What Is a POA&M?
Updated:
September 2, 2026
A Plan of Action and Milestones (POA&M) records unresolved security weaknesses and explains how and when they will be fixed, who is responsible, and what resources are needed. It helps teams track remediation through verified closure, but having one does not automatically prove compliance.
This guide explains when a POA&M is required, what it should contain, how to maintain it, and how the rules differ under the Cybersecurity Maturity Model Certification (CMMC) program.

Terminology note: The official term is Plan of Action and Milestones, abbreviated POA&M. “POAM” is a common search variation, but this article uses POA&M throughout.
Key Takeaways
- A POA&M is a structured remediation record for unresolved weaknesses, corrective actions, milestones, resources, and scheduled completion dates.
- Federal Risk Management Framework (RMF), FedRAMP, and CMMC programs formally use POA&Ms; other frameworks may use them as an internal management tool.
- Every item should identify the finding, affected system or requirement, risk, owner, action, milestones, evidence, and current status.
- Remediation work needs a named owner and a realistic scheduled completion date, with approved changes documented when dates move.
- “Work completed” is not the same as “closed.” Closure should follow independent or program-required validation.
- CMMC Conditional Level 2 requires at least 88 of 110 points, permits only eligible items, and requires assessment POA&M closeout within 180 days.
When Is a POA&M Required?
A POA&M is required under some federal security and authorization programs.
Programs such as the federal RMF and FedRAMP use it to track security weaknesses and corrective work. CMMC permits POA&Ms only in certain cases.
SOC 2, ISO/IEC 27001, HIPAA, and PCI DSS do not usually require a document called a POA&M. Organizations may still use one internally to track and correct security issues.
The specific program, framework, or contract determines whether a POA&M is required and what rules apply.

The main formal references are NIST SP 800-53 Rev. 5 control CA-5 for the federal RMF and 32 CFR 170.21 for CMMC assessment POA&Ms. FedRAMP also provides its own POA&M requirements and templates.
POA&M Use Across Different Frameworks
POA&M requirements vary across security and compliance programs. Some formally require or permit them, while others use them internally for remediation tracking.
The table below summarizes these differences:
| Program or Framework | How a POA&M Is Used |
|---|---|
| Federal RMF | CA-5 uses a POA&M to record plans for fixing security weaknesses and vulnerabilities. It is included in the authorization package and updated as findings change. |
| FedRAMP | Cloud service providers use the FedRAMP POA&M template during authorization and continuous monitoring. |
| CMMC | Some requirements marked NOT MET may be placed on an assessment POA&M when the conditional-status rules are met. Level 1 does not allow assessment POA&Ms. |
| DFARS and NIST SP 800-171 | Contract and assessment rules determine the security requirements. Having a POA&M alone does not prove compliance. |
| SOC 2, ISO/IEC 27001, HIPAA, and PCI DSS | These frameworks do not usually require a document called a POA&M, but organizations may use one internally to manage security issues and corrective work. |
What Does a POA&M Contain?
A POA&M contains a record of each security weakness and the work needed to correct it. It records who owns the work, when it should be completed, and how closure will be confirmed. Compliance automation can centralize status updates, ownership records, remediation evidence, and closure documentation. This record helps management and assessors understand remediation progress, delays, and remaining risk.
NIST refers to the planned deadline as the scheduled completion date.
A POA&M commonly contains the following information:

- Finding Details: The basic record usually covers the finding number, source, discovery date, affected system or asset, and related control or requirement.
- Risk and Impact: This part describes the weakness, its possible security or operational effects, its severity rating, existing compensating controls, and any remaining risk.
- Remediation Plan: Planned work is documented through the corrective action, accountable owner, supporting teams, required resources, dependencies, measurable milestones, and scheduled completion date.
- Progress Tracking: Current status is shown through milestone updates, reasons for deadline changes, the next review date, and approved deferral details when applicable.
- Closure and Verification: Once the corrective action is complete, the entry may include the evidence location, validation method and result, verifier, actual completion date, closure approval, and risk-acceptance information when required.
POA&M Template & Example
The following general-purpose template is split into planning and closure tables so it remains readable on smaller screens. The two example rows describe the same completed remediation item.
