POA&M

Track remediation of compliance gaps and risks as a Plan of Action & Milestones — targets, milestones, status, and system scope — and see how open and overdue items shape your SPRS score and posture.

A Plan of Action & Milestones (POA&M) is your documented plan to fix a security requirement that isn't met yet. Each item names the gap, who owns it, what will be done, the systems it affects, and a target completion date — so a not-yet-implemented practice becomes a tracked commitment instead of an open question.

CMMC and NIST SP 800-171 expect exactly this: where a control isn't fully in place, you record a plan to close it. Under the CMMC program a limited set of not-yet-met requirements may be carried on a POA&M for a conditional result, provided your SPRS score clears the program minimum and each item is closed within the program's deadline. Higher-weight requirements are not POA&M-eligible and must be met outright. This module is where those plans live, and their status feeds your compliance posture, your SPRS view, the SSP, and the AI connector.

POA&Ms live inside your assessment — open an assessment and use its POA&M tab to see every item for that assessment. Each system also shows the POA&Ms that apply to it. Viewing is open to any role that can read compliance data; creating and editing require a manager role — see Permissions.

Key concepts

What a POA&M item holds

Every item is one remediation plan, anchored to an assessment and to one or more failing objectives.

FieldWhat it captures
Title & descriptionA short name for the gap and a plain-language plan for closing it
ObjectivesThe specific NIST SP 800-171 objective(s) the plan addresses — a POA&M can cover several
AssigneeThe person accountable for getting it done
Target completion dateWhen you expect the gap to be closed
StatusWhere the item sits in its lifecycle
ScopeWhether the item applies to all systems or to specific systems

Status

A POA&M moves through a short lifecycle. The status drives whether it counts as open work and whether it shows as completed.

StatusMeaning
Not startedLogged, work hasn't begun
In progressRemediation is underway
CompletedThe gap is closed — excluded from open and overdue counts
An item is overdue when its target date has passed and it isn't yet Completed. Marking it Completed clears it from both the open and overdue counts.

Scope — all systems vs. specific systems

Scope decides which systems a POA&M applies to. This matters because your environment usually has several systems, and not every gap touches all of them.

ScopeApplies toUse it when
All systemsEvery system in the assessmentThe gap is organization-wide (e.g. a missing policy or an enterprise control)
Specific systemsOnly the systems you pickThe gap lives on particular systems (e.g. one enclave lacks a control the rest already have)
An all-systems POA&M carries no per-system list — it's understood to cover everything, and it appears on every system automatically. A specific-systems POA&M carries the exact list of systems you chose and appears only on those. The two are never mixed: switching an item to all-systems clears its system list, and switching to specific systems is where you name the systems.

Using POA&Ms

You'll find POA&Ms in two places: an assessment's POA&M tab (the full library for that assessment, with summary tiles for Overdue, Due Soon, In Progress, and Completed) and each system page (the items that apply to that system). You can create an item from a compliance gap, from a risk, or from scratch.

Create a POA&M from a gap

The most common path — you're looking at a control that isn't met and want to commit to fixing it.

Start a new POA&M

From the assessment's POA&M tab, begin a new item.

Choose the objectives

Pick the failing objective(s) this plan will address. One POA&M can cover several objectives that will be closed together.

Describe the plan

Give it a title and write the description — what's needed and what you'll do. This is what an assessor and your team read to understand the remediation.

Set scope

Choose all systems or specific systems. If specific, pick the systems the gap applies to.

Assign an owner and target date

Set an assignee and a target completion date, then save. The item appears in the library with status Not started.

Create a POA&M from a risk

When a risk in your Risk Register represents a compliance gap, you can raise a POA&M straight from it — the risk's context comes along so the plan lands fully populated.

Open the risk

From the register, expand the risk and open its POA&M section.

Create the POA&M

Create a new POA&M from the risk. Its owner becomes the assignee, its treatment plan becomes the description, its linked systems set the scope (specific systems if the risk names any, otherwise all systems), and its CMMC family resolves the objectives.

