New: Autonomous AI risk intelligence is live — your compliance program in 12 minutes. Get started →

CMMC · Common question

What is a POA&M in CMMC?

Short answer

A POA&M (Plan of Action & Milestones) is a formal document capturing control gaps and the plan to close them. Under CMMC 2.0, POA&Ms are permitted at Level 2 assessment — but only for a limited set of controls, and every POA&M item must close within 180 days of assessment.

POA&M stands for Plan of Action and Milestones. It's a formal, documented plan describing:

(a) which specific NIST 800-171 control is not currently met, (b) what remediation steps will bring it into compliance, (c) who owns the remediation, and (d) the target completion date.

Under CMMC 2.0, POA&Ms are allowed at Level 2 assessment — but with real constraints:

Only a limited set of controls can carry an open POA&M through assessment. The DoD publishes the specific control identifiers that are POA&M-eligible; the rest must be fully implemented at assessment time.

Every POA&M item must be closed within 180 days of assessment. Beyond 180 days, the assessment is considered lapsed and re-assessment may be required.

The total number of open POA&M items must keep your SPRS score above the DoD's threshold. Too many open items and the assessment can't be issued at all.

In practice, the smart use of POA&M is narrow: reserve it for controls that have real timing dependencies (e.g. contract-driven vendor migrations), not for controls you simply didn't implement in time. Every SMB that treats POA&M as a way to defer implementation ends up in a 180-day scramble.

Scarlet Comply generates POA&M artifacts in the exact format DoD contracting officers and C3PAOs expect, and tracks the 180-day closure clock automatically.

Related

Still have questions?

Book a 20-minute walkthrough.

More on CMMC