Guide

POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M

Last updated: 2026-04-15

What Is a POA&M? POA&M vs. OPA Required Contents The 180-Day Rule What Can't Go on a POA&M POA&M Limitations Credible Milestones Closeout Assessment FAQ

What Is a POA&M?

A Plan of Action & Milestones (POA&M) is a document that identifies security deficiencies — requirements that aren't fully implemented — and describes the remediation plan: what you're going to do, who's responsible, and when it will be complete.

The POA&M is a standard artifact in federal cybersecurity compliance. NIST, FISMA, and CMMC all require it because real-world organizations rarely achieve perfect compliance overnight. The POA&M is the mechanism for acknowledging gaps honestly while demonstrating a credible path to resolution.

Critical Insight
A missing POA&M is worse than a POA&M with items in it. If you have unmet requirements and no POA&M, assessors conclude you don't know you have gaps — or worse, that you're concealing them. A thorough POA&M with realistic timelines signals organizational maturity, not weakness.

POA&M vs. Operational Plan of Action: Two Different Documents

The CMMC Final Rule (32 CFR Part 170) introduced a terminology distinction that catches many contractors off guard. Before the Final Rule, the term "POA&M" was used broadly under NIST SP 800-171 to describe the ongoing artifact tracking implementation deficiencies. The Final Rule split this into two separate concepts with different purposes.

Under the Final Rule, POA&M refers specifically to the list of NOT MET requirements documented after a CMMC assessment. This is the artifact that governs your 180-day closeout window and conditional certification status. It is an assessment output — it exists only after a formal assessment has occurred.

The artifact previously called a POA&M under NIST SP 800-171 — the ongoing document tracking day-to-day implementation gaps between assessments — was renamed the Operational Plan of Action (OPA) in the Final Rule. The OPA satisfies CA.L2-3.12.2 and continues between assessment cycles. It is not the same thing as the assessment POA&M and does not govern the 180-day rule.

Key Distinction
POA&M: Post-assessment document. Governs conditional certification and the 180-day closeout window.
OPA (Operational Plan of Action): Ongoing compliance artifact satisfying CA.L2-3.12.2. Exists between assessments. Not subject to the 180-day rule.

Required POA&M Contents

Each item in your POA&M should document the following for every unmet or partially-met requirement:

FieldWhat to Include
Requirement IDThe CMMC requirement identifier (e.g., IA.L2-3.5.3)
Weakness DescriptionSpecific description of what isn't implemented or what the gap is
Point of ContactWho in the organization owns remediation of this item
Resources RequiredBudget, personnel, tools, or time needed to remediate
Scheduled CompletionRealistic target date for full implementation
MilestonesInterim steps and their target dates showing measurable progress
StatusCurrent status — Ongoing, In Progress, Delayed, Completed

The 180-Day Closeout Rule

When a C3PAO assessment results in a Conditional Level 2 certification — meaning you passed but have open POA&M items — you have exactly 180 days from the Conditional CMMC Status Date to close all POA&M items and achieve Final Level 2 status.

The Conditional CMMC Status Date is the date assessment results are submitted to SPRS or eMASS, as defined in 32 CFR 170. The 180-day clock starts from that date, not from the last day of the assessment week.

This is not a soft deadline. If POA&M items remain open after 180 days, your conditional certification lapses and you must undergo a full new assessment. Note: if it takes you the full 180 days to close your POA&M, that time counts against your three-year certification period — leaving you only 2.5 years before reassessment is required.

180-Day Timeline
Day 0: Conditional Level 2 (C3PAO) status date — results posted to SPRS/eMASS
Days 1–150: Remediate all open POA&M items, document evidence of closure
Days 150–170: Schedule your C3PAO closeout assessment (allow for their availability)
Day 180: Hard deadline — POA&M closeout assessment must be complete

If you miss this window, your conditional status expires and a new full assessment is required.

What Can't Go on a POA&M

Not every unmet requirement can be deferred to a POA&M. Under 32 CFR 170.21, POA&M eligibility for CMMC Level 2 is tightly restricted by two separate rules: a point-value restriction and a list of explicitly prohibited requirements.

Point-Value Restriction

Only requirements worth 1 point under the CMMC scoring methodology may appear on a POA&M. Requirements worth 3 points or 5 points must be fully implemented before your C3PAO assessment — they cannot be deferred.

There is one narrow exception: SC.L2-3.13.11 (CUI Encryption / FIPS-validated cryptography) may be placed on a POA&M if encryption is already employed but is not yet FIPS-validated. In this specific scenario, the requirement scores as a 3-point deduction rather than 5. This exception does not apply if no encryption is in place at all.

Explicitly Prohibited Requirements

Even among 1-point requirements, six specific controls are prohibited from appearing on a POA&M under 32 CFR 170.21(a)(2)(iii). These requirements must be fully implemented at the time of assessment regardless of their point value:

Requirement IDRequirementDomain
CA.L2-3.12.1Periodically assess the security controls in organizational systems to determine if the controls are effective in their application (System Security Plan)CA
CA.L2-3.12.4Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systemsCA
PE.L2-3.10.3Escort visitors and monitor visitor activityPE
PE.L2-3.10.4Maintain audit logs of physical accessPE
PE.L2-3.10.6Enforce safeguarding measures for CUI at alternate work sitesPE
SI.L2-3.14.7Identify unauthorized use of organizational systemsSI
Why These Six
These requirements are treated as program integrity controls. CA.L2-3.12.4 (the SSP itself) and CA.L2-3.12.1 (the security assessment process) are foundational to the entire compliance program — without them, no assessment score is defensible. The PE controls establish minimum physical CUI protections. SI.L2-3.14.7 ensures unauthorized use can be detected. The DoD considers these non-negotiable regardless of point weight.

