M free →How to write your POA&M, step by step
Find your gaps
Run a SPRS self-assessment so you know exactly which requirements are unmet, and what each one costs you in points.
One row per gap
For each unmet requirement, capture the weakness, milestones, owner, and a realistic completion date inside the 180-day window.
Highest value first
Fix the ineligible 3- and 5-point gaps before your assessment, then drive the 1-point POA&M items to closure and update status.
- Start from a real assessment. Calculate your SPRS score so your POA&M reflects your actual environment, not guesses.
- Separate eligible from ineligible. Any 3- or 5-point gap (and the six barred controls) has to be fixed, not deferred — handle those before assessment.
- Write a milestone-based row for each remaining 1-point gap: weakness, concrete steps, owner, and a date within 180 days.
- Track it to closure. A POA&M is a living document — update status as you close items, because a closeout assessment will check them.
A note for 2026
SPRS scoring and CMMC assessment still run on NIST SP 800-171 Revision 2 — the Department of War has not moved scoring to Revision 3. Point values and POA&M eligibility in this guide reflect the Rev 2 requirements and the CMMC Program rule your assessment will actually use.
Frequently asked questions
Can I get CMMC Level 2 certified with open POA&M items?
Yes, conditionally. If your score divided by 110 is at least 0.8 (a minimum of 88), you can receive Conditional Level 2 with eligible gaps on a POA&M — then you must close them within 180 days to reach Final status.
How long do I have to close a POA&M?
180 days from the date of Conditional CMMC status. A POA&M closeout assessment confirms the items are done.
Which requirements can't go on a POA&M?
All 3-point and 5-point requirements must be met — only 1-point requirements are eligible. Even then, six are barred entirely (AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5). FIPS crypto (3.13.11) is the one narrow exception, deferrable only if encryption is in place but not yet FIPS-validated.
What's the difference between an SSP and a POA&M?
The SSP documents how you meet each requirement today; the POA&M documents how and when you'll close the ones you don't. NIST 800-171 requires the SSP under 3.12.4 and the POA&M under 3.12.2.
Score, document, plan — free
The fastest path: calculate your SPRS score, draft your SSP, then build your POA&M from the gaps. All three are free and run in your browser.