DEFENSE & CMMC
What Is POA&M (Plan of Action and Milestones)?
DEFINITION
A POA&M (Plan of Action and Milestones) is a documented plan identifying security requirements an organization has not yet fully implemented, the tasks needed to close each gap, the resources required, and target completion dates. Under CMMC, POA&Ms are permitted only for a limited subset of requirements and must be closed out within 180 days of the assessment.
A POA&M is the standard federal artifact for tracking known security gaps to closure. It originated in federal agency practice under the Risk Management Framework and carried into contractor obligations through NIST SP 800-171, which requires organizations to develop and implement plans of action for unimplemented requirements. Each POA&M entry typically records the deficient requirement, the remediation tasks, the owner, the resources needed, and milestone dates.
For defense contractors the POA&M has two distinct roles. Under the DFARS self-assessment regime, requirements that are not fully implemented reduce the SPRS score and should each have a corresponding plan of action. Under CMMC, the rules tighten considerably: a contractor can achieve a conditional CMMC status with open POA&M items only if its score meets a minimum threshold, only certain lower-weighted requirements are eligible for a POA&M at all, and the items must be remediated and verified within 180 days or the conditional status lapses.
The practical implication is that a POA&M is a bridge, not a parking lot. Organizations that treat it as a place to indefinitely record accepted gaps find that the highest-weighted requirements, such as multifactor authentication and FIPS-validated encryption, cannot be deferred at all. Building the plan backward from the 180-day clock is the discipline that matters. See CMMC Level 2 requirements for small business for prioritization guidance.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →