CMMC · Common question
What is a POA&M in CMMC?
Short answer
A POA&M (Plan of Action & Milestones) is a formal document capturing control gaps and the plan to close them. Under CMMC 2.0, POA&Ms are permitted at Level 2 assessment — but only for a limited set of controls, and every POA&M item must close within 180 days of assessment.
POA&M stands for Plan of Action and Milestones. It's a formal, documented plan describing:
(a) which specific NIST 800-171 control is not currently met, (b) what remediation steps will bring it into compliance, (c) who owns the remediation, and (d) the target completion date.
Under CMMC 2.0, POA&Ms are allowed at Level 2 assessment — but with real constraints:
Only a limited set of controls can carry an open POA&M through assessment. The DoD publishes the specific control identifiers that are POA&M-eligible; the rest must be fully implemented at assessment time.
Every POA&M item must be closed within 180 days of assessment. Beyond 180 days, the assessment is considered lapsed and re-assessment may be required.
The total number of open POA&M items must keep your SPRS score above the DoD's threshold. Too many open items and the assessment can't be issued at all.
In practice, the smart use of POA&M is narrow: reserve it for controls that have real timing dependencies (e.g. contract-driven vendor migrations), not for controls you simply didn't implement in time. Every SMB that treats POA&M as a way to defer implementation ends up in a 180-day scramble.
Scarlet Comply generates POA&M artifacts in the exact format DoD contracting officers and C3PAOs expect, and tracks the 180-day closure clock automatically.
Related
Still have questions?
Book a 20-minute walkthrough.
