Documentation Guide

CMMC POA&M Template: How to Write Items That Survive C3PAO Review

Most CMMC POA&Ms fail not because the gaps are too large but because the plan isn't credible. This guide covers every required field, how to write milestones assessors accept, how to sequence items by SPRS point impact, and the mistakes that turn a reasonable remediation plan into a finding.

Last updated: March 24, 2026

Required fields Field-by-field template Credible milestones SPRS prioritization What can't be deferred What assessors check Common mistakes

A CMMC Plan of Action & Milestones is not optional if you have any unmet requirements going into your assessment — and almost every organization does. The POA&M is the formal mechanism for acknowledging gaps while demonstrating a credible path to close them. Done well, it signals organizational maturity. Done poorly, it creates additional findings on top of the gaps it was meant to address.

This guide covers how to build a POA&M that holds up to C3PAO scrutiny: the fields each item must contain, what credible milestones actually look like, how to sequence items by the SPRS point impact of closing them, and the constraints that apply before you can use a POA&M at all.

For the rules governing which requirements can appear on a POA&M, the 80% scoring threshold for conditional certification, and the 180-day closeout requirement, see the companion article: POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M. This article is focused on how to write each item, not the regulatory constraints on what can be deferred.

What every POA&M item must contain

The CMMC Assessment Guide and NIST SP 800-171 both specify what a POA&M must document. Assessors evaluate each item against these requirements — a POA&M entry that's missing fields isn't just incomplete, it's a signal that the remediation plan isn't real.

Every item in your POA&M must document all of the following:

Field What it requires Common mistake
Requirement ID The CMMC practice identifier — e.g., IA.L2-3.5.3 Using a vague description instead of the actual practice ID
Weakness description Specific description of what isn't implemented or what the gap is — not a restatement of the requirement "MFA not implemented" instead of what is and isn't in place
Point of contact A named individual who owns remediation — name and title, not just a role or department "IT Department" — untraceable, unaccountable
Resources required Budget, tools, personnel time, or vendor services needed — something specific Left blank, or "internal resources"
Scheduled completion A realistic target date for full implementation — not a year from now unless the work genuinely requires it Dates that are implausibly far out, or all items with the same date
Milestones Interim steps with individual target dates showing measurable progress toward the completion date A single line item with no interim steps
Status Current status — Not Started, In Progress, Delayed, or Completed — updated as work progresses Status never updated after initial submission

Field-by-field: writing each element correctly

Requirement ID and weakness description

Start with the specific practice ID. The weakness description is the most important narrative field in the item — and the one most commonly written incorrectly. The description should explain the current state of the control, not restate the requirement.

Weak description
IA.L2-3.5.3 — MFA not implemented.

This tells an assessor nothing beyond what the practice ID already implies. There's no context about what authentication is currently in place, what's missing, or what the scope of remediation is.
Strong description
IA.L2-3.5.3 — MFA not enforced for network access to CUI systems.

Password-based authentication is currently in place for all user accounts, including the 12 accounts with access to CUI-bearing systems on the 192.168.10.x VLAN. MFA (Cisco Duo) has been licensed but not yet deployed. Enforcement policy has not been activated. Accounts with local bypass exceptions have not been reviewed. Scope: 12 user accounts, 3 administrative accounts.

The strong description tells the assessor what exists, what's missing, and what the scope of work is. It makes the subsequent milestones plausible because the starting point is clearly defined.

Point of contact

Name a specific person. "IT Department" or "ISSO" is not a point of contact — it's a role, and it doesn't create accountability. Use first and last name, title, and if useful, contact information. If the person responsible for implementing MFA is the IT Director, the POA&M should say "Jane Smith, IT Director." When an assessor asks who owns this item and you point to Jane Smith, that conversation has a different character than pointing at a department.

Resources required

This field is often left blank or filled with "internal resources" as if that answers the question. It doesn't. Resources required means the specific budget, tools, personnel time, or external services the remediation requires. For the MFA example above: "Cisco Duo — 15 licenses already procured at $6/user/month. Implementation time: approximately 8 hours IT staff across Milestones 1 and 2. No additional budget required." That's a complete answer. It also makes the timeline believable — because the resources exist to support it.

Scheduled completion

Use a specific date, not a quarter. "Q3 2026" is not a completion date — it's a range of up to three months and signals that no one has actually planned the work. "June 30, 2026" is a date. It implies someone looked at the milestones, estimated the work, and committed to a timeline.

