CMMC | | 23 min read
CMMC POA&M Rules: What Can Wait and What Cannot
Key Takeaways
The operator view
Eligibility is item specific
A score of 88 opens the test. It does not make every unmet requirement eligible.
Provider work scores 93
External dependencies leave less recovery time inside a fixed 180 day closeout window.
Prove closure before finalization
Test the fix, evidence, scope, and operator explanation before the official closeout.
A CMMC POA&M is not permission to finish security later. It is a narrow conditional lane with a fixed exit.
The common mistake is to look at the score, see 88, and assume the remaining gaps can wait. That is only the first gate. Current Level 2 rules test the score, the point value of each unmet requirement, six named exclusions, the assessment path, and the 180 day closeout deadline. Level 1 does not permit a plan of action and milestones at all.
Use this guide with the CMMC Resource Hub, the CMMC Level 2 control and evidence guide, and the SPRS score guide. The score explains where you stand. This article explains which gaps can enter a conditional status and how to close them without losing the window.
Test the POA&M before you plan around it.
GS Consulting helps defense contractors verify item eligibility, sequence closure work, rehearse evidence, and protect the finalization window.
Request a CMMC Closeout ReviewThe CMMC POA&M Rule Boundary
There are two different records that teams sometimes call a POA&M. An organization can keep an operating plan of action for internal remediation. The CMMC program also defines which assessment findings may support a conditional status. An internal plan can contain any risk the organization needs to manage. That does not mean the CMMC program will accept every item for conditional status.
For current Level 2 rules, conditional status starts with a score of at least 88 out of 110. The contractor must record the allowed unmet requirements, complete the applicable affirmation, close every accepted item within 180 days, and complete the required closeout. Final status comes only after all accepted items are met.
The codified Level 2 rule in 32 CFR 170.21 controls the eligibility mechanics. The DFARS 252.204-7021 clause connects status and closeout to covered contract performance when the clause and required level apply.
Run the Eligibility Test in the Right Order
Do not start with a remediation calendar. Start with a rule decision for every unmet requirement.
- Confirm the required CMMC level and assessment path. Read the solicitation, award, flowdowns, and current program notice. Do not infer the requirement from the type of contractor.
- Confirm the scored assessment result. Level 2 conditional status requires at least 88 points under the current rule.
- Test each unmet requirement. Check its point value, named exclusion status, and any stated exception.
- Confirm the closeout route. A self assessment and a certification assessment do not use the same finalization party.
- Confirm that 180 days is operationally credible. Eligibility does not prove that a provider, hardware, architecture, or evidence problem can be closed in time.
The matrix is a GS Consulting reading aid based on the current rule and official program material. It is not a legal or assessment determination. Verify the current codified text, contract language, assessment record, and official instructions for the specific organization.
What Cannot Wait
Level 1 gaps cannot enter a CMMC POA&M. At Level 2, a score below 88 cannot support conditional status. A score at or above 88 still does not rescue an ineligible item.
The current rule bars the following six Level 2 requirements from a plan of action and milestones:
- AC.L2-3.1.20. Verify and control or limit connections to and use of external systems.
- AC.L2-3.1.22. Control CUI posted or processed on publicly accessible systems.
- CA.L2-3.12.4. Develop, document, and periodically update system security plans.
- PE.L2-3.10.3. Escort visitors and monitor visitor activity.
- PE.L2-3.10.4. Maintain audit logs of physical access.
- PE.L2-3.10.5. Control and manage physical access devices.
Requirements worth more than one point are also generally barred. The stated exception is SC.L2-3.13.11 when encryption is used but is not FIPS validated. That exception is not a general waiver for weak cryptography. It is a specific rule condition that still sits inside the score floor, assessment, and closure requirements.
A missing system security plan is especially consequential. It is both a named exclusion and a basic condition for completing the assessment. If the system description, boundary, environment, implementation, and connections are not documented, the team does not merely have a writing task. It has an unresolved control picture.
