A Plan of Action & Milestones (POA&M) is how you document the security requirements you have not fully met yet, and your plan to close them. Used well, it is a sign of a mature program. Used poorly, it is a list of promises an assessor will not accept. Here is how to stay on the right side of that line at CMMC Level 2.

Do

  • Be specific and dated. Each item should name the gap, the remediation, an owner, and a real closure date — not ‘in progress, ongoing.’
  • Close within the window. At CMMC Level 2, a limited POA&M can support a conditional result, but the open items must be closed and re-verified within 180 days. Plan the work to fit that window.
  • Keep it live. A POA&M is a working document. Update it as items close, with the evidence attached.

Don't

  • Do not assume everything is POA&M-eligible. Certain higher-weighted requirements cannot be deferred — they must be met before you can reach a passing result at all. Know which ones before you rely on a plan.
  • Do not use it to hide a scope problem. If a control is failing because CUI has sprawled into systems that never needed it, the fix is scoping, not a milestone.
  • Do not let it become a graveyard. A POA&M full of dates that already slipped tells an assessor more about your operating discipline than any policy will.

The best POA&M is a short one, closing on schedule, backed by evidence. See how we build and operate the SSP, POA&M, and evidence alongside our clients.