sha3:7c8eb1be7fa18bea9d8440c3b6b25d41e98e16b5c4d64e80a0b7c8d5f9f72f08Intact158585c85b2aca1fe659d5d655b8067d5bb9738cb0a732ef567a5ec79d59b52eprev:95acd212024cRegisterGlossary
What is POA&M?
A POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates.
bbf188a56e8126127f2bf7917bd4d6d3c1e414f33bfd852f0aca5d2ffdcac617prev:158585c85b2aPOA&M stands for Plan of Action and Milestones.
A Plan of Action and Milestones (POA&M) lists known control gaps and the plan to close them. Under CMMC, a limited set of non-critical controls may be POA&M'd to achieve conditional certification.
Conditional Level 2 status requires closing the POA&M items within 180 days, verified by a follow-on assessment. Critical controls generally cannot be POA&M'd.
Between 15% and 30% of first-attempt assessments end with open POA&M items — one reason a readiness review before the formal assessment materially lowers risk.
7c8eb1be7fa18bea9d8440c3b6b25d41e98e16b5c4d64e80a0b7c8d5f9f72f08prev:bbf188a56e81Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended
- Unchanged since sealing