---
title: POA&M
description: Track remediation of compliance gaps and risks as a Plan of Action & Milestones — targets, milestones, status, and system scope — and see how open and overdue items shape your SPRS score and posture.
navigation:
  icon: i-lucide-list-checks
---

# POA&M (Plan of Action & Milestones)

A **Plan of Action & Milestones (POA&M)** is your documented plan to fix a security requirement that isn't met yet. Each item names the gap, who owns it, what will be done, the systems it affects, and a **target completion date** — so a not-yet-implemented practice becomes a tracked commitment instead of an open question.

CMMC and NIST SP 800-171 expect exactly this: where a control isn't fully in place, you record a plan to close it. Under the CMMC program a limited set of not-yet-met requirements may be carried on a POA&M for a **conditional** result, provided your **SPRS score** clears the program minimum and each item is closed within the program's deadline. Higher-weight requirements are **not** POA&M-eligible and must be met outright. This module is where those plans live, and their status feeds your **compliance posture**, your **SPRS** view, the **SSP**, and the **AI connector**.

::note
POA&Ms live inside your assessment — open an assessment and use its **POA&M** tab to see every item for that assessment. Each **system** also shows the POA&Ms that apply to it. Viewing is open to any role that can read compliance data; creating and editing require a manager role — see [Permissions](#permissions).
::

---

## Key concepts

### What a POA&M item holds

Every item is one remediation plan, anchored to an assessment and to one or more failing **objectives**.

| Field | What it captures |
| --- | --- |
| **Title & description** | A short name for the gap and a plain-language plan for closing it |
| **Objectives** | The specific NIST SP 800-171 objective(s) the plan addresses — a POA&M can cover several |
| **Assignee** | The person accountable for getting it done |
| **Target completion date** | When you expect the gap to be closed |
| **Status** | Where the item sits in its lifecycle |
| **Scope** | Whether the item applies to **all systems** or to **specific systems** |

### Status

A POA&M moves through a short lifecycle. The status drives whether it counts as open work and whether it shows as completed.

| Status | Meaning |
| --- | --- |
| :badge[Not started]{color="neutral"} | Logged, work hasn't begun |
| :badge[In progress]{color="info"} | Remediation is underway |
| :badge[Completed]{color="success"} | The gap is closed — **excluded** from open and overdue counts |

::tip
An item is **overdue** when its target date has passed and it isn't yet **Completed**. Marking it Completed clears it from both the open and overdue counts.
::

### Scope — all systems vs. specific systems

Scope decides which systems a POA&M applies to. This matters because your environment usually has several systems, and not every gap touches all of them.

| Scope | Applies to | Use it when |
| --- | --- | --- |
| **All systems** | Every system in the assessment | The gap is organization-wide (e.g. a missing policy or an enterprise control) |
| **Specific systems** | Only the systems you pick | The gap lives on particular systems (e.g. one enclave lacks a control the rest already have) |

::note
An **all-systems** POA&M carries no per-system list — it's understood to cover everything, and it appears on every system automatically. A **specific-systems** POA&M carries the exact list of systems you chose and appears only on those. The two are never mixed: switching an item to all-systems clears its system list, and switching to specific systems is where you name the systems.
::

---

## Using POA&Ms

You'll find POA&Ms in two places: an assessment's **POA&M** tab (the full library for that assessment, with summary tiles for **Overdue**, **Due Soon**, **In Progress**, and **Completed**) and each **system** page (the items that apply to that system). You can create an item from a compliance gap, from a risk, or from scratch.

### Create a POA&M from a gap

The most common path — you're looking at a control that isn't met and want to commit to fixing it.

::steps{level="4"}

#### Start a new POA&M

From the assessment's POA&M tab, begin a new item.

#### Choose the objectives

Pick the failing **objective(s)** this plan will address. One POA&M can cover several objectives that will be closed together.

#### Describe the plan

Give it a **title** and write the **description** — what's needed and what you'll do. This is what an assessor and your team read to understand the remediation.

#### Set scope

Choose **all systems** or **specific systems**. If specific, pick the systems the gap applies to.

#### Assign an owner and target date

Set an **assignee** and a **target completion date**, then save. The item appears in the library with status **Not started**.

::

### Create a POA&M from a risk

When a risk in your [Risk Register](https://app.dibfi.com/dashboard/risk) represents a compliance gap, you can raise a POA&M straight from it — the risk's context comes along so the plan lands fully populated.

::steps{level="4"}

#### Open the risk

From the register, expand the risk and open its POA&M section.

#### Create the POA&M

Create a new POA&M from the risk. Its **owner** becomes the assignee, its **treatment plan** becomes the description, its **linked systems** set the scope (specific systems if the risk names any, otherwise all systems), and its **CMMC family** resolves the objectives.