Identification and Remediation Plan
| Field | Details |
|---|---|
| Item | POA&M-001 |
| Affected System | VPN gateway GW-01 |
| Source and Date | Vulnerability scan, August 25, 2026 |
| Weakness and Risk | Critical firmware vulnerability; High risk |
| Corrective Action | Update firmware, restrict management access, and retest |
| Owner and Support | Network Engineering, IT Operations, and Security |
| Milestones | Test August 27; approve August 29; upgrade September 2; retest September 3 |
| Dependency | Approved outage window |
| Scheduled Completion | September 3, 2026 |
| Status | Closed |
Validation, Residual Risk, and Approval
| Field | Details |
|---|---|
| Item | POA&M-001 |
| Closure Evidence | Change ticket CHG-4821, firmware inventory, configuration export, and scan report |
| Validation Result | Scan confirmed the vulnerable firmware was removed. Access testing confirmed administrative network restrictions. |
| Verifier | Security Engineering Manager |
| Completion Date | September 3, 2026 |
| Compensating Controls | Administrative IP allowlist remained active during validation |
| Residual Risk | Low; routine patch monitoring continues |
| Closure Approval | Security Director, September 3, 2026 |
| Next Review | Reopen if the fix regresses or the evidence becomes invalid |
Defense-Specific Template Note
Defense-contractor records may include a Commercial and Government Entity (CAGE) code, Information System Security Manager (ISSM), alternate ISSM, Facility Security Officer (FSO), assessment score, and CMMC status.
Those fields are not part of a general business template. The older download below is a one-page Defense Security Service (DSS) example; DSS was replaced by the Defense Counterintelligence and Security Agency (DCSA), so use it only as a legacy reference and follow current DCSA, CMMC, and contract guidance for present-day work.

How to Create and Maintain a POA&M
A POA&M records each security weakness, its risk rating, corrective action, responsible owner, milestones, scheduled completion date, current status, and supporting evidence.
Compliance monitoring can reveal control failures that need formal remediation. Regular POA&M updates give management and assessors an accurate record of remediation work, delays, approved exceptions, remaining risk, and closure decisions.
The following process covers each POA&M item from initial recording through verified closure:

- Record the Weakness and Affected Requirement: Document the weakness, discovery source, discovery date, affected system or asset, and relevant security control or contractual requirement.
- Assess the Risk and Operational Effect: Consider exploitability, exposure, business impact, asset criticality, existing safeguards, and applicable scoring requirements.
- Define the Corrective Action: State the specific technical, procedural, configuration, access-control, or training changes needed to address the underlying cause. Record any required resources, approvals, vendors, or dependent changes.
- Assign a Responsible Owner: Name one person accountable for coordinating the item and record the teams responsible for supporting the work.
- Set Milestones and Track Progress: Create measurable milestones and a scheduled completion date based on risk, remediation complexity, available resources, and program deadlines. Update completed work, current status, blockers, and approved schedule changes as the item progresses.
- Collect Evidence and Validate Remediation: Preserve relevant change tickets, configuration records, scan results, test records, screenshots, and approvals. Use an appropriate reviewer and testing method to confirm that the weakness has been corrected without introducing new issues.
- Document and Approve Closure: Record the actual completion date, validation result, reviewer, evidence location, and closure approval. When exposure remains, document the residual risk, compensating controls, approving authority, and required follow-up actions.
Use Consistent Status Categories
Use the categories required under the governing program.
The following categories provide a clear remediation lifecycle when no prescribed terminology applies:
- Open: The weakness has been recorded, but remediation has not started.
- In Progress: Remediation work is underway.
- Pending Validation: The corrective action is complete and awaiting verification.
- Closed: The corrective action has been verified and closure has been approved.
An approved deferral is an exception rather than a remediation stage.
Record the item’s current status separately and document the reason for the delay, approving authority, revised milestones, compensating controls, remaining risk, permitted target-date changes, and next review date.
Do not treat “completed” and “closed” as interchangeable.
Completed means the corrective action has been performed. Closed means the result has been validated and formally approved.
A missed deadline may require escalation, contractual reporting, reassessment, or a formal risk decision under the governing program.
Ownership, Validation, and Reopening
A security, risk, compliance, or system-management lead commonly maintains the overall POA&M, while each item has a named remediation owner.
A control owner, security assessor, internal audit function, or other qualified person should validate completed actions.
The official who approves deferrals or risk acceptance varies across RMF, FedRAMP, CMMC, and internal programs.
Keep an item open when the corrective action is incomplete, evidence is missing, validation fails, or residual risk has not received the required approval.
Reopen a closed item when a fix regresses, new evidence invalidates the closure basis, the affected scope expands, or a reassessment shows the weakness persists.
How to Prioritize Remediation?
