Skip to main content
CMMC Compliance

CMMC Plan of Action and Milestones: 5 Critical Rules to Avoid Losing Your Certification

A POA&M can keep your CMMC certification on track when controls are not yet fully implemented. It can also get you decertified if you use it incorrectly.

By Telco United • 7 min read

Every defense contractor pursuing CMMC Level 2 certification will encounter controls that are not fully implemented by assessment day. The CMMC plan of action and milestones (POA&M) is the mechanism designed to handle that reality, but it comes with strict rules that many contractors misunderstand.

For CNC machining shops, aerospace subcontractors, precision fabricators, and other Tier 2/3 DoD suppliers, a mismanaged POA&M is one of the fastest ways to turn a near-pass into a certification failure or a post-certification decertification finding.

This post explains exactly how CMMC POA&Ms work, which controls are eligible, and the 5 rules you must follow to use one safely.

What Is a CMMC Plan of Action and Milestones?

A CMMC plan of action and milestones is a formal document that identifies security controls not yet fully implemented, assigns an owner to each gap, and sets a target remediation date. It is a standard component of any System Security Plan (SSP) under NIST SP 800-171 and is carried forward into the CMMC assessment process.

Under CMMC Level 2, a POA&M does not mean you failed your assessment. It means you were conditionally certified, with the clock running on closing your open items.

The key distinction from pre-CMMC self-attestation: a C3PAO assessor reviews and approves which controls can be placed on a POA&M. You cannot unilaterally decide to defer any control you find inconvenient.

Relevant resource: CMMC POA&M Guidance, DoD CMMC Program Office

Which Controls Are Eligible for POA&M Deferral?

Not all NIST 800-171 controls can be deferred. The CMMC program distinguishes between controls based on their assessed risk weight.

Controls that are generally not eligible for POA&M deferral include:

Controls that are generally eligible for POA&M deferral include lower-weighted practices where partial implementation exists and a credible remediation path can be documented.

The practical rule: if your assessor flags it as deferrable, it goes on the POA&M. If they flag it as a finding, it must be remediated before certification is granted.

Related reading: What Is a CMMC System Security Plan and Why Yours Will Fail an Audit

5 Rules for Using a CMMC POA&M Without Losing Your Certification

Rule 1: Every Item Needs a Real Owner, Not a Department

"IT Team" is not an owner. "John Smith, IT Director" is an owner. Each POA&M item must be assigned to a named individual who is accountable for remediation, has the authority to get it done, and will be interviewed by assessors if the item is reviewed.

Generic ownership is a red flag that tells assessors the gap is not being actively managed.

Rule 2: Target Dates Must Be Within 180 Days of Certification

CMMC Level 2 requires all POA&M items to be closed within 180 days of your conditional certification date. This is not a soft deadline. Items still open at 180 days put your certification at risk of revocation.

Set target dates conservatively. A target date of day 175 with no buffer for testing and documentation leaves no room for the unexpected.

Rule 3: Milestone Evidence Must Be Trackable

Each POA&M item needs documented milestones, not just a start date and an end date. Break remediation into phases: procurement approved, vendor selected, system configured, testing completed, SSP updated.

Your C3PAO may conduct a follow-up review before the 180-day window closes. You will need to show progress at each milestone, not just a completed checkbox.

Rule 4: Score Impact Must Be Calculated and Disclosed

Every open POA&M item affects your SPRS score. Before submitting your score to the SPRS portal, calculate the point deduction for each deferred control and reflect it accurately.

Submitting an SPRS score that does not account for known open POA&M items is a False Claims Act exposure. The Civil Cyber-Fraud Initiative has already pursued contractors for exactly this type of discrepancy.

Rule 5: The POA&M Must Be Reviewed and Updated Regularly

A POA&M written at assessment time and never touched again is not a POA&M, it is a liability. Schedule monthly reviews. Update remediation status. Escalate stalled items. Document every update with a date and author.

When your assessor conducts a closeout review, they will look at the revision history of your POA&M to determine whether your organization was actively managing its gaps or simply hoping the clock would run out.

A POA&M with a creation date of three years ago and no subsequent updates is not a compliance tool. It is evidence that your organization is not actively managing its security posture.

POA&M Closeout: What the 180-Day Clock Actually Means

The 180-day window begins on the date your conditional CMMC Level 2 certification is granted, not the date your C3PAO assessment concluded. These can differ by weeks depending on the certification approval process.

By day 180, your organization must:

If you cannot close all items within 180 days, contact your C3PAO immediately. There is no automatic extension. Unresolved items at 180 days trigger a compliance review that can result in certification suspension.

Milestone What Must Be Complete
Day 30 All POA&M items active, owners confirmed, first milestone documented
Day 90 Procurement or tooling decisions finalized, progress documented
Day 150 Implementation complete, testing underway, SSP drafts updated
Day 170 All controls closed, evidence artifacts collected, SPRS score updated
Day 180 C3PAO notified, closeout verification scheduled or completed

How to Manage Your POA&M After Certification

CMMC certification is a three-year cycle with annual affirmations. Your POA&M does not disappear after closeout. It becomes a standing tool for tracking any new gaps identified through continuous monitoring, vulnerability scanning, or configuration changes.

Defense manufacturers and aerospace subcontractors that maintain a live, updated POA&M throughout their certification period are significantly better positioned for renewal assessments than those who treat it as a one-time document.

Need help building or cleaning up a CMMC POA&M before your assessment? Talk to our compliance team or start with the free Telco United self-assessment to identify your current control gaps.

Know Your POA&M Gaps Before Your Assessor Does

Find out where you stand against the 110 NIST 800-171 controls. Take the free self-assessment and get a clear compliance baseline in 15 minutes.

Take Free Self-Assessment Or talk to our CMMC compliance team directly

Subscribe to our Newsletter: