POA&M
A Plan of Action & Milestones (POA&M) is your documented plan to fix a security requirement that isn't met yet. Each item names the gap, who owns it, what will be done, the systems it affects, and a target completion date — so a not-yet-implemented practice becomes a tracked commitment instead of an open question.
CMMC and NIST SP 800-171 expect exactly this: where a control isn't fully in place, you record a plan to close it. Under the CMMC program a limited set of not-yet-met requirements may be carried on a POA&M for a conditional result, provided your SPRS score clears the program minimum and each item is closed within the program's deadline. Higher-weight requirements are not POA&M-eligible and must be met outright. This module is where those plans live, and their status feeds your compliance posture, your SPRS view, the SSP, and the AI connector.
Key concepts
What a POA&M item holds
Every item is one remediation plan, anchored to an assessment and to one or more failing objectives.
| Field | What it captures |
|---|---|
| Title & description | A short name for the gap and a plain-language plan for closing it |
| Objectives | The specific NIST SP 800-171 objective(s) the plan addresses — a POA&M can cover several |
| Assignee | The person accountable for getting it done |
| Target completion date | When you expect the gap to be closed |
| Status | Where the item sits in its lifecycle |
| Scope | Whether the item applies to all systems or to specific systems |
Status
A POA&M moves through a short lifecycle. The status drives whether it counts as open work and whether it shows as completed.
| Status | Meaning |
|---|---|
| Not started | Logged, work hasn't begun |
| In progress | Remediation is underway |
| Completed | The gap is closed — excluded from open and overdue counts |
Scope — all systems vs. specific systems
Scope decides which systems a POA&M applies to. This matters because your environment usually has several systems, and not every gap touches all of them.
| Scope | Applies to | Use it when |
|---|---|---|
| All systems | Every system in the assessment | The gap is organization-wide (e.g. a missing policy or an enterprise control) |
| Specific systems | Only the systems you pick | The gap lives on particular systems (e.g. one enclave lacks a control the rest already have) |
Using POA&Ms
You'll find POA&Ms in two places: an assessment's POA&M tab (the full library for that assessment, with summary tiles for Overdue, Due Soon, In Progress, and Completed) and each system page (the items that apply to that system). You can create an item from a compliance gap, from a risk, or from scratch.
Create a POA&M from a gap
The most common path — you're looking at a control that isn't met and want to commit to fixing it.
Start a new POA&M
From the assessment's POA&M tab, begin a new item.
Choose the objectives
Pick the failing objective(s) this plan will address. One POA&M can cover several objectives that will be closed together.
Describe the plan
Give it a title and write the description — what's needed and what you'll do. This is what an assessor and your team read to understand the remediation.
Set scope
Choose all systems or specific systems. If specific, pick the systems the gap applies to.
Assign an owner and target date
Set an assignee and a target completion date, then save. The item appears in the library with status Not started.
Create a POA&M from a risk
When a risk in your Risk Register represents a compliance gap, you can raise a POA&M straight from it — the risk's context comes along so the plan lands fully populated.
Open the risk
From the register, expand the risk and open its POA&M section.
Create the POA&M
Create a new POA&M from the risk. Its owner becomes the assignee, its treatment plan becomes the description, its linked systems set the scope (specific systems if the risk names any, otherwise all systems), and its CMMC family resolves the objectives.
Create a POA&M manually
You can also log an item from a blank form — useful for planned work that isn't yet pinned to a single risk. You still choose at least one objective, set scope, and give it an owner and target date.
Work an item to completion
Move it to In progress
As remediation begins, set the status to In progress so it reads as active work.
Update the plan and target as needed
Refine the description, reassign the owner, adjust the objectives, or push the target date if the timeline changes.
Mark it Completed
When the gap is closed, set the status to Completed. It drops out of your open and overdue counts and shows in the completed tally.
Permissions
Access is governed by the role matrix.
| Capability | Permission |
|---|---|
| View POA&Ms on assessments and systems | (any role that can read compliance data) |
| Create, edit, delete, set scope, change status | CREATE_POAM |
CREATE_POAM is held by Org Admin, Org User, and MSP Super. It is not held by Assessor (read-only), Platform Admin, or MSP Admin. Every POA&M change — creating, editing, re-scoping, reassigning, or completing — requires it.
How it works
Extra detail on what the module stores and how it behaves — product behavior, not internals.
What a POA&M item stores
Each item is one plan tied to a single assessment.
How open, overdue, and due-soon are counted
The library summarizes your items into a few plain signals:
- Open — anything not yet Completed.
- Overdue — past its target date and not Completed.
- Due Soon — a target date within the next 30 days and not Completed.
- Completed — closed items, kept for the record but out of the open and overdue counts.
How POA&Ms connect to your SPRS score and posture
A POA&M records the plan to fix a gap; it doesn't change whether the gap is met. Your SPRS score and completion percentages come from the actual implementation status of each objective — a control counts only when all of its in-scope objectives are satisfied. So an open POA&M sits alongside a not-yet-met control: it tracks the promise to close it, while the score still reflects that it's open today. When you complete the remediation and mark the objectives implemented, the score rises on its own.
Because CMMC lets you certify conditionally on a limited POA&M, the open and overdue counts are the operational read on that path: they show how much remediation is outstanding and whether any of it has slipped past its deadline. Overdue items are the ones most likely to jeopardize a conditional result.
How POA&Ms connect to risks and objectives
- To objectives: every POA&M points at the specific NIST SP 800-171 objectives it will close, so the plan is anchored to real gaps rather than a vague intention. Those same objectives drive your completion metrics.
- To risks: a risk that maps to a compliance gap can raise a POA&M, and the two stay linked — the risk shows its remediation is tracked, and the POA&M carries the risk's owner, plan, systems, and CMMC family. See Risk Management.
AI assistant access
When the AI Connector is enabled, assistants can read (never change) your POA&Ms:
get_poam_items— the open items for an assessment (completed items excluded), each with its control reference, weakness, status, target date, and milestones, plus the open and total counts.
Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.
Related features
Compliance Operations
Keep your CMMC posture current between assessments with a calendar of recurring compliance tasks — scheduled by cadence, completed with a guided checklist, and turned into dated evidence automatically.
Reviews & Readiness
Request an expert reviewer to validate your evidence, SSP, and scope before a formal C3PAO assessment, receive a readiness score and written findings, and track each review from request to completed report.

