Most defense contractors know they are supposed to have a Plan of Action and Milestones. Fewer understand what it does inside the CMMC framework. Almost none are managing it with the rigor the current enforcement environment demands.
A POA&M is not a compliance placeholder. Under the 2025 DFARS final rule, it is a time-bound legal instrument that determines whether your organization qualifies for Conditional CMMC Level 2 status, how long that status remains valid, and whether your SPRS record will satisfy a contracting officer's pre-award verification check.
Managed poorly, a POA&M does not protect your compliance posture. It documents the gap that disqualifies you.
This blog covers how POA&Ms function within the current CMMC Level 2 framework, the 180-day remediation clock, what third-party assessors examine, and the specific management failures that are moving contractors from conditional eligibility to disqualified, quietly, before they reach evaluation.
A Plan of Action and Milestones identifies security control deficiencies, describes the remediation steps required to close each gap, assigns ownership, and establishes target completion dates. In the context of CMMC Level 2, a POA&M is the mechanism that allows a contractor to receive Conditional status when the full 110-point SPRS threshold has not yet been achieved.
The CMMC Level 2 Assessment Guide and DoD guidance establish a specific scoring framework that governs how POA&Ms interact with certification status. A fully compliant environment earns a score of 110. Unmet controls produce deductions, and scores can fall as low as negative 203 for organizations with widespread deficiencies. Organizations scoring between approximately 88 and 109 points may qualify for Conditional CMMC Level 2 status, provided that each deficiency is documented in an approved POA&M and all items are closed within 180 days of the assessment.
Final CMMC Level 2 certification requires a score of 110 with all POA&M items closed. Conditional status is not equivalent to Final status for all contracting purposes. Requiring activities with higher-risk programs may mandate Final certification as an award condition regardless of POA&M documentation.
The 180-day window is a hard deadline. Organizations that do not close all POA&M items within 180 days of their assessment lose Conditional status and may be required to initiate a new assessment cycle. For organizations managing active contracts or pursuing new awards, losing Conditional status mid-cycle is both an operational and a competitive problem.
Treating POA&Ms as Documentation Rather Than Execution Plans
The most common POA&M failure is treating the document as a compliance artifact rather than an active management tool. Organizations create a POA&M during their self-assessment, assign general completion dates, and file it. Nobody owns the remediation milestones. Nobody tracks progress. Nobody confirms when items are actually closed.
When a C3PAO assessor or contracting officer reviews the POA&M, they are not looking for a list of acknowledged deficiencies. They are looking for evidence that remediation is actively underway: documented progress updates, completed control implementations verified against assessment objectives, and accurate status flags that distinguish open items from closed ones.
A POA&M created six months ago and never updated since is not a compliant POA&M. It is evidence of a compliance program that exists on paper but not in practice. Under the False Claims Act framework that governs SPRS self-attestation, that distinction has legal consequences, not just compliance ones.
Missing the 180-Day Closure Deadline Without Escalation
The 180-day remediation clock begins at the time of assessment. For self-assessed organizations, it starts when the assessment is recorded in SPRS. For C3PAO-assessed organizations, it starts when the formal assessment findings are documented.
Many contractors are missing this deadline not because the remediation work is impossible, but because the deadline is not being tracked as a hard constraint. POA&M items slip due to competing operational priorities, IT resource constraints, or administrative neglect. By the time the deadline approaches, the organization faces a choice between seeking an extension, which requires documented justification and is not guaranteed, or losing Conditional status entirely.
The cost of a new assessment, ranging from $50,000 to more than $100,000 for a C3PAO engagement plus internal labor, is entirely avoidable. The disqualification risk during the gap period is not. Organizations that have gone through this once rarely repeat the mistake.
Incomplete or Inaccurate POA&M Entries
CMMC Level 2 assessment methodology evaluates 110 security requirements across 320 assessment objectives drawn from NIST SP 800-171A Rev. 3. A compliant POA&M must address each deficiency at the assessment objective level, not just at the control level.
