Skip to content
Cyber Defense Technologies

Compliance

POA&Ms Done Right: Turning Gaps into a Credible Remediation Plan

A Plan of Action and Milestones is where compliance programs prove they are serious. How to write POA&M items that assessors and authorizing officials trust, and what CMMC allows.

By Cyber Defense Technologies January 13, 2026 5 min read

No organization has a perfect security program. What distinguishes a mature program from a struggling one is how it handles what is not yet done. The Plan of Action and Milestones (POA&M) is the tool for that: a living record of known weaknesses and the concrete plan to correct them.

POA&Ms appear throughout federal compliance. NIST SP 800-171 requirement 3.12.2 calls for plans of action to correct deficiencies. The Risk Management Framework uses POA&Ms to track weaknesses that remain when a system is authorized. FedRAMP expects them as part of continuous monitoring. The format varies, but the principles are the same.

Anatomy of a credible POA&M item

A POA&M item should let someone unfamiliar with your environment understand the problem and judge whether the plan is realistic. At a minimum, include:

  • Weakness: a clear description of what is missing or not working
  • Requirement or control: the specific requirement affected, such as 3.5.3 or IA-2(1)
  • Source: where the weakness was identified: self-assessment, scan, audit, incident
  • Affected assets: which systems or components
  • Risk: the likely impact if the weakness were exploited, in plain terms
  • Planned remediation: what will be done, technically and procedurally
  • Milestones: intermediate steps with dates
  • Resources: who and what is required, including budget if relevant
  • Owner: a named role accountable for completion
  • Scheduled completion date and status

The life of a POA&M item

  1. 1

    Identify

    A gap is found in a self-assessment, scan, audit or incident.

  2. 2

    Record

    Document the weakness, the requirement, the affected assets and the risk.

  3. 3

    Plan

    Define milestones, an owner, resources and a realistic completion date.

  4. 4

    Track

    Review progress on a schedule; update dates only with justification.

  5. 5

    Close

    Implement the fix, verify it, keep the evidence, and close the item.

A weak item vs. a strong item

A weak item reads: "MFA not fully implemented. Remediate by Q3."

A strong item reads: "Multifactor authentication is not enforced for administrative access to the three on-premises hypervisors (3.5.3). Identified in the March self-assessment. Risk: stolen administrator credentials could allow control of all virtual machines hosting CUI. Plan: integrate hypervisor management with the identity provider and require phishing-resistant MFA; restrict management access to the admin jump host. Milestones: design approved by April 15; pilot on one host by May 1; all hosts by May 20; verification and evidence by May 31. Owner: Infrastructure Manager."

The second version can be tracked, verified and trusted.

What CMMC allows on a POA&M

The CMMC program rule, 32 CFR 170.21, sets strict limits for Level 2 assessments:

  • The assessment score must be at least 88 of 110 to reach conditional status.
  • Only requirements with a weight of 1 point may be on the POA&M, with a narrow exception for FIPS-validated cryptography (3.13.11) when encryption is in place but the module is not yet validated.
  • Certain requirements can never be on a POA&M, and every 5-point requirement, including multifactor authentication and incident response capability, must be fully met at assessment.
  • POA&M items must be closed out, and verified, within 180 days, or the conditional status expires.

For self-assessments under Phase 1, the same discipline applies to your SPRS score: every open POA&M item is a requirement not yet met, and the score should reflect that.

Prioritizing the backlog

When the list is long, order it by risk and weight:

  1. High-weight requirements first. In the DoD Assessment Methodology, 5-point requirements such as MFA, encryption and incident response dominate both risk and score.
  2. Exposure next. Weaknesses on internet-facing or remote access systems deserve urgency.
  3. Quick wins. Low-effort items build momentum and reduce the list's size.
  4. Dependencies. Some fixes, such as a new identity platform, unlock several others.

Keeping POA&Ms honest

A POA&M loses credibility quickly when dates slip silently. Practical habits help:

  • Review on a schedule. Monthly for active items, with the owner present.
  • Document every date change with the reason and who approved it.
  • Close with evidence. An item is not closed until the fix is verified and the evidence is filed.
  • Do not hide risk acceptance. If leadership decides not to fix a weakness, document the decision, the rationale and the compensating measures, where the framework allows it.
  • Reconcile regularly. New scan findings, audit results and incidents should flow into the POA&M, not sit in separate reports.

The payoff

A well-run POA&M is evidence of a functioning security program. It shows assessors and authorizing officials that the organization knows its weaknesses, has a plan, and follows through. That credibility is often the difference between a smooth assessment and a difficult one.

Handling risk acceptance honestly

Sometimes a weakness will not be fixed: a legacy system cannot support a control, a vendor product has a limitation, or the cost outweighs the risk. That is a legitimate outcome in frameworks that allow it, such as the Risk Management Framework, if it is handled properly:

  • The decision is made by someone with authority to accept the risk, typically the authorizing official, not by the team that owns the weakness.
  • The rationale is documented, including why remediation is not feasible.
  • Compensating measures are described and verified.
  • The acceptance is revisited periodically, and when conditions change.

What does not work is quietly leaving an item open indefinitely. That looks like neglect, not risk management. Note also that CMMC does not provide for accepting risk on requirements in place of meeting them; an unmet requirement is scored as unmet.

Frequently asked questions

How many POA&M items is too many? There is no universal number. What matters is whether items are prioritized sensibly, owned, progressing, and consistent with the framework's rules. A long list with steady progress is more credible than a short list that never changes.

Should findings from a vulnerability scan all go on the POA&M? Follow your program's rules. Many programs track routine patching through vulnerability management and place on the POA&M only findings that cannot be remediated within standard timeframes. Whatever the rule, apply it consistently.

Can a POA&M item be closed without evidence? It should not be. Close items only when the fix is verified and the evidence is filed where an assessor can find it.

How CDT can help

CDT builds and manages POA&Ms as part of our CMMC readiness, RMF and ATO and inspection readiness work, and our engineers close the technical gaps behind them.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.