The date also needs to be plausible. An item with resources already procured and a named owner should close in weeks to months, not years. An item requiring a major infrastructure change or a vendor procurement cycle can legitimately take longer — but the milestones should explain why.

Writing milestones that assessors accept

Milestones are where most POA&Ms fall apart. A single line that says "implement MFA by June 30" is not a milestone — it's the completion date restated. Milestones are the interim steps that demonstrate the work is planned and progressing.

Good milestones have three properties: they're specific about what gets done, they have individual dates (not all the same date), and together they create a logical sequence that makes the completion date credible.

Non-credible milestones
Milestone 1 (June 30): Implement MFA

This is the completion date with a different label. There's no evidence of planning, no interim steps, no indication of what "implement" entails. An assessor reading this has no basis for believing the date is achievable.
Credible milestones — same item
Milestone 1 (April 15): Cisco Duo tenant configured; pilot enrollment of 3 administrative accounts completed; bypass exception review initiated. Owner: IT Director.

Milestone 2 (May 1): All 12 CUI-access user accounts enrolled in Duo push. Enrollment verified by IT Director. Bypass exceptions documented and approved or removed.

Milestone 3 (May 20): MFA enforcement policy activated on CUI VLAN. Local bypass provisions removed. Post-enforcement access audit completed, results documented.

Completion (May 31): All 15 accounts under MFA enforcement. Duo configuration screenshots captured as evidence for IA.L2-3.5.3. Evidence uploaded to Evidence Manager.

The credible version gives an assessor a clear picture of how the work progresses, who owns each step, and what evidence will exist at completion. It also makes the May 31 date obviously achievable — because the milestones account for the actual work required to get there.

How many milestones per item

Three to five milestones is the typical range for a meaningful remediation item. Fewer than three usually means the planning is incomplete. More than six often means the item should be broken into multiple POA&M entries — one per system, one per domain, or one per distinct remediation track.

Simple items — a missing policy document, a configuration change on a single system — can have two or three milestones. Complex items — implementing a new access control architecture, deploying encryption across multiple systems — should have more, and may warrant milestone reviews with documented progress updates.

Sequencing POA&M items by SPRS point impact

Not all unmet requirements affect your SPRS score equally. Requirements are weighted at 5, 3, or 1 point, and closing a 5-point item has five times the score impact of closing a 1-point item. If you have limited remediation capacity, the sequencing of your POA&M directly affects how quickly your SPRS score improves — which matters both for contract eligibility and for the trajectory assessors see during a conditional certification period.

Point weight Number of requirements POA&M eligibility Prioritization logic
5 points 44 requirements Generally cannot appear on POA&M — must be implemented at assessment These must be resolved before assessment, not planned for after
3 points 23 requirements Can appear on POA&M if 80% threshold is met Highest priority for POA&M closure — maximum score recovery per item
1 point 43 requirements Can appear on POA&M if 80% threshold is met Address after 3-point items unless implementation is faster

The practical sequencing rule: build your POA&M with 3-point items scheduled earliest, because each closure recovers 3 points toward your final SPRS score. Group 1-point items that share a remediation track — configuration changes on the same system, policy documents that can be written in one effort — so that multiple items close simultaneously rather than sequentially.

Your remediation roadmap should also account for dependencies. You cannot close AU.L2-3.3.1 (create audit logs) before you have a logging system configured. That system configuration is itself a prerequisite that may need to appear as a milestone in the AU domain items, not as a separate POA&M entry.

SPRS score projection
Before finalizing your POA&M sequencing, calculate what your SPRS score will be at each milestone checkpoint — not just at final completion. A conditional certification requires your score to reach 110 within 180 days. Knowing your projected score at 60, 90, and 120 days tells you whether your current sequencing keeps you on track or whether high-point items need to move earlier.

What cannot appear on a POA&M

Before writing any POA&M item, verify the requirement is eligible for deferral. Three categories of requirements cannot appear on a POA&M under CMMC Level 2:

5-point requirements (with one narrow exception)

All 44 requirements weighted at 5 points must be fully implemented at the time of assessment. You cannot defer them to a POA&M and achieve even conditional certification. The one exception is SC.L2-3.13.11 (FIPS-validated cryptography), which may be conditionally deferred if encryption is partially implemented — but this exception is narrow and the partial implementation must be genuine.