Raising a POA&M from a risk is idempotent — if the risk already has one, the same POA&M is returned instead of a duplicate. The risk keeps a link to the item so the two stay connected; if the POA&M is later removed, the link simply clears.

Create a POA&M manually

You can also log an item from a blank form — useful for planned work that isn't yet pinned to a single risk. You still choose at least one objective, set scope, and give it an owner and target date.

Work an item to completion

Move it to In progress

As remediation begins, set the status to In progress so it reads as active work.

Update the plan and target as needed

Refine the description, reassign the owner, adjust the objectives, or push the target date if the timeline changes.

Mark it Completed

When the gap is closed, set the status to Completed. It drops out of your open and overdue counts and shows in the completed tally.

Keep target dates honest. Because overdue is derived from the target date, letting dates slip silently understates the problem — either do the work or move the date deliberately.

Permissions

Access is governed by the role matrix.

CapabilityPermission
View POA&Ms on assessments and systems(any role that can read compliance data)
Create, edit, delete, set scope, change statusCREATE_POAM

CREATE_POAM is held by Org Admin, Org User, and MSP Super. It is not held by Assessor (read-only), Platform Admin, or MSP Admin. Every POA&M change — creating, editing, re-scoping, reassigning, or completing — requires it.

POA&Ms are always scoped to the organization that owns the assessment. A user can only ever see and change the POA&Ms belonging to their own organization's assessments — there is no cross-organization access.

How it works

Extra detail on what the module stores and how it behaves — product behavior, not internals.

What a POA&M item stores

Each item is one plan tied to a single assessment.

Title & description
A short name (required) and the free-text remediation plan.
Objectives
one or more
The NIST SP 800-171 objectives this plan will close. A single POA&M can address several at once.
Status
Not started, In progress, or Completed.
Target completion date
When you expect the gap to be closed. Drives the overdue and due-soon signals.
Assignee
The person accountable for the remediation.
Scope
All systems, or a specific list of systems the item applies to.
Linked risk
If the item was raised from a risk, the two stay connected.

How open, overdue, and due-soon are counted

The library summarizes your items into a few plain signals:

  • Open — anything not yet Completed.
  • Overdue — past its target date and not Completed.
  • Due Soon — a target date within the next 30 days and not Completed.
  • Completed — closed items, kept for the record but out of the open and overdue counts.
Completed items are deliberately excluded from open and overdue so they can't distort your remaining workload. They stay in the library as a record of closed remediation.

How POA&Ms connect to your SPRS score and posture

A POA&M records the plan to fix a gap; it doesn't change whether the gap is met. Your SPRS score and completion percentages come from the actual implementation status of each objective — a control counts only when all of its in-scope objectives are satisfied. So an open POA&M sits alongside a not-yet-met control: it tracks the promise to close it, while the score still reflects that it's open today. When you complete the remediation and mark the objectives implemented, the score rises on its own.

Because CMMC lets you certify conditionally on a limited POA&M, the open and overdue counts are the operational read on that path: they show how much remediation is outstanding and whether any of it has slipped past its deadline. Overdue items are the ones most likely to jeopardize a conditional result.

How POA&Ms connect to risks and objectives

  • To objectives: every POA&M points at the specific NIST SP 800-171 objectives it will close, so the plan is anchored to real gaps rather than a vague intention. Those same objectives drive your completion metrics.
  • To risks: a risk that maps to a compliance gap can raise a POA&M, and the two stay linked — the risk shows its remediation is tracked, and the POA&M carries the risk's owner, plan, systems, and CMMC family. See Risk Management.

AI assistant access

When the AI Connector is enabled, assistants can read (never change) your POA&Ms:

  • get_poam_items — the open items for an assessment (completed items excluded), each with its control reference, weakness, status, target date, and milestones, plus the open and total counts.

Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.


Risk Management

Raise a POA&M straight from a risk and keep the two linked.

Compliance Ops

Turn recurring remediation into scheduled operational tasks.

AI Connector

Read your open POA&M items through an AI assistant.