Prioritize items based on exploitability and business impact. The Verizon 2026 Data Breach Investigations Report (DBIR) provides useful remediation data. Vulnerability exploitation accounted for 31% of breach initial access, up from 20%. Only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38%.
The median time to full remediation increased from 32 to 43 days. Organizations also had a median of 16 CISA KEVs to patch in 2025, compared with 11 in 2024. These figures support risk-based remediation schedules. A continuous vulnerability management program can supply recurring scan results and risk-ranked findings for POA&M tracking.
Match each corrective action to the underlying cause. The non-intentional human element appeared in 62% of breaches, up from 60%. Training is one possible response. Access controls or process changes may address the cause more directly.
Phone-centered phishing simulations produced a median click rate of about 2%, compared with approximately 1.4% for email. The phone-centered rate was about 40% higher.
IBM’s 2026 Cost of a Data Breach Report places the global average breach cost at $4.99 million. Use this figure as breach-impact context. Program-specific requirements should determine POA&M deadlines.
POA&M Versus an SSP, Risk Register, and Task Ticket
A POA&M and System Security Plan (SSP) support formal security documentation. A Risk Register and Task Ticket cover risk and work-tracking activities.
The table below explains the primary purpose of each record:
| Document | Primary Purpose |
|---|---|
| 1. POA&M | Tracks unresolved weaknesses, corrective actions, owners, milestones, scheduled completion dates, evidence, and validated closure. |
| 2. System Security Plan (SSP) | Describes the system boundary, environment, and how applicable security requirements are implemented. |
| 3. Risk Register | Records and monitors broader organizational risks, responses, owners, and risk decisions. |
| 4. Task Ticket | Tracks individual work activities but may not include formal risk, approval, evidence, and compliance fields. |
These records can be linked without being merged.
For example, the SSP describes a control implementation, the POA&M records a deficiency in that implementation, the risk register captures the broader business exposure, and a task ticket assigns a specific technical change.
How POA&Ms Work Under CMMC
The Cybersecurity Maturity Model Certification (CMMC) program applies to Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) environments. The CMMC assessment process permits POA&Ms only for eligible requirements scored NOT MET.
The controlling rules are in the CMMC final rule and 32 CFR 170.21. Level 1 does not permit an assessment POA&M.
Conditional Level 2 Scoring and Eligibility
An organization seeking Conditional Level 2 must score at least 88 out of 110 points, which is 80% of the maximum score. Requirements worth more than one point generally cannot be placed on the assessment POA&M.
The exception is SC.L2-3.13.11, CUI Encryption: it may be included with a three-point deduction when encryption is used but is not Federal Information Processing Standards (FIPS) validated.
The following six Level 2 requirements cannot be placed on an assessment POA&M:
- AC.L2-3.1.20: External Connections
- AC.L2-3.1.22: Control Public Information
- CA.L2-3.12.4: System Security Plan
- PE.L2-3.10.3: Escort Visitors
- PE.L2-3.10.4: Physical Access Logs
- PE.L2-3.10.5: Manage Physical Access
The 180-Day Assessment POA&M Rule
Every eligible requirement on a CMMC assessment POA&M must be remediated and successfully closed through the applicable POA&M closeout assessment within 180 days of the Conditional CMMC Status Date.
That date is tied to submission of the assessment results in the Supplier Performance Risk System (SPRS) or the CMMC instance of the Enterprise Mission Assurance Support Service (eMASS), as applicable.
An assessment POA&M cannot remain open past the deadline through ordinary risk acceptance; the conditional status expires if closeout is not completed on time.
A Level 2 self-assessment uses a closeout self-assessment. A Level 2 certification assessment requires an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO) to conduct the closeout assessment.
Level 3 also permits conditional status when the score is at least 80% and all open items meet the Level 3 eligibility rules; its assessment and closeout work is performed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Assessment POA&M Versus Operational Plan of Action
A CMMC assessment POA&M records eligible requirements scored NOT MET during an assessment and is subject to the conditional-status rules. An operational plan of action under CA.L2-3.12.2 addresses temporary vulnerabilities or deficiencies that arise after requirements have been implemented. The operational plan is not the assessment POA&M and is not subject to the same 180-day assessment closeout period, although contract, risk, and incident obligations may still impose deadlines.
DFARS Clauses and NIST SP 800-171 Rev. 2
- DFARS 252.204-7012 covers safeguarding covered defense information and cyber incident reporting.
