A CMMC Plan of Action & Milestones is not optional if you have any unmet requirements going into your assessment — and almost every organization does. The POA&M is the formal mechanism for acknowledging gaps while demonstrating a credible path to close them. Done well, it signals organizational maturity. Done poorly, it creates additional findings on top of the gaps it was meant to address.
This guide covers how to build a POA&M that holds up to C3PAO scrutiny: the fields each item must contain, what credible milestones actually look like, how to sequence items by the SPRS point impact of closing them, and the constraints that apply before you can use a POA&M at all.
For the rules governing which requirements can appear on a POA&M, the 80% scoring threshold for conditional certification, and the 180-day closeout requirement, see the companion article: POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M. This article is focused on how to write each item, not the regulatory constraints on what can be deferred.
What every POA&M item must contain
The CMMC Assessment Guide and NIST SP 800-171 both specify what a POA&M must document. Assessors evaluate each item against these requirements — a POA&M entry that's missing fields isn't just incomplete, it's a signal that the remediation plan isn't real.
Every item in your POA&M must document all of the following:
| Field | What it requires | Common mistake |
|---|---|---|
| Requirement ID | The CMMC practice identifier — e.g., IA.L2-3.5.3 | Using a vague description instead of the actual practice ID |
| Weakness description | Specific description of what isn't implemented or what the gap is — not a restatement of the requirement | "MFA not implemented" instead of what is and isn't in place |
| Point of contact | A named individual who owns remediation — name and title, not just a role or department | "IT Department" — untraceable, unaccountable |
| Resources required | Budget, tools, personnel time, or vendor services needed — something specific | Left blank, or "internal resources" |
| Scheduled completion | A realistic target date for full implementation — not a year from now unless the work genuinely requires it | Dates that are implausibly far out, or all items with the same date |
| Milestones | Interim steps with individual target dates showing measurable progress toward the completion date | A single line item with no interim steps |
| Status | Current status — Not Started, In Progress, Delayed, or Completed — updated as work progresses | Status never updated after initial submission |
Field-by-field: writing each element correctly
Requirement ID and weakness description
Start with the specific practice ID. The weakness description is the most important narrative field in the item — and the one most commonly written incorrectly. The description should explain the current state of the control, not restate the requirement.
This tells an assessor nothing beyond what the practice ID already implies. There's no context about what authentication is currently in place, what's missing, or what the scope of remediation is.
Password-based authentication is currently in place for all user accounts, including the 12 accounts with access to CUI-bearing systems on the 192.168.10.x VLAN. MFA (Cisco Duo) has been licensed but not yet deployed. Enforcement policy has not been activated. Accounts with local bypass exceptions have not been reviewed. Scope: 12 user accounts, 3 administrative accounts.
The strong description tells the assessor what exists, what's missing, and what the scope of work is. It makes the subsequent milestones plausible because the starting point is clearly defined.
Point of contact
Name a specific person. "IT Department" or "ISSO" is not a point of contact — it's a role, and it doesn't create accountability. Use first and last name, title, and if useful, contact information. If the person responsible for implementing MFA is the IT Director, the POA&M should say "Jane Smith, IT Director." When an assessor asks who owns this item and you point to Jane Smith, that conversation has a different character than pointing at a department.
Resources required
This field is often left blank or filled with "internal resources" as if that answers the question. It doesn't. Resources required means the specific budget, tools, personnel time, or external services the remediation requires. For the MFA example above: "Cisco Duo — 15 licenses already procured at $6/user/month. Implementation time: approximately 8 hours IT staff across Milestones 1 and 2. No additional budget required." That's a complete answer. It also makes the timeline believable — because the resources exist to support it.
Scheduled completion
Use a specific date, not a quarter. "Q3 2026" is not a completion date — it's a range of up to three months and signals that no one has actually planned the work. "June 30, 2026" is a date. It implies someone looked at the milestones, estimated the work, and committed to a timeline.