Summary: POA&M Eligibility at a Glance

Requirement TypePOA&M Eligible?
5-point requirementsNo — must be fully implemented before assessment
3-point requirementsNo — must be fully implemented before assessment
SC.L2-3.13.11 (encryption present, not FIPS-validated)Yes — narrow exception, scores as 3-point deduction
1-point requirements (general)Yes — subject to 80% threshold
CA.L2-3.12.1, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.6, SI.L2-3.14.7No — explicitly prohibited regardless of point value

POA&M Limitations Under CMMC

The 80% Scoring Threshold

To achieve Conditional Level 2, your assessment score divided by the total number of CMMC Level 2 security requirements must be greater than or equal to 0.8 — per 32 CFR 170.21(a)(2)(i). Since the maximum possible SPRS score is 110 points, the minimum passing score is 88 points.

Every unmet 5-point requirement deducts 5 from your score. Every unmet 3-point requirement deducts 3. Getting to 88 with gaps means all 5-point and 3-point requirements must be fully met. The practical ceiling for POA&M use is a small number of residual 1-point gaps — not a strategy for deferring significant portions of your program.

Credibility of Timelines

POA&M completion dates must be credible. An item scheduled for completion in 5 years is not a plan — it's a deferred problem. Assessors evaluate whether your timelines are realistic given available resources and organizational capacity. The 180-day window is the absolute ceiling, but your closeout milestones should reflect what you can actually accomplish, not the maximum time allowed.

SPRS Impact
Requirements on your POA&M are requirements you haven't yet met — which means they're already deducting from your SPRS score. Remediating POA&M items is the most direct way to improve your SPRS score over time. 1TEN links your POA&M items directly to the SPRS point weights affected, so you can prioritize by score impact.

Writing Credible Milestones

C3PAO assessors are trained to distinguish between credible remediation plans and wishful thinking. A credible POA&M item has specific, measurable interim milestones — not just a target completion date.

Example: Credible vs. Non-Credible
Non-credible: "Implement MFA by Q3 2026."

Credible: "MFA implementation for CUI boundary systems using Cisco Duo. Milestone 1 (April 15): Duo licenses procured, pilot group of 3 admin accounts enrolled. Milestone 2 (May 1): All 12 CUI-access accounts enrolled with Duo push. Milestone 3 (May 15): Bypass provisions removed, enforcement policy active. Responsible: IT Director. Budget: $1,200/yr."

The difference is specificity. Credible milestones name the tool, define interim steps with dates, identify the responsible person, and acknowledge the resources required. Assessors see enough vague POA&M items to spot them immediately.

POA&M Closeout Assessment

Closing your POA&M items isn't just a matter of checking them off a list. Depending on your certification path, closure requires a formal verification:

Level 2 (Self): You perform a POA&M closeout self-assessment — evaluating only the previously-unmet requirements — and update your SPRS score accordingly.

Level 2 (C3PAO): Your C3PAO must perform a POA&M closeout certification assessment. This is a focused re-assessment evaluating only the requirements that were NOT MET during the initial assessment. Once all items are verified as closed, your status moves from Conditional Level 2 (C3PAO) to Final Level 2 (C3PAO).

The closeout assessment must be completed within the 180-day window. Plan backwards from day 180 to ensure your C3PAO has availability — scheduling delays can cause you to miss the deadline even when remediation is complete.

Managing Your POA&M in 1TEN

1TEN creates POA&M items automatically when you mark a requirement as Not Met or Partially Met during your assessment. Each item is linked to the specific requirement, pre-populated with the requirement statement and relevant assessment guidance, and tracked against your remediation timeline.

The dashboard shows your POA&M count and trend over time — a chart that should be moving in the right direction as you remediate items. Your C3PAO assessors can review the POA&M section of your generated SSP export, which presents all items in the format they expect.

Frequently Asked Questions

A Plan of Action & Milestones (POA&M) is a document that identifies unmet security requirements and describes the specific steps, timelines, responsible parties, and resources needed to remediate each gap. It is a required artifact for CMMC Level 2 compliance.

You have 180 days from the Conditional CMMC Status Date — the date results are submitted to SPRS or eMASS — to close all POA&M items and achieve Final Level 2 status. If items remain open after 180 days, the conditional certification expires and a new full assessment is required.

Under 32 CFR 170.21, only 1-point requirements are POA&M-eligible for CMMC Level 2. Requirements worth 3 or 5 points must be fully implemented before assessment. There is one narrow exception: SC.L2-3.13.11 (CUI Encryption) may appear on a POA&M if encryption is employed but not yet FIPS-validated. Additionally, six specific 1-point requirements are explicitly prohibited from POA&Ms: CA.L2-3.12.1, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.6, and SI.L2-3.14.7.

The CMMC Final Rule (32 CFR Part 170) uses POA&M specifically to refer to the list of NOT MET items after a CMMC assessment, subject to the 180-day closeout window. The ongoing artifact that tracks implementation deficiencies between assessments — previously also called a POA&M under NIST SP 800-171 — was renamed the Operational Plan of Action (OPA) in the Final Rule. The OPA satisfies CA.L2-3.12.2 and is not subject to the 180-day rule.

No. A well-maintained POA&M demonstrates organizational maturity. It shows assessors that you have identified gaps honestly, have a credible plan to address them, and are actively managing remediation. A missing POA&M when gaps exist is far worse.

Yes. Every requirement on your POA&M is a requirement you haven't fully implemented, which means its point value is deducted from your SPRS score. Closing POA&M items directly improves your score.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo