POA&M Rules Under CMMC: What You Can Defer and What You Can’t

Flowchart showing CMMC POA&M rules for what contractors can and cannot defer

Table of Contents

Many contractors treat a POA&M like a safety net. The thinking goes: fail a few controls, write them onto a plan, promise to fix them later, and still win the contract. Under CMMC, that assumption can end your assessment on day one.

A Plan of Action and Milestones (POA&M) is a clear document that shows security gaps and how you will close them, helping contractors feel more confident in their compliance journey. Under the CMMC final rule, POA&Ms exist, but they cover far less than most people expect. The rule spells out a minimum score, a short list of deferrable items, a list of controls you can never defer, and a hard deadline.

Here is the short version. You can defer only minor, low-weight gaps, and only if you already meet most of your requirements. Everything critical must be done before your assessment. This article breaks down the exact CMMC POA&M rules so you understand what counts as deferrable and what does not, helping you feel more prepared and confident.

Key Takeaways

  1. A POA&M lets you achieve Conditional CMMC Status, not full certification.
  2. You qualify only if your score is at least 80% of your Level 2 requirements.
  3. You can defer only 1-point controls, plus one encryption exception (SC.L2-3.13.11).
  4. Six specific controls can never go on a POA&M, no matter their point value.
  5. You have 180 days to close every POA&M item and pass a closeout assessment.
  6. CMMC Level 1 does not allow POA&Ms at all.

What Is a POA&M Under CMMC?

A POA&M under CMMC is a formal plan that documents security requirements you have not yet met, along with the steps and timeline to fix them. It allows a contractor to earn a temporary, conditional pass while remediation is underway.

The keyword is conditional. A POA&M does not give you full CMMC certification. It gives you Conditional CMMC Status, which starts a clock. You still have to close the gaps and prove it.

Definition: POA&M (Plan of Action and Milestones) is a tracked list of unmet security requirements and the actions, resources, and dates needed to meet them. Under CMMC, it enables only a conditional status, not final certification.

The 80% Rule: You Have to Pass Most of It First

Before a POA&M is an option, you must meet the 80% scoring threshold, ensuring your assessment score divided by the total requirements is at least 0.8, which is critical for passing.

For CMMC Level 2, that means you need to meet at least 80% of your controls. Level 2 aligns with the 110 security requirements in NIST Special Publication 800-171. So 80% works out to meeting at least 88 of those 110 controls.

If you fall below that line, a POA&M cannot save you. You do not get Conditional Status. You fail the assessment and have to remediate and try again.

Expert tip: The 80% threshold is a minimum, not a goal. Aim to pass everything. A POA&M should catch a few stragglers, not carry a long list of unfinished work, encouraging contractors to aim higher and feel motivated to complete all requirements.

What You Can Defer

The deferrable list is short by design. Under the rule, you can place a requirement on a POA&M only if it is worth 1 point in the Department of Defense scoring methodology, which weights each control at 1, 3, or 5 points based on its security impact.

In practice, that means:

  • Only 1-point controls qualify: These are the lower-impact requirements.
  • One higher-value exception exists: CUI Encryption (SC.L2-3.13.11) can go on a POA&M in the specific case where you use encryption, but it is not yet FIPS-validated.

Controlled Unclassified Information (CUI) is sensitive government data that is not classified but still requires protection. Because encryption of that data is so important, the rule treats the encryption exception narrowly.

What You Can Never Defer

This is where contractors get caught. Two categories can never sit on a POA&M.

Controls worth 3 or 5 points, like access control and multi-factor authentication, must be fully implemented and can never be deferred, emphasizing their importance.

Second, six specific Level 2 controls are prohibited from POA&Ms regardless of their point value:

Control ID What It Covers
AC.L2-3.1.20 External system connections (CUI)
AC.L2-3.1.22 Control of public information (CUI)
CA.L2-3.12.4 System Security Plan
PE.L2-3.10.3 Escorting visitors (CUI areas)
PE.L2-3.10.4 Physical access logs (CUI)
PE.L2-3.10.5 Managing physical access (CUI)

Notice the System Security Plan (SSP) on that list. The SSP is the document that describes how you meet each requirement. If it is missing or incomplete, you cannot defer it. No SSP means no path to certification.

The 180-Day Closeout Clock

A POA&M is not open-ended. Once you receive Conditional CMMC Status, the countdown starts.

Once you receive Conditional CMMC Status, you have exactly 180 days from that date to close all POA&M items and pass a closeout assessment, making timely action essential.

Who performs the closeout depends on your assessment type. For a Level 2 self-assessment, your organization confirms the fixes. For a certification assessment, a Certified Third-Party Assessment Organization (C3PAO) validates them.

