What Is a POA&M in CMMC and How Does It Work?
A Plan of Action and Milestones (POA&M) is a key tool that helps organizations achieve conditional CMMC certification when they fall short on a few specific cybersecurity controls. To qualify, organizations must demonstrate compliance with most requirements and provide a clear plan to quickly remediate any deficiencies.
To fully understand the role of POA&Ms in CMMC compliance, it’s important to consider:
- The background of CMMC and why POA&Ms were introduced
- The purpose and detailed requirements of a POA&M
- How POA&Ms are applied differently across CMMC Level 2 and Level 3
Regulatory Context for CMMC and POA&Ms
The Department of Defense (DoD) introduced the Cybersecurity Maturity Model Certification (CMMC) program in 2020 to strengthen cybersecurity across the Defense Industrial Base (DIB). Originally, CMMC included five maturity levels with complex requirements, which posed challenges for many contractors.
In 2023, CMMC 2.0 simplified the program to three levels and streamlined assessments. Alongside these changes, Plans of Action and Milestones (POA&Ms) were introduced to support organizations that meet most requirements but fall short on a few critical controls. POA&Ms provide a path to conditional compliance, ensuring that deficiencies are addressed within a specified timeframe. This approach balances strict cybersecurity standards with practical contractor capabilities.
POA&Ms Explained: Plan of Action and Milestones 101
Plans of Action and Milestones (POA&Ms) primarily apply at CMMC Level 2 or higher. They provide organizations a structured method to achieve conditional certification while addressing gaps in compliance. To qualify for a POA&M, organizations (OSAs) must:
- Achieve a minimum aggregate score of 0.8 or higher on their CMMC assessment
- Avoid missing any critical controls worth 1 point, except for SC.L2-3.13.11 (cryptographic protection of CUI) under specific conditions
- Create a customized POA&M that clearly outlines remediation steps for each deficiency
- Complete a POA&M closeout assessment within 180 days to verify that corrective actions have been implemented
There is no one-size-fits-all POA&M template. Each POA&M must be tailored to an organization’s specific compliance gaps and approved by a Certified Third-Party Assessor Organization (C3PAO) or DIBCAC assessor.
Applicability of POA&Ms by CMMC Level
Level 1: Not Eligible for POA&Ms
Organizations conducting self-assessments at CMMC Level 1 are not eligible for conditional certification via POA&Ms. Level 1 focuses on basic security controls for Federal Contract Information (FCI), assessed annually through self-assessment.
Level 2: POA&Ms for Controlled Unclassified Information (CUI)
At CMMC Level 2, organizations can use POA&Ms if they meet an 80% assessment score and satisfy all non-negotiable requirements, including:
- AC.L2-3.1.20: Secure external connections for CUI
- CA.L2-3.12.4: Documented system security plans
- PE.L2-3.10.3–5: Physical access safeguards for CUI systems
Level 3: POA&Ms for High-Security Requirements
For CMMC Level 3, eligibility for POA&Ms requires meeting critical controls, such as:
- IR.L3-3.6.1e: SOC controls
- RA.L3-3.11.6e: Supply chain risk response
- SI.L3-3.14.3e: Specialized asset security management
POA&M Closeout Assessment Requirements
Conditional CMMC status lasts 180 days. Organizations must complete a POA&M closeout assessment within this period to confirm all deficiencies are corrected. The closeout process differs by level:
- Level 2 (self-assessment): Conducted internally
- Level 2 (C3PAO): Closed out by the same C3PAO
- Level 3: Government-led closeout via DIBCAC
Broader Requirements for CMMC Certification
POA&Ms do not replace full CMMC compliance. The broader control requirements include:
- Level 1: 15 controls for FCI, assessed annually via self-assessment
- Level 2: 110 controls from NIST SP 800-171, protecting FCI and CUI, assessed by self or C3PAO
- Level 3: 134 controls, combining Level 2 with NIST SP 800-172, assessed triennially by DIBCAC
Streamline Your CMMC Certification with POA&Ms
POA&Ms enable near-compliant organizations to stay competitive by addressing gaps in cybersecurity controls. By leveraging a Plan of Action and Milestones, defense contractors can earn conditional CMMC certification and move to full compliance within 180 days.
At RSI Security, we help organizations achieve and maintain CMMC certification at all levels, whether through POA&Ms or standard compliance processes. Our team of experts guides you through planning, implementation, and official assessments as a Certified Third-Party Assessor Organization (C3PAO).
Download Our CMMC Checklist