Skip to the main content.

2 min read

What is a POA&M in CMMC?

What is a POA&M in CMMC?
3:24

If you're an Idaho defense contractor navigating CMMC compliance, you've probably run into the term POA&M. What an acronym — CMMC has several of them. But once it's spelled out, a Plan of Actions and Milestones isn't complicated. It's a documented commitment: here's a control we haven't fully implemented yet, here's what we're going to do about it, and here's when it will be done.

What a POA&M is and how it works

Under CMMC, a POA&M allows a DIB company to receive contract awards even if it hasn't fully implemented every NIST SP 800-171 control — provided it meets a baseline threshold of requirements first and has a credible, time-bound plan to close the remaining gaps.

The key rules: critical and highly weighted controls are not eligible for a POA&M. You have to have those in place. The remaining subset can be addressed on a POA&M timeline, but that timeline is binding — if it's not closed by the designated date, the contract award can be revoked.

A well-structured POA&M entry includes:

  • The specific control that isn't yet fully implemented
  • A description of the weakness or gap
  • The remediation steps planned
  • The resources and responsible parties assigned
  • A scheduled completion date
  • Interim mitigation measures already in place

NIST provides a free Excel template to help organizations build their POA&M. It's a reasonable starting point, though organizations managing larger environments typically need something more structured.

POA&M

Image from NIST

What the Phase II suspension means for POA&Ms

On July 13, 2026, the Department of War suspended CMMC Phase II — the mandatory third-party C3PAO assessments that were scheduled to begin November 10, 2026. A 60-day CMMC Reform Task Force is reviewing the program, with findings expected around mid-September.

What this doesn't change: Phase I self-assessments are still active and required. If your organization is completing a Level 1 or Level 2 self-assessment and submitting your score in SPRS, POA&Ms are still part of that process. The suspension paused external verification, not your obligation to document gaps and close them on schedule.

Why the timeline matters more now, not less

With Phase II on hold, some contractors may be tempted to slow down their compliance work. That would be a mistake.

The Department of Justice's Civil Cyber-Fraud Initiative continues to pursue contractors who self-attest to compliance scores that don't reflect reality. If your SPRS score reflects a POA&M that you're not actually working to close, that's not a paperwork problem — it's a False Claims Act exposure. Recent settlements have run into the hundreds of thousands of dollars.

A POA&M only works as a protection if it's being actively executed. "We planned to fix it" is defensible. "We said we planned to fix it and then didn't" is not.

TotalCare IT can help

We help Idaho DIB companies and their subcontractors assess where they stand against NIST SP 800-171 Rev 2 controls, identify what needs a POA&M, build a realistic remediation roadmap, and stay on track to close it.

Implementing security controls doesn't happen overnight, and with FCA enforcement active and the Phase II review underway, now is the time to make sure your documentation reflects your actual posture. Contact TotalCare IT to get started.

What Idaho DIB Companies Need to Know About CMMC Right Now

1 min read

What Idaho DIB Companies Need to Know About CMMC Right Now

If you're an Idaho company doing business with the Department of War — whether as a prime contractor or a subcontractor — CMMC has been a moving...

Read More
How Compliance Standards Like CMMC & NIST Affect Idaho Manufacturers

1 min read

How Compliance Standards Like CMMC & NIST Affect Idaho Manufacturers

When most Idaho manufacturers think about compliance, the first thing that comes to mind is OSHA safety standards, environmental regulations, or...

Read More
Why OT Security Belongs in Every Manufacturer’s Playbook

1 min read

Why OT Security Belongs in Every Manufacturer’s Playbook

On a manufacturing floor, technology isn’t just computers—it’s the heartbeat of your operations. From production lines and robotics to SCADA systems...

Read More