The date also needs to be plausible. An item with resources already procured and a named owner should close in weeks to months, not years. An item requiring a major infrastructure change or a vendor procurement cycle can legitimately take longer — but the milestones should explain why.
Writing milestones that assessors accept
Milestones are where most POA&Ms fall apart. A single line that says "implement MFA by June 30" is not a milestone — it's the completion date restated. Milestones are the interim steps that demonstrate the work is planned and progressing.
Good milestones have three properties: they're specific about what gets done, they have individual dates (not all the same date), and together they create a logical sequence that makes the completion date credible.
This is the completion date with a different label. There's no evidence of planning, no interim steps, no indication of what "implement" entails. An assessor reading this has no basis for believing the date is achievable.
Milestone 2 (May 1): All 12 CUI-access user accounts enrolled in Duo push. Enrollment verified by IT Director. Bypass exceptions documented and approved or removed.
Milestone 3 (May 20): MFA enforcement policy activated on CUI VLAN. Local bypass provisions removed. Post-enforcement access audit completed, results documented.
Completion (May 31): All 15 accounts under MFA enforcement. Duo configuration screenshots captured as evidence for IA.L2-3.5.3. Evidence uploaded to Evidence Manager.
The credible version gives an assessor a clear picture of how the work progresses, who owns each step, and what evidence will exist at completion. It also makes the May 31 date obviously achievable — because the milestones account for the actual work required to get there.
How many milestones per item
Three to five milestones is the typical range for a meaningful remediation item. Fewer than three usually means the planning is incomplete. More than six often means the item should be broken into multiple POA&M entries — one per system, one per domain, or one per distinct remediation track.
Simple items — a missing policy document, a configuration change on a single system — can have two or three milestones. Complex items — implementing a new access control architecture, deploying encryption across multiple systems — should have more, and may warrant milestone reviews with documented progress updates.
Sequencing POA&M items by SPRS point impact
Not all unmet requirements affect your SPRS score equally. Requirements are weighted at 5, 3, or 1 point, and closing a 5-point item has five times the score impact of closing a 1-point item. If you have limited remediation capacity, the sequencing of your POA&M directly affects how quickly your SPRS score improves — which matters both for contract eligibility and for the trajectory assessors see during a conditional certification period.
| Point weight | Number of requirements | POA&M eligibility | Prioritization logic |
|---|---|---|---|
| 5 points | 44 requirements | Generally cannot appear on POA&M — must be implemented at assessment | These must be resolved before assessment, not planned for after |
| 3 points | 23 requirements | Can appear on POA&M if 80% threshold is met | Highest priority for POA&M closure — maximum score recovery per item |
| 1 point | 43 requirements | Can appear on POA&M if 80% threshold is met | Address after 3-point items unless implementation is faster |
The practical sequencing rule: build your POA&M with 3-point items scheduled earliest, because each closure recovers 3 points toward your final SPRS score. Group 1-point items that share a remediation track — configuration changes on the same system, policy documents that can be written in one effort — so that multiple items close simultaneously rather than sequentially.
Your remediation roadmap should also account for dependencies. You cannot close AU.L2-3.3.1 (create audit logs) before you have a logging system configured. That system configuration is itself a prerequisite that may need to appear as a milestone in the AU domain items, not as a separate POA&M entry.
What cannot appear on a POA&M
Before writing any POA&M item, verify the requirement is eligible for deferral. Three categories of requirements cannot appear on a POA&M under CMMC Level 2:
5-point requirements (with one narrow exception)
All 44 requirements weighted at 5 points must be fully implemented at the time of assessment. You cannot defer them to a POA&M and achieve even conditional certification. The one exception is SC.L2-3.13.11 (FIPS-validated cryptography), which may be conditionally deferred if encryption is partially implemented — but this exception is narrow and the partial implementation must be genuine.
Requirements that break the 80% threshold
Even 3-point and 1-point requirements cannot be deferred if deferring them would push your SPRS score below 88. The 80% threshold is a hard floor for conditional certification. Calculate your score with all intended POA&M items removed before assuming they're deferrable — if the math doesn't work, the items aren't eligible regardless of their point weight.
