CMMC and NIST 800-171
POA&Ms: What They Cover and the 180 Day Clock
Level 2 of the Cybersecurity Maturity Model Certification (CMMC) and NIST SP 800-171 both require a POA&M, or Plan of Action and Milestones. This document lays out your plans for addressing gaps in security controls and helps you track remediation efforts. The 180 day remediation window gives you a set period to fix issues, which plays an important role in meeting compliance obligations and managing risk.
What is a POA&M and why do you need one?
A POA&M is a documented plan that outlines specific actions your company will take to address cybersecurity gaps identified during a self assessment or internal review. For each gap, the POA&M must define what needs to be fixed, who is responsible, and the timeline for completion. This process is not optional if you find that any of the 320 assessment objectives under the 110 NIST SP 800-171 controls are not fully met. The requirement for POA&Ms comes directly from the CMMC Scoping and Assessment Guides and is aligned with NIST SP 800-171A.
DFARS 252.204-7012 and NIST SP 800-171 Rev 2 require you to safeguard CUI and document both your System Security Plan (SSP) and any gaps through a POA&M. These documents must be available for review during a government-led assessment, and your SPRS score must reflect your actual state of compliance.
How does a POA&M work at CMMC Level 2?
At Level 2, you are required to implement all 110 NIST SP 800-171 Rev 2 controls. The CMMC Scoping and Assessment Guide Level 2 v2.13 is clear: every assessment objective under each control must be met for the control to be considered fully implemented. If you identify a gap, meaning an objective is not met, you must document it in a POA&M.
The POA&M must include:
- The specific control and objective not met (for example, AC.L2-3.1.5 for Least Privilege).
- The reason for the gap.
- The actions planned to remediate the gap.
- The responsible party.
- The scheduled completion date.
Importantly, you cannot simply leave a gap unaddressed. The Department of Defense expects you to remediate all POA&M items within 180 days of identification. This 180 day clock is a hard deadline for closing gaps and updating your self assessment and SPRS score. If you do not complete remediation within this window, you are not fully compliant and your senior official’s annual affirmation may be at risk.
What happens to POA&Ms at Level 3?
POA&Ms are not permitted at Level 3. At this level, your environment must be fully compliant with all 110 NIST SP 800-171 Rev 2 controls plus 24 enhanced controls from NIST SP 800-172. Assessment is conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and every assessment objective must be met at the time of assessment. If you have any open POA&M items, your environment does not qualify for Level 3. This is stated in the CMMC Scoping and Assessment Guide and 32 CFR Part 170.
What does the 180 day POA&M clock mean for your business?
Once you identify a gap during your self assessment, the 180 day timeline begins. You must document your plan, execute remediation, and update your records within that period. This timeline is enforced by the Department of Defense through ongoing self assessment requirements under DFARS 252.204-7012 and annual senior official affirmation. The government has stated it will continue to enforce compliance through self assessments and select government-led reviews, even while third party certification is suspended.
Failing to remediate within 180 days, or inaccurately representing your state of compliance, increases your exposure to False Claims Act liability. The signature of your senior official on the annual affirmation is now the primary assurance to the government, as the requirement for third party certification is currently suspended.
What must a POA&M contain to satisfy CMMC and NIST SP 800-171?
A valid POA&M must be specific and actionable. It cannot be a general statement that you will fix something at some point. The CMMC Scoping and Assessment Guide Level 2 v2.13 requires you to state the control, the specific gap, planned actions, responsible party, and deadline. The POA&M must tie directly to your SSP and be updated as you make progress. Documentation alone is not proof; you must be able to show evidence of execution, system logs, configuration screenshots, or other timestamped artifacts.
What are the risks of ignoring or mishandling POA&Ms?
If you fail to maintain accurate POA&Ms, you risk both compliance violations and contractual liability. The Department of Defense has taken enforcement action against companies that falsely certified compliance or failed to remediate known vulnerabilities. For example, Health Net Federal Services was found to have certified compliance without scanning and remediating vulnerabilities, and Aero Turbine was cited for failing controls and sharing defense data with an unauthorized foreign entity. In these cases, liability extended more than to the companies, but also to prime contractors, subcontractors, and private equity owners.
Maintaining accurate POA&Ms is more than a paperwork exercise. It is a core part of your legal and contractual obligations to the government.
Can you use POA&Ms to manage partial compliance at Level 2?
You may use POA&Ms to document and manage gaps at Level 2, but only if you are actively working to remediate those gaps within the 180 day window. Your SPRS score must accurately reflect your current state, including any open POA&M items. You must update your SSP and POA&M as you close gaps. If you reach the end of the 180 days with open items, you are no longer considered compliant for those controls.
Common questions
What is the difference between an SSP and a POA&M? An SSP (System Security Plan) describes your system and how you meet each required control. A POA&M documents the specific actions you will take to address any gaps found during assessment.
Can I submit a POA&M instead of being fully compliant at Level 2? You may use a POA&M to document gaps, but you must remediate all items within 180 days. Your SPRS score must reflect your actual status, and your annual affirmation must be accurate.
What happens if I do not remediate a POA&M item within 180 days? You are not considered compliant for that control, and your annual affirmation may be invalid. This increases your risk of enforcement action or False Claims Act liability.
For more on CMMC and NIST SP 800-171 requirements, you can review NIST SP 800-171 Rev 2 directly from NIST.
How to Track Your 180 Day POA&M Timeline
If you need help assessing your current compliance or closing POA&M items, consider applying for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more and apply at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.