Requirements that break the 80% threshold

Even 3-point and 1-point requirements cannot be deferred if deferring them would push your SPRS score below 88. The 80% threshold is a hard floor for conditional certification. Calculate your score with all intended POA&M items removed before assuming they're deferrable — if the math doesn't work, the items aren't eligible regardless of their point weight.

The SSP itself

CA.L2-3.12.4 — the requirement to have a System Security Plan — cannot be on a POA&M. The SSP must exist at assessment. This applies to the SSP as a whole; individual sections that are incomplete or inaccurate are a different category of finding, but the absence of an SSP is not something that can be deferred to a remediation plan.

For a complete breakdown of deferral rules, the 180-day closeout clock, and the scoring threshold, see: POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M.

What C3PAO assessors actually examine in your POA&M

Assessors don't just confirm that a POA&M exists. They evaluate it against specific credibility criteria. Understanding what they're looking for changes how you write each item.

Timeline plausibility

Assessors look at whether the timeline is credible given the resources available. An item requiring a major software procurement and deployment scheduled to close in two weeks is not credible. An item where the tool is already licensed and one administrator needs to run an enrollment script scheduled to close in three weeks is entirely credible. The milestones need to support the date — if the milestones don't add up to the timeline, that's a flag.

Specificity of ownership

Items assigned to departments or roles without named individuals signal that no one has actually committed to closing them. Assessors will ask who owns each item in personnel interviews. If the person interviewed doesn't know they own a POA&M item, the POA&M is not being actively managed — which is itself a finding against CA.L2-3.12.2.

Progress evidence for in-progress items

If your assessment follows a period of active remediation and some items are listed as "In Progress," assessors will ask for evidence that progress has actually occurred. Status field updates alone are not evidence. Screenshots of completed milestones, procurement records, enrollment confirmations, or configuration change logs are evidence. Update the status field, but attach the artifact.

Internal consistency

Assessors compare your POA&M against your SSP and your SPRS score. If your SSP describes a control as "planned" and your POA&M lists it with a completion date, those two documents need to be consistent. If your SPRS score implies more items are Met than your POA&M accounts for, the inconsistency raises questions about both documents. Keep these artifacts synchronized.

The most common POA&M mistakes

Using the POA&M as a strategy rather than a plan

Some organizations approach the POA&M as a way to defer requirements they don't want to implement — putting 5-point items on it hoping assessors won't notice, or loading it with items that will never realistically close. This approach fails at assessment and creates FCA exposure if the self-attested SPRS score doesn't reflect the deductions those items should be applying. The POA&M is a remediation tool, not a deferral mechanism.

Writing the POA&M the week before assessment

A POA&M created immediately before an assessment has no completion history, no milestone progress updates, and no evidence of active management. Assessors are trained to look at document creation dates and revision history. A POA&M that was created two weeks before the assessment date and has never been updated is a credibility problem regardless of how well the items are written.

Start your POA&M when you start your gap assessment. Let it accumulate history. By the time your C3PAO arrives, the document should have months of updates that demonstrate it has been actively managed.

Letting the POA&M and SSP fall out of sync

As POA&M items close, the implementation statements in your SSP need to be updated to reflect the new status. Closed POA&M items that still show as "Not Implemented" in the SSP create a contradiction assessors will probe. Keep the two documents synchronized — ideally with a platform that links them so that closing a POA&M item automatically updates the relevant SSP section.

Not linking evidence at closure

Closing a POA&M item means the control is now implemented and the evidence supporting that implementation is attached. An item marked Completed with no evidence is a closed claim without proof. For every item you close before or during assessment, the corresponding evidence artifact should be uploaded and linked to the practice objective it satisfies. If you're closing 8 items in the 90 days before your assessment, that's 8 separate evidence uploads with 8 separate linkages.

The POA&M as evidence of organizational maturity

A well-executed POA&M doesn't just document gaps — it demonstrates that your organization understands its security posture, has accountable ownership for remediation, and is actively managing the program between assessment cycles. That demonstration matters independently of whether the gaps themselves are large or small.

Assessors who arrive and find a current, detailed, actively-managed POA&M with milestone evidence already attached approach the rest of the assessment differently than assessors who find a sparse document clearly written the week before. The POA&M is the first signal of how seriously the organization takes its compliance program. It's worth getting right.

See every gap.

1TEN maps all 110 NIST SP 800-171 controls to your environment and shows you exactly where you stand.

Request a Demo