What Is a POA&M? Complete Guide for Defense Contractors

Defense contractor reviewing a Plan of Action and Milestones (POA&M) document for CMMC Level 2 compliance and cybersecurity remediation.

A POA&M — Plan of Action and Milestones — is the document that lists every NIST SP 800-171 security requirement you haven’t fully implemented yet, along with what it will take to close each one and a realistic completion date. It’s not a confession. It’s proof you have a real plan, and it’s exactly what an assessor expects to see alongside your system security plan (SSP), not instead of it. 

A lot of owners hear “plan of action” and assume it means they’ve failed something. It doesn’t. Almost no shop starts with every one of the 110 requirements fully met. The POA&M is how you show the gap is being managed instead of ignored, with a real action plan behind it rather than a vague promise to “get to it.” 

Related Topic: FCI vs. CUI: What Every Defense Subcontractor Needs to Know

What an SSP Shows vs. What a POA&M Shows

Your SSP documents where you stand today — the security controls you have in place, your system boundaries, how CUI flows through your environment. The POA&M is the forward-looking half: it takes every deficiency the SSP surfaces and turns it into a tracked item with an owner, a remediation plan, and a completion date. 

Think of it this way: the SSP is the map of your environment as it exists right now. The POA&M is the punch list for everything that map shows still needs work. An assessor reviewing your compliance posture wants both, because a clean-looking SSP with no open items and no POA&M usually means something wasn’t documented honestly, not that the shop is actually done. 

Related Topic: Why Passing CMMC Starts With Finding the Gaps First?

What Actually Goes Into a POA&M

A POA&M isn’t a vague list of “things to fix.” Each entry needs to hold up on its own: 

The Specific Deficiency 

Which of the 110 NIST SP 800-171 security requirements isn’t fully met, and why. 

The Remediation or Mitigation Plan 

What tool, policy, or process change closes the gap. 

Resources Required 

What it will take, in terms of budget, vendor involvement, or internal effort. 

A Completion Date 

A realistic target, not a placeholder. 

A generic POA&M template gives you the columns. It doesn’t know your actual environment, your actual vendor relationships, or which gaps genuinely depend on someone else’s timeline versus your own. 

Related Topic: CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

Why Your SPRS Score Doesn’t Have to Be Good Before You Start a POA&M 

Here’s something that catches owners off guard: the SPRS scoring range runs from a perfect 110 all the way down to negative 203, and a deeply negative starting score is common, not alarming. We’ve worked with a shop that started at negative 145 — meaning most of the 110 requirements were still open — and closed a meaningful chunk of that gap just by finishing policy documentation for controls they’d already partially implemented in practice. Having an antivirus tool in place but no written policy governing it costs you points you’re otherwise entitled to. 

That’s the real value of building the POA&M honestly instead of chasing a good-looking number. A shop working from a negative starting score with a real, dated remediation plan is in a stronger compliance posture than one reporting an inflated self-assessment score with nothing behind it. 

Related Topic: What Is a Passing CMMC Score and How Is It Calculated?

Not Every Gap Can Go on a POA&M 

This is a distinction that trips a lot of shops up: some requirements are “POA&M-able,” and some aren’t. Certain higher-weighted NIST SP 800-171 requirements — generally the ones scored at three or five points instead of one — have to be fully implemented before you can complete a CMMC Level 2 self-assessment at all. You can’t POA&M your way around those. 

That’s part of why a lot of shops work through this in stages rather than attempting the full CMMC Level 2 self-assessment on day one. It’s common to start by submitting a NIST SP 800-171 self-assessment score to SPRS at whatever the honest starting number is — even deeply negative — while those non-POA&M-able gaps are still being closed. Once the basic Level 1 controls are in place (Level 1 covers Federal Contract Information and is a much shorter list — 15 controls, roughly half of them physical security), a shop can complete that self-assessment relatively quickly. The full CMMC Level 2 self-assessment comes once the higher-weighted, non-POA&M-able requirements are actually closed — often a few months further out, depending on what an IT provider needs to implement. 