This distinction is frequently misunderstood. A contractor may document a deficiency under a NIST control heading without recognizing that the deficiency maps to multiple specific assessment objectives, each of which may require a distinct remediation action. A POA&M entry that addresses the control heading but not the specific objective is incomplete. The associated SPRS score deduction remains in effect until the specific objective is demonstrably closed.
This level of specificity requires that the people maintaining the POA&M understand NIST SP 800-171A assessment methodology, not just the high-level control framework. For small and mid-sized contractors that assigned POA&M ownership to general IT staff or operations personnel without compliance training, this is a gap that surfaces at exactly the wrong moment: formal assessment.
Third-party C3PAO assessors approach POA&M review with a defined methodology. Understanding what they are looking for is the most direct path to avoiding preventable findings.
The organizations that consistently pass CMMC Level 2 assessments without surprises manage their POA&M as a live operational document, not a static compliance artifact. The difference between those two approaches is visible in the first five minutes of an assessor review.
POA&M management is not just a compliance operations issue. It sits at the intersection of SPRS self-attestation requirements and False Claims Act exposure.
Under the CMMC framework, an Affirming Official, typically a senior company executive, certifies that the SPRS assessment accurately reflects the organization's compliance status. A POA&M that misrepresents the status of open items, overstates remediation progress, or attributes closed status to items still deficient is a false attestation. Under 31 U.S.C. § 3729, knowing submission of false or fraudulent claims to the federal government exposes the organization and the certifying official to treble damages and civil penalties.
The Department of Justice Civil Cyber-Fraud Initiative has demonstrated consistent willingness to pursue enforcement actions against contractors who misrepresent cybersecurity compliance. MORSE Corporation paid $4.6 million to resolve false SPRS scoring allegations. Raytheon Technologies paid $8.3 million following whistleblower complaints about cybersecurity misrepresentations. The legal risk is not theoretical.
For the Affirming Official signing the SPRS entry, POA&M accuracy is a personal legal accountability, not a documentation preference.
What is the minimum SPRS score required to maintain Conditional CMMC Level 2 status?
Current DoD guidance indicates that organizations scoring approximately 88 to 109 points may qualify for Conditional status, provided all deficiencies are documented in approved POA&Ms and closed within 180 days of the assessment. Organizations below this threshold are generally not eligible for Conditional status. Final certification requires a score of 110 with all POA&M items closed. Specific threshold application may vary by program, and contracting officers retain discretion on how Conditional status is treated for their requirements.
Can I extend the 180-day POA&M remediation window?
Extensions are not automatically available. DoD guidance does not establish a formal extension process for the 180-day closure deadline, and organizations that miss the deadline risk losing Conditional status. If unforeseen circumstances are delaying remediation, document the situation clearly and consult with a qualified compliance advisor about available options. The safest path is to build sufficient buffer into your remediation planning so that extensions are never needed.
How specific do POA&M entries need to be?
Entries should map to specific NIST SP 800-171A assessment objectives, not just high-level control numbers. Each entry should identify the deficient objective, describe the remediation action required, assign a named owner, establish a target completion date, and indicate current status. Entries that address only the control-level heading without identifying which assessment objectives are unmet will be flagged as incomplete during formal assessment review.
Does a subcontractor need its own POA&M?
Yes. Any subcontractor that processes, stores, or transmits CUI on a contractor-owned information system is independently subject to CMMC Level 2 requirements, including the POA&M obligation for any unmet controls. Prime contractors are responsible for ensuring that CUI-handling subcontractors meet these requirements. A subcontractor that cannot demonstrate a current, accurate POA&M for any open deficiencies creates award eligibility risk for the prime.
A POA&M that nobody is actively managing is not a compliance asset. It is a documented record of unresolved deficiencies that an assessor, a contracting officer, or a DOJ investigator can read. The organizations that treat POA&M discipline as an operational priority, not a compliance formality, are the ones that reach Final status on schedule and hold it. Contact us today to learn more about how Atlantic Digital helps defense contractors build POA&M management systems that satisfy assessor scrutiny, protect SPRS status, and support contract eligibility across the Defense Industrial Base.