::

::note
Raising a POA&M from a risk is **idempotent** — if the risk already has one, the same POA&M is returned instead of a duplicate. The risk keeps a link to the item so the two stay connected; if the POA&M is later removed, the link simply clears.
::

### Create a POA&M manually

You can also log an item from a blank form — useful for planned work that isn't yet pinned to a single risk. You still choose at least one objective, set scope, and give it an owner and target date.

### Work an item to completion

::steps{level="4"}

#### Move it to In progress

As remediation begins, set the status to **In progress** so it reads as active work.

#### Update the plan and target as needed

Refine the description, reassign the owner, adjust the objectives, or push the target date if the timeline changes.

#### Mark it Completed

When the gap is closed, set the status to **Completed**. It drops out of your open and overdue counts and shows in the completed tally.

::

::tip
Keep target dates honest. Because **overdue** is derived from the target date, letting dates slip silently understates the problem — either do the work or move the date deliberately.
::

---

## Permissions

Access is governed by the role matrix.

| Capability | Permission |
| --- | --- |
| View POA&Ms on assessments and systems | *(any role that can read compliance data)* |
| Create, edit, delete, set scope, change status | :badge[CREATE_POAM]{color="info"} |

`CREATE_POAM` is held by **Org Admin**, **Org User**, and **MSP Super**. It is **not** held by **Assessor** (read-only), **Platform Admin**, or **MSP Admin**. Every POA&M change — creating, editing, re-scoping, reassigning, or completing — requires it.

::warning
POA&Ms are always scoped to the organization that owns the assessment. A user can only ever see and change the POA&Ms belonging to their own organization's assessments — there is no cross-organization access.
::

---

## How it works

Extra detail on what the module stores and how it behaves — product behavior, not internals.

### What a POA&M item stores

Each item is one plan tied to a single assessment.

:::field-group
::field{name="Title & description"}
A short name (required) and the free-text remediation plan.
::
::field{name="Objectives" type="one or more"}
The NIST SP 800-171 objectives this plan will close. A single POA&M can address several at once.
::
::field{name="Status"}
Not started, In progress, or Completed.
::
::field{name="Target completion date"}
When you expect the gap to be closed. Drives the overdue and due-soon signals.
::
::field{name="Assignee"}
The person accountable for the remediation.
::
::field{name="Scope"}
All systems, or a specific list of systems the item applies to.
::
::field{name="Linked risk"}
If the item was raised from a risk, the two stay connected.
::
:::

### How open, overdue, and due-soon are counted

The library summarizes your items into a few plain signals:

- **Open** — anything not yet **Completed**.
- **Overdue** — past its target date and not Completed.
- **Due Soon** — a target date within the next 30 days and not Completed.
- **Completed** — closed items, kept for the record but out of the open and overdue counts.

::warning
Completed items are deliberately excluded from open and overdue so they can't distort your remaining workload. They stay in the library as a record of closed remediation.
::

### How POA&Ms connect to your SPRS score and posture

A POA&M **records the plan to fix a gap; it doesn't change whether the gap is met.** Your **SPRS score** and completion percentages come from the actual implementation status of each objective — a control counts only when **all** of its in-scope objectives are satisfied. So an open POA&M sits alongside a not-yet-met control: it tracks the promise to close it, while the score still reflects that it's open today. When you complete the remediation and mark the objectives implemented, the score rises on its own.

Because CMMC lets you certify **conditionally** on a limited POA&M, the open and overdue counts are the operational read on that path: they show how much remediation is outstanding and whether any of it has slipped past its deadline. Overdue items are the ones most likely to jeopardize a conditional result.

### How POA&Ms connect to risks and objectives

- **To objectives:** every POA&M points at the specific NIST SP 800-171 objectives it will close, so the plan is anchored to real gaps rather than a vague intention. Those same objectives drive your completion metrics.
- **To risks:** a risk that maps to a compliance gap can raise a POA&M, and the two stay linked — the risk shows its remediation is tracked, and the POA&M carries the risk's owner, plan, systems, and CMMC family. See [Risk Management](https://app.dibfi.com/dashboard/risk).

### AI assistant access

When the [AI Connector](https://app.dibfi.com/dashboard/org-settings) is enabled, assistants can **read** (never change) your POA&Ms:

- **`get_poam_items`** — the **open** items for an assessment (completed items excluded), each with its control reference, weakness, status, target date, and milestones, plus the open and total counts.

Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.

---

## Related features

:::card-group

::card{title="Risk Management" icon="i-lucide-shield-alert" to="https://app.dibfi.com/dashboard/risk"}
Raise a POA&M straight from a risk and keep the two linked.
::

::card{title="Compliance Ops" icon="i-lucide-calendar-check" to="https://app.dibfi.com/dashboard/compliance-ops"}
Turn recurring remediation into scheduled operational tasks.
::

::card{title="AI Connector" icon="i-lucide-bot"}
Read your open POA&M items through an AI assistant.
::

:::