- DFARS 252.204-7019 gives notice of the NIST SP 800-171 DoD assessment requirement and requires a current assessment for covered systems relevant to an offer when applicable.
- DFARS 252.204-7020 establishes the NIST SP 800-171 DoD assessment requirements for applicable covered contractor information systems.
CMMC and the cited contractual assessment process continue to use NIST SP 800-171 Rev. 2 because the current CMMC rule, clauses, and assessment methodology incorporate that revision even though Rev. 3 has been published. The NIST 800-171 compliance checklist outlines the requirements contractors need to review before documenting unresolved items in a POA&M.
Current CMMC Program Status
Last Updated: August 30, 2026
On July 13, 2026, the U.S. Department of War, the agency formerly named the Department of Defense, announced the immediate suspension of CMMC Phase II requirements, which had been scheduled for November 10, 2026. Pending and future implementation milestones were placed on hold during the review.
- Still in place: CMMC Level 1 self-assessment and Level 2 self-assessment requirements, which may continue to appear in procurements.
- Suspended during the review: Level 2 C3PAO and Level 3 DIBCAC assessment designations.
- Still in effect: baseline NIST SP 800-171 Rev. 2 compliance through self-assessments and select government-led assessments, plus applicable DFARS 252.204-7012 safeguarding and incident-reporting obligations.
The announced 60-day review began July 13, 2026, so the stated period runs to approximately September 11, 2026. Readers should check the official CMMC page and implementation memoranda for any result, extension, or replacement guidance issued after this article’s update date.
Contractual cybersecurity obligations also remain enforceable. On June 18, 2026, the Department of Justice announced that Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 to resolve False Claims Act allegations involving cybersecurity requirements in two Navy contracts (DOJ announcement). The resolved claims were allegations, and there was no determination of liability.
Frequently Asked Questions
1. What does POA&M mean?
POA&M means Plan of Action and Milestones. It is a document for tracking unresolved weaknesses and the work required to correct them.
2. What is the purpose of a POA&M?
Its purpose is to create a controlled record of findings, risk, corrective actions, owners, resources, milestones, scheduled completion dates, evidence, and validated closure.
3. What information belongs in a POA&M?
Include the finding and source, affected system or requirement, discovery date, risk, action, owner, resources, dependencies, milestones, scheduled and actual completion dates, status, evidence, validation, residual risk, verifier, and approval information.
4. How is a POA&M different from an SSP?
A System Security Plan describes the system and how security requirements are implemented. A POA&M tracks weaknesses or requirements that remain unresolved and the plan for correcting them.
5. How does a POA&M work under CMMC?
Level 1 does not allow an assessment POA&M. Levels 2 and 3 may allow conditional status when the minimum score and eligibility conditions are met, but eligible items must be closed through the required assessment within 180 days.
6. Who manages a POA&M?
A security, risk, compliance, or system-management lead often maintains the overall document. Each item should have a named remediation owner, and a qualified verifier should confirm closure.
7. How often should a POA&M be updated?
Update it whenever a status, milestone, owner, deadline, finding, evidence record, validation result, or risk decision changes. Formal review frequency depends on risk, reporting obligations, remediation deadlines, and program rules.
8. How long can a POA&M item remain open?
The governing program, contract, risk decision, and remediation deadline control the answer. CMMC assessment POA&M items associated with conditional status must be successfully closed within 180 days.
9. What evidence is needed to close an item?
Use evidence appropriate to the finding, such as a retest report, authenticated scan, configuration export, change ticket, log, approved policy, access review, or test result. The evidence must support the validation conclusion.
10. Is a POA&M required for SOC 2?
No. SOC 2 does not prescribe a document called a POA&M. An organization may use one internally to manage control deficiencies, remediation tasks, ownership, and evidence.
11. How Do I Write a POA&M for the First Time?
Start by identifying a specific security weakness, compliance gap, failed control, audit finding, or other issue that needs corrective action. Each POA&M entry should focus on one clearly defined problem rather than combining several unrelated issues into a single item.
For each issue, document what the problem is, which system or control it affects, why it matters, and what needs to be done to correct it. Then assign an owner who is responsible for remediation and establish realistic milestones that show how the issue will be resolved.
A basic POA&M entry will usually include:
- A unique tracking number
- The identified weakness or deficiency
- The affected system, control, or requirement
- The planned corrective action
- The person or team responsible
- Milestone dates
- The expected completion date
- The current status
- Supporting notes or evidence
The goal is not simply to record that a problem exists. A useful POA&M should clearly explain how the organization plans to move from an identified weakness to a verified resolution.
