Every defense contractor pursuing CMMC Level 2 certification will encounter controls that are not fully implemented by assessment day. The CMMC plan of action and milestones (POA&M) is the mechanism designed to handle that reality, but it comes with strict rules that many contractors misunderstand.
For CNC machining shops, aerospace subcontractors, precision fabricators, and other Tier 2/3 DoD suppliers, a mismanaged POA&M is one of the fastest ways to turn a near-pass into a certification failure or a post-certification decertification finding.
This post explains exactly how CMMC POA&Ms work, which controls are eligible, and the 5 rules you must follow to use one safely.
What Is a CMMC Plan of Action and Milestones?
A CMMC plan of action and milestones is a formal document that identifies security controls not yet fully implemented, assigns an owner to each gap, and sets a target remediation date. It is a standard component of any System Security Plan (SSP) under NIST SP 800-171 and is carried forward into the CMMC assessment process.
Under CMMC Level 2, a POA&M does not mean you failed your assessment. It means you were conditionally certified, with the clock running on closing your open items.
The key distinction from pre-CMMC self-attestation: a C3PAO assessor reviews and approves which controls can be placed on a POA&M. You cannot unilaterally decide to defer any control you find inconvenient.
Relevant resource: CMMC POA&M Guidance, DoD CMMC Program Office
Which Controls Are Eligible for POA&M Deferral?
Not all NIST 800-171 controls can be deferred. The CMMC program distinguishes between controls based on their assessed risk weight.
Controls that are generally not eligible for POA&M deferral include:
- Controls with a single-item point value of 5 or higher in the NIST 800-171 DoD assessment methodology
- Multi-factor authentication requirements (AC.2.013), considered a critical baseline
- Incident response planning (IR.2.092, IR.2.093), which must be in place before certification
- Media protection controls covering CUI at rest
Controls that are generally eligible for POA&M deferral include lower-weighted practices where partial implementation exists and a credible remediation path can be documented.
The practical rule: if your assessor flags it as deferrable, it goes on the POA&M. If they flag it as a finding, it must be remediated before certification is granted.
Related reading: What Is a CMMC System Security Plan and Why Yours Will Fail an Audit
5 Rules for Using a CMMC POA&M Without Losing Your Certification
Rule 1: Every Item Needs a Real Owner, Not a Department
"IT Team" is not an owner. "John Smith, IT Director" is an owner. Each POA&M item must be assigned to a named individual who is accountable for remediation, has the authority to get it done, and will be interviewed by assessors if the item is reviewed.
Generic ownership is a red flag that tells assessors the gap is not being actively managed.
Rule 2: Target Dates Must Be Within 180 Days of Certification
CMMC Level 2 requires all POA&M items to be closed within 180 days of your conditional certification date. This is not a soft deadline. Items still open at 180 days put your certification at risk of revocation.
Set target dates conservatively. A target date of day 175 with no buffer for testing and documentation leaves no room for the unexpected.
Rule 3: Milestone Evidence Must Be Trackable
Each POA&M item needs documented milestones, not just a start date and an end date. Break remediation into phases: procurement approved, vendor selected, system configured, testing completed, SSP updated.
Your C3PAO may conduct a follow-up review before the 180-day window closes. You will need to show progress at each milestone, not just a completed checkbox.
Rule 4: Score Impact Must Be Calculated and Disclosed
Every open POA&M item affects your SPRS score. Before submitting your score to the SPRS portal, calculate the point deduction for each deferred control and reflect it accurately.
Submitting an SPRS score that does not account for known open POA&M items is a False Claims Act exposure. The Civil Cyber-Fraud Initiative has already pursued contractors for exactly this type of discrepancy.
Rule 5: The POA&M Must Be Reviewed and Updated Regularly
A POA&M written at assessment time and never touched again is not a POA&M, it is a liability. Schedule monthly reviews. Update remediation status. Escalate stalled items. Document every update with a date and author.
When your assessor conducts a closeout review, they will look at the revision history of your POA&M to determine whether your organization was actively managing its gaps or simply hoping the clock would run out.
A POA&M with a creation date of three years ago and no subsequent updates is not a compliance tool. It is evidence that your organization is not actively managing its security posture.
POA&M Closeout: What the 180-Day Clock Actually Means
The 180-day window begins on the date your conditional CMMC Level 2 certification is granted, not the date your C3PAO assessment concluded. These can differ by weeks depending on the certification approval process.
By day 180, your organization must:
- Have all POA&M controls fully implemented
- Have updated the SSP to reflect the new control status
- Have collected and retained evidence artifacts for each closed control
- Have submitted an updated SPRS score reflecting the closed items
- Have notified your C3PAO and scheduled a closeout verification if required
If you cannot close all items within 180 days, contact your C3PAO immediately. There is no automatic extension. Unresolved items at 180 days trigger a compliance review that can result in certification suspension.
| Milestone | What Must Be Complete |
|---|---|
| Day 30 | All POA&M items active, owners confirmed, first milestone documented |
| Day 90 | Procurement or tooling decisions finalized, progress documented |
| Day 150 | Implementation complete, testing underway, SSP drafts updated |
| Day 170 | All controls closed, evidence artifacts collected, SPRS score updated |
| Day 180 | C3PAO notified, closeout verification scheduled or completed |
How to Manage Your POA&M After Certification
CMMC certification is a three-year cycle with annual affirmations. Your POA&M does not disappear after closeout. It becomes a standing tool for tracking any new gaps identified through continuous monitoring, vulnerability scanning, or configuration changes.
Defense manufacturers and aerospace subcontractors that maintain a live, updated POA&M throughout their certification period are significantly better positioned for renewal assessments than those who treat it as a one-time document.
Need help building or cleaning up a CMMC POA&M before your assessment? Talk to our compliance team or start with the free Telco United self-assessment to identify your current control gaps.
