CMMC POA&M eligibility checker
Mark the NIST 800-171 requirements you have open. This works out which of them a CMMC Level 2 POA&M can actually carry under 32 CFR 170.21, which have to be closed before an assessor arrives, and whether you clear the score floor to use a POA&M at all.
Runs entirely in your browser. Nothing is uploaded, stored, or emailed - no account, no gate.
What 32 CFR 170.21 actually says
A POA&M reads, to most program managers filling one out for the first time, like a second chance: list what is not done, promise a date, and the assessment proceeds as though the gap were closed. It is not a second chance. It is a narrow exception to the requirement that every control be implemented before certification, and it is bounded four ways at once - a score floor, a point ceiling, a list of named exclusions, and a single deadline.
The point ceiling is the rule programs misread most. It does not bar a handful of famous controls; it bars every 3-point and 5-point requirement in the set. The regulation makes one exception, and it runs opposite to what most programs assume: 3.13.11 may be carried when encryption is employed but is not FIPS-validated. Encryption missing outright is worth 5 points and gets no such allowance. Meanwhile multifactor authentication sits at the same 3 points in its partial state and is not excepted.
The score floor catches the rest. Conditional CMMC Status requires at least 88 of 110, so a program can have nothing open but eligible 1-point requirements and still be barred from using a POA&M because the total falls short. And the clock is singular: 180 days from the Conditional CMMC Status Date, confirmed by a closeout assessment, regardless of how a program prioritises the work internally.
None of this makes the document useless. An eligible gap with a named owner and a defensible date is a legitimate answer to a real deficiency, and it buys time a program would not otherwise have. What it cannot do is make an assessment easier than the underlying requirements are - which is why sorting your gaps before the plan is written beats discovering the sort after it is rejected.
Frequently asked questions
What is a POA&M?
A Plan of Action and Milestones is the document that records security requirements an organization has not yet implemented, with the action, owner, and date for each. In CMMC it is not a general-purpose tracker: it is a narrow, rule-bound exception under 32 CFR 170.21 that allows Conditional CMMC Status while a small set of eligible gaps remain open. A requirement on a POA&M is NOT MET until a closeout assessment says otherwise.
What can go on a CMMC Level 2 POA&M?
Only requirements worth 1 point in the DoD Assessment Methodology, minus six that are named as excluded regardless of weight: 3.1.20 (connections to external systems), 3.1.22 (CUI on publicly accessible systems), 3.10.3 (escort visitors), 3.10.4 (physical access logs), 3.10.5 (manage physical access devices), and 3.12.4 (the system security plan). The regulation makes exactly one exception above the 1-point ceiling: 3.13.11 may be carried when encryption is employed but is not FIPS-validated.
What SPRS score do I need before a POA&M is allowed?
At least 88 of 110 - eighty percent of the requirements. Below that, no POA&M is permitted at all, no matter how eligible the individual gaps look. This is the rule programs are most often surprised by: you can have nothing but 1-point gaps open and still be barred, because it is the total that governs.
How long do I have to close a CMMC POA&M?
One 180-day window, running from the Conditional CMMC Status Date and confirmed by a POA&M closeout assessment. It is not a tiered 90-day and 180-day split by internal priority, and it does not start when the plan is filed. Miss the window and Conditional status for that information system expires.
Can multifactor authentication (3.5.3) go on a POA&M?
No. 3.5.3 is worth 5 points when unimplemented and 3 points in its partial state, and both exceed the 1-point ceiling. This catches people because 3.13.11 sits at the same 3 points in its partial state and IS eligible - that exception is written for FIPS validation specifically and does not extend to MFA.
Does a POA&M restore SPRS points?
No. The deduction applies until the requirement is actually implemented. A contracting officer reading your SPRS score sees the same number whether or not a remediation plan exists behind it, which is why a POA&M buys schedule rather than score.
Are POA&Ms allowed at CMMC Level 1?
No. Level 1 requires all 17 practices to be met at self-assessment; there is no conditional status and no POA&M mechanism. The POA&M rules in 170.21 apply to Level 2 and Level 3.
Is a CMMC POA&M the same as an RMF or Army POA&M?
They share a name and a shape but not a rulebook. A POA&M under the Risk Management Framework supports an authorizing official granting an ATO, and the constraints on what may remain open are set by that AO and the system risk posture. A CMMC POA&M is bounded by 32 CFR 170.21 - fixed point ceiling, named exclusions, a score floor, and a fixed 180-day window. If you run both programs, keep the artifacts separate and do not assume RMF latitude carries over.
The long-form argument behind this page, with the regulation walked line by line, is in MacZine: What you can put on a POA&M, and what you cannot.
Not sure what your score is yet? The free CMMC readiness check estimates it in five minutes, and the CMMC MCP server gives an AI assistant the full control catalog and exact SPRS weights.
MacTech Solutions is an SDVOSB that builds CUI enclaves and takes defense contractors from first SSP to C3PAO-ready. See the CMMC Level 2 programme or start a verified readiness scan.