Related Topic: Department of War Suspends CMMC Phase II Certification: What It Means for Defense Contractors

Where POA&M Items Actually Come From 

Not every open item on a POA&M comes from the same place, and knowing the source usually tells you how urgent it is: 

Gap Analysis Against Your SSP 

The most common source. Comparing what your system security plan says against what’s actually configured in your information system surfaces most POA&M entries directly. 

Vulnerability Scans 

A scan finding an unpatched system or an exposed service becomes its own POA&M item, separate from documentation gaps. These tend to carry shorter completion timelines because they represent active exposure, not a paperwork lag. 

Related Topic: CMMC Readiness: Prepare Your Business for Compliance

Security Assessment or Audit Findings 

When a third-party assessor or your own internal review turns something up that wasn’t previously tracked, it goes on the POA&M with the same rigor as anything else, even if it was found late. 

Knowing where an item came from helps you and your IT provider prioritize. A vulnerability-scan finding on a system touching Controlled Unclassified Information (CUI) usually needs to move faster than a documentation gap on a control you’ve already partially implemented.

Related Topic: CMMC Readiness: Prepare Your Business for Compliance

Vendor Dependencies and Your POA&M Completion Timeline 

A POA&M target date is only as real as what it depends on. If closing a gap requires a new tool, a managed detection and response rollout, or configuration work from your IT provider, your completion date needs to reflect their timeline, not just your own intentions. Validate vendor timelines before committing to POA&M milestones, because capable remediation partners close cybersecurity gaps and meet DoD compliance deadlines.

Related Topic: CMMC Audit Preparation: Avoid Common Compliance Mistakes

Keeping the POA&M Current 

A POA&M isn’t a document you write once and file. As items close, they move off the list. As your environment changes — new tools, new vendors, new system boundaries — new items can appear. Assessors expect to see a POA&M that reflects actual, current remediation status, not a snapshot from your last audit cycle. Review your POA&M quarterly, update your SPRS score simultaneously, and keep both aligned with your environment’s actual cybersecurity implementation status.

If you’re not sure whether your current gaps are documented in a way that would hold up, that’s the right place to start. A CMMC-certified team can walk through your SSP and POA&M together, confirm which of your open items are genuinely POA&M-eligible, and help you build a realistic remediation timeline instead of a guess. 

Related Topic: C3PAO: What It Is and How to Choose One for CMMC Level 2

Frequently Asked Questions 

What’s the difference between an SSP and a POA&M?

An SSP documents implemented security controls, while a POA&M tracks unresolved deficiencies, remediation actions, responsible owners, and target completion dates.

What are the main components of a POA&M?

A POA&M includes identified deficiencies, remediation actions, assigned owners, required resources, milestones, target completion dates, and current implementation status tracking.

What does POA&M stand for?

POA&M stands for Plan of Action and Milestones, documenting cybersecurity deficiencies, remediation activities, milestones, and compliance progress for defense contractors.

Can every NIST SP 800-171 requirement go on a POA&M?

No. High-priority requirements require full implementation before assessment, while eligible lower-priority controls may remain on a compliant POA&M temporarily.

What is a POA&M tracker?

A POA&M tracker records open security deficiencies, remediation tasks, responsible owners, milestones, completion dates, and ongoing implementation progress efficiently.

Our Blog

What Is a POA&M? Complete Guide for Defense Contractors

What Is a POA&M? Complete Guide for Defense Contractors

A POA&M — Plan of Action and Milestones — is the document that lists…

FCI vs. CUI: What Every Defense Subcontractor Needs to Know

FCI vs. CUI: What Every Defense Subcontractor Needs to Know

FCI vs. CUI: What the Difference Actually Means for Your Subcontractors  Federal Contract Information (FCI)…

Why Passing CMMC Starts With Finding the Gaps First?

Why Passing CMMC Starts With Finding the Gaps First?

A CMMC gap assessment checks your environment against all 320 assessment objectives behind the 110 NIST…