12. How Do I Decide What to Include in a POA&M?
Include issues that require corrective action and need to be formally tracked until they are resolved. These commonly come from security assessments, vulnerability scans or penetration tests, internal audits, compliance assessments, risk assessments, control testing, or management reviews.
For example, an organization might create a POA&M item because multifactor authentication has not yet been implemented, a required security policy is incomplete, system logs are not being reviewed, or a vulnerability cannot be immediately remediated.
Each entry should contain enough information for another person to understand:
- What the problem is
- Why the problem exists
- What requirement or system is affected
- What corrective action is planned
- Who is responsible
- When the work should be completed
- How progress will be measured
- How the organization will confirm the issue has been resolved
Avoid vague entries such as “Improve access control.” A stronger POA&M entry would explain the specific deficiency, such as “Administrative accounts currently do not require multifactor authentication.”
The more specific the entry is, the easier it becomes to track remediation and demonstrate progress during an audit or assessment.
13. How Do I Set a Realistic Completion Date for a POA&M Item?
Do not choose a completion date simply because it looks reasonable. The date should reflect the actual amount of work required to remediate the issue.
Consider factors such as:
- Technical complexity
- Availability of staff
- Budget requirements
- Vendor dependencies
- Procurement timelines
- Testing requirements
- Business disruption
- Approval processes
- The severity of the weakness
A simple configuration change may be completed within a few days, while replacing a major system or implementing a new security platform could require several months.
For larger remediation efforts, break the work into milestones. Instead of creating one distant deadline, document intermediate steps such as:
Milestone 1: Select a solution
Milestone 2: Purchase and configure the solution
Milestone 3: Deploy the solution
Milestone 4: Test the implementation
Milestone 5: Verify remediation and close the finding
Milestones make it easier to demonstrate that remediation is actively progressing even when the final completion date is several months away.
Organizations should also review whether the applicable framework, contract, authorization program, or regulatory requirement imposes specific remediation deadlines. A POA&M does not automatically allow an organization to postpone a requirement indefinitely.
14. How Do I Assign Responsibility for Fixing a POA&M Finding?
Assign every POA&M item to a specific person or accountable team that has the authority and resources to move the remediation forward.
Avoid assigning responsibility to vague groups such as “IT” or “Security” whenever possible. Instead, identify an actual role or owner, such as:
System Administrator
Information Security Manager
Network Engineering Team
Application Owner
Compliance Manager
The assigned owner does not necessarily have to perform every technical task personally. Their responsibility is to make sure the remediation progresses, coordinate with other teams, update milestones, identify blockers, and provide evidence when the issue has been resolved.
For complex findings, multiple teams may be involved. For example, remediation might require the security team to define requirements, IT to configure the system, procurement to purchase software, and compliance personnel to verify the final implementation.
Even in those situations, it is useful to have one primary owner responsible for the overall POA&M item.
15. How Do I Update and Close a POA&M Item After the Issue Is Fixed?
A POA&M should be treated as a living document. Update the entry whenever significant progress occurs, a milestone is completed, a deadline changes, or a new obstacle affects remediation.
Common status labels include:
- Open
- In Progress
- Delayed
- Pending Validation
- Completed
- Closed
Do not close an item simply because someone says the work has been completed. The organization should verify that the corrective action actually resolved the original weakness.
Verification might include reviewing screenshots or configuration settings, examining updated policies, rerunning a vulnerability scan, performing control testing, reviewing system logs, or conducting a retest.
Once remediation has been verified, record the completion date and retain evidence showing what was changed. The POA&M entry can then be marked as completed or closed according to the organization’s tracking process.
Keeping this evidence is particularly important because auditors, assessors, customers, or authorization officials may later ask how the organization confirmed that the weakness was properly remediated.
Using a POA&M as an Operational Remediation Record
A well-maintained Plan of Action and Milestones turns assessment findings into assigned, measurable work. Its value comes from documented ownership, realistic milestones, evidence collection, independent or program-required validation, and clear approval of closure or exceptions. Requirements still come from the applicable contract, regulation, framework, or authorization program.
Bright Defense POA&M and Compliance Support
Bright Defense helps organizations identify control gaps, build remediation plans, collect evidence, and prepare for assessments. Our vCISO services can provide program ownership and management support, while our security assessment and remediation services can help validate weaknesses and corrective actions.
Engagement scope and deliverables are matched to the applicable framework, contract, and assessment requirements rather than treating a POA&M as proof of compliance.



