1 min read
What Idaho DIB Companies Need to Know About CMMC Right Now
If you're an Idaho company doing business with the Department of War — whether as a prime contractor or a subcontractor — CMMC has been a moving...
If you're an Idaho defense contractor navigating CMMC compliance, you've probably run into the term POA&M. What an acronym — CMMC has several of them. But once it's spelled out, a Plan of Actions and Milestones isn't complicated. It's a documented commitment: here's a control we haven't fully implemented yet, here's what we're going to do about it, and here's when it will be done.
Under CMMC, a POA&M allows a DIB company to receive contract awards even if it hasn't fully implemented every NIST SP 800-171 control — provided it meets a baseline threshold of requirements first and has a credible, time-bound plan to close the remaining gaps.
The key rules: critical and highly weighted controls are not eligible for a POA&M. You have to have those in place. The remaining subset can be addressed on a POA&M timeline, but that timeline is binding — if it's not closed by the designated date, the contract award can be revoked.
A well-structured POA&M entry includes:
NIST provides a free Excel template to help organizations build their POA&M. It's a reasonable starting point, though organizations managing larger environments typically need something more structured.

Image from NIST
On July 13, 2026, the Department of War suspended CMMC Phase II — the mandatory third-party C3PAO assessments that were scheduled to begin November 10, 2026. A 60-day CMMC Reform Task Force is reviewing the program, with findings expected around mid-September.
What this doesn't change: Phase I self-assessments are still active and required. If your organization is completing a Level 1 or Level 2 self-assessment and submitting your score in SPRS, POA&Ms are still part of that process. The suspension paused external verification, not your obligation to document gaps and close them on schedule.
With Phase II on hold, some contractors may be tempted to slow down their compliance work. That would be a mistake.
The Department of Justice's Civil Cyber-Fraud Initiative continues to pursue contractors who self-attest to compliance scores that don't reflect reality. If your SPRS score reflects a POA&M that you're not actually working to close, that's not a paperwork problem — it's a False Claims Act exposure. Recent settlements have run into the hundreds of thousands of dollars.
A POA&M only works as a protection if it's being actively executed. "We planned to fix it" is defensible. "We said we planned to fix it and then didn't" is not.
We help Idaho DIB companies and their subcontractors assess where they stand against NIST SP 800-171 Rev 2 controls, identify what needs a POA&M, build a realistic remediation roadmap, and stay on track to close it.
Implementing security controls doesn't happen overnight, and with FCA enforcement active and the Phase II review underway, now is the time to make sure your documentation reflects your actual posture. Contact TotalCare IT to get started.
1 min read
If you're an Idaho company doing business with the Department of War — whether as a prime contractor or a subcontractor — CMMC has been a moving...
1 min read
When most Idaho manufacturers think about compliance, the first thing that comes to mind is OSHA safety standards, environmental regulations, or...
1 min read
On a manufacturing floor, technology isn’t just computers—it’s the heartbeat of your operations. From production lines and robotics to SCADA systems...