Miss the 180-day deadline and your Conditional CMMC Status expires. At that point, you are no longer covered, which can put your eligibility and your contract at risk.

Why This Matters Even During the CMMC Pause

The Department of War suspended CMMC Phase 2 third-party assessments in July 2026 and opened a review. That pause changed the assessment timeline, but it did not change the standard. The POA&M rules in 32 CFR 170.21 still define what a passing result looks like.

So the pause is preparation time, not permission to relax. If you know which of your gaps are deferrable and which are not, you can spend this window closing the ones that would otherwise sink you. When assessments resume, you will be ready instead of scrambling.

Common POA&M Mistakes to Avoid

The rules are unforgiving, and the same errors trip up contractors again and again. Watch for these:

  • Treating the POA&M as a catch-all. It only covers minor, low-point gaps, not major ones.
  • Leaving the SSP incomplete. The System Security Plan cannot be deferred and must match reality.
  • Overstating your SPRS score. Your Supplier Performance Risk System (SPRS) entry must reflect what is truly implemented, not what you hope to finish.
  • Ignoring the clock. The 180-day window moves fast once remediation involves new tools, training, or documentation.
  • Assuming Level 1 works the same way. It does not. Level 1 self-assessments allow no POA&Ms at all.

How CyberX Gov Solutions Can Help

The hardest part of CMMC is not the POA&M itself. It is knowing your real position before an assessor tells you. A gap that looks minor may turn out to be a 5-point control or one of the six that can never be deferred.

CyberX Gov Solutions helps small and mid-sized contractors get ahead of that. Through the Get Fed Ready™ program, we help you understand your requirements, review your documentation, and map which gaps are deferrable and which must be fixed first. That way, you walk into your assessment knowing your score and your plan, not guessing at them.

The Bottom Line

CMMC POA&M rules reward contractors who prepare and punish those who count on deferring their way through. You can defer only 1-point gaps, only if you already meet 80% of your controls, and never the six named exceptions or your System Security Plan. Then the 180-day clock starts.

Treat the POA&M as a short bridge for small gaps, not a plan to finish later. Know your score, close the controls that cannot wait, and use any delay in the assessment schedule to get genuinely ready.

Not sure which of your gaps you can defer?

Do not wait for an assessor to find out the hard way. CyberX Gov Solutions can help your team assess your current CMMC position, prioritize the controls you must fix first, and build a realistic path to certification.
Schedule a free consultation at cyberxgovsolutions.com/schedule-a-meeting/

Frequently Asked Questions

What is a POA&M in CMMC?

A POA&M, or Plan of Action and Milestones, is a document listing security requirements you have not met and how you will fix them. Under CMMC, it lets you earn Conditional CMMC Status while you remediate, but it does not grant full certification on its own.

Can you get CMMC certified with a POA&M?

Not fully, at least not right away. A POA&M grants only Conditional CMMC Status. You must close every item and pass a closeout assessment within 180 days to reach full certification. If you miss that deadline, your conditional status expires.

What is the minimum score to qualify for a CMMC POA&M?

You need to meet at least 80% of your requirements. Under 32 CFR 170.21, your assessment score divided by total requirements must be 0.8 or higher. For Level 2, that means meeting at least 88 of the 110 NIST SP 800-171 controls.

What controls cannot be placed on a CMMC POA&M?

Any control worth 3 or 5 points must be fully met and cannot be deferred. Six specific Level 2 controls are also prohibited regardless of value, including the System Security Plan (CA.L2-3.12.4), external connection controls, and three physical access controls.

How long do you have to close a CMMC POA&M?

You have 180 days from your Conditional CMMC Status Date. Within that window, you must remediate every open item and pass a closeout assessment that re-checks the previously unmet controls. A self-assessment closeout is done internally, while a certification closeout requires a C3PAO.

Does CMMC Level 1 allow POA&Ms?

No. CMMC Level 1 self-assessments do not permit POA&Ms at any time. You must meet all 15 Level 1 requirements fully. The POA&M option applies only to Level 2 and Level 3, and even then under the strict conditions set in the rule.

Is a POA&M the same as a CMMC waiver?

No. A POA&M is a self-managed remediation plan for minor gaps. A waiver is a rare, government-granted exception issued at the contract level for specific mission needs. Most contractors will never see a waiver, so plan to meet the requirements rather than expecting one.

What happens if I overstate my readiness in SPRS?

Your SPRS score must reflect what you have actually implemented, not what you plan to finish. Overstating your status can undermine your compliance standing and create serious credibility problems during an assessment. Keep your System Security Plan accurate and your reported score honest.