The SSP itself
CA.L2-3.12.4 — the requirement to have a System Security Plan — cannot be on a POA&M. The SSP must exist at assessment. This applies to the SSP as a whole; individual sections that are incomplete or inaccurate are a different category of finding, but the absence of an SSP is not something that can be deferred to a remediation plan.
For a complete breakdown of deferral rules, the 180-day closeout clock, and the scoring threshold, see: POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M.
What C3PAO assessors actually examine in your POA&M
Assessors don't just confirm that a POA&M exists. They evaluate it against specific credibility criteria. Understanding what they're looking for changes how you write each item.
Timeline plausibility
Assessors look at whether the timeline is credible given the resources available. An item requiring a major software procurement and deployment scheduled to close in two weeks is not credible. An item where the tool is already licensed and one administrator needs to run an enrollment script scheduled to close in three weeks is entirely credible. The milestones need to support the date — if the milestones don't add up to the timeline, that's a flag.
Specificity of ownership
Items assigned to departments or roles without named individuals signal that no one has actually committed to closing them. Assessors will ask who owns each item in personnel interviews. If the person interviewed doesn't know they own a POA&M item, the POA&M is not being actively managed — which is itself a finding against CA.L2-3.12.2.
Progress evidence for in-progress items
If your assessment follows a period of active remediation and some items are listed as "In Progress," assessors will ask for evidence that progress has actually occurred. Status field updates alone are not evidence. Screenshots of completed milestones, procurement records, enrollment confirmations, or configuration change logs are evidence. Update the status field, but attach the artifact.
Internal consistency
Assessors compare your POA&M against your SSP and your SPRS score. If your SSP describes a control as "planned" and your POA&M lists it with a completion date, those two documents need to be consistent. If your SPRS score implies more items are Met than your POA&M accounts for, the inconsistency raises questions about both documents. Keep these artifacts synchronized.
The most common POA&M mistakes
Using the POA&M as a strategy rather than a plan
Some organizations approach the POA&M as a way to defer requirements they don't want to implement — putting 5-point items on it hoping assessors won't notice, or loading it with items that will never realistically close. This approach fails at assessment and creates FCA exposure if the self-attested SPRS score doesn't reflect the deductions those items should be applying. The POA&M is a remediation tool, not a deferral mechanism.
Writing the POA&M the week before assessment
A POA&M created immediately before an assessment has no completion history, no milestone progress updates, and no evidence of active management. Assessors are trained to look at document creation dates and revision history. A POA&M that was created two weeks before the assessment date and has never been updated is a credibility problem regardless of how well the items are written.
Start your POA&M when you start your gap assessment. Let it accumulate history. By the time your C3PAO arrives, the document should have months of updates that demonstrate it has been actively managed.
Letting the POA&M and SSP fall out of sync
As POA&M items close, the implementation statements in your SSP need to be updated to reflect the new status. Closed POA&M items that still show as "Not Implemented" in the SSP create a contradiction assessors will probe. Keep the two documents synchronized — ideally with a platform that links them so that closing a POA&M item automatically updates the relevant SSP section.
Not linking evidence at closure
Closing a POA&M item means the control is now implemented and the evidence supporting that implementation is attached. An item marked Completed with no evidence is a closed claim without proof. For every item you close before or during assessment, the corresponding evidence artifact should be uploaded and linked to the practice objective it satisfies. If you're closing 8 items in the 90 days before your assessment, that's 8 separate evidence uploads with 8 separate linkages.
The POA&M as evidence of organizational maturity
A well-executed POA&M doesn't just document gaps — it demonstrates that your organization understands its security posture, has accountable ownership for remediation, and is actively managing the program between assessment cycles. That demonstration matters independently of whether the gaps themselves are large or small.
Assessors who arrive and find a current, detailed, actively-managed POA&M with milestone evidence already attached approach the rest of the assessment differently than assessors who find a sparse document clearly written the week before. The POA&M is the first signal of how seriously the organization takes its compliance program. It's worth getting right.