What May Wait
An unmet one point Level 2 requirement may be eligible when the organization remains at or above 88, the requirement is not one of the named exclusions, and every other current program condition is met. The FIPS validation condition noted above is the narrow exception to the general point value limit.
“May wait” does not mean “start later.” It means the program can recognize a conditional status while the contractor executes a bounded closure plan. The safest candidates have a known technical fix, a named owner, available evidence, limited external dependency, and enough calendar margin for retest.
Reject a proposed deferral when any of these facts are missing:
- The exact unmet assessment objective and requirement are not recorded.
- The team has not reconciled the score after every finding.
- The fix depends on a provider, purchase, boundary change, or migration with no committed date.
- The proposed evidence cannot show the requirement operating across the assessed scope.
- The internal review and official closeout cannot fit before day 180 with recovery time.
GS CMMC Closure Pressure Index
GS Consulting built a derived planning model for eight common closeout workstreams. It is applied only after the rule eligibility test. The index combines schedule dependency, implementation dependency, evidence burden, external dependency, and validation burden. Each factor uses a documented 1 to 5 analyst rating. Weighted results run from 0 to 100.
FIPS validation correction scores 100 in the model. A cross boundary architecture change scores 97. Provider dependent control work scores 93, and hardware replacement scores 90. Identity policy and deployment scores 77. A contained configuration change scores 37.
The result is not a claim that a high score makes an item ineligible. Eligibility comes from the rule. The index measures closure pressure after eligibility. A technically allowed gap can still be a bad operational bet when procurement, provider action, architecture, testing, and assessor scheduling leave no recovery time.
A sensitivity test shifted ten percentage points toward evidence and external dependencies. The rank order remained stable and no score moved materially. That limited test supports the planning observation, but it does not make the ratings universal. Replace them with local lead times, vendor commitments, change windows, test capacity, and evidence maturity.
The index is a GS Consulting derived planning tool based on cited public sources and documented assumptions. It is not an official CMMC score, legal opinion, assessment result, or prediction of closeout acceptance.
Operate the 180 Day Closeout as a Program
Day 180 is an expiration point, not the day to finish the technical change. Build the schedule backward from official closeout. Reserve time for evidence collection, internal testing, correction, the finalization event, and the accountable affirmation.
Use three dates for every item: the implementation date, the evidence ready date, and the internal acceptance date. A change can be installed while its operating proof remains weak. Separating the dates makes that gap visible.
The current DoD FAQ states that closeout evaluates the requirements recorded as not met, not a fresh full assessment. It also states that one closeout finalization is allowed. That makes an internal dry run essential. The team should reproduce the expected examine, interview, and test evidence before it schedules the official event.
Track the critical path weekly. Escalate missed provider dates, failed tests, scope changes, and evidence gaps immediately. A green milestone should mean the requirement is implemented and independently reviewable, not that a ticket is almost complete.
Build the Closeout Evidence Packet With the Fix
For every item, keep the requirement, point value, finding, owner, due date, implementation record, evidence crosswalk, test result, reviewer decision, and closeout outcome. Link each artifact to the exact assessment objective it supports.
Do not rely on one screenshot. Show the configuration, the covered assets or users, the operating record, the exception path, and the review. If the fix changes the system boundary or a provider responsibility, update the system security plan, diagram, inventory, and responsibility matrix before closeout.
Protect the packet. Findings and implementation proof can expose security weaknesses, architecture, accounts, and provider details. Apply access limits, integrity controls, version history, retention, and secure transfer.
Six CMMC POA&M Failures That Repeat
The first failure is a score only decision. The second is waiting to start work that depends on procurement or another company. The third is installing a fix without building evidence. The fourth is allowing the boundary to change while the closeout record stays frozen. The fifth is sending untested proof into the one closeout finalization. The sixth is forgetting that status and affirmation records remain part of the operating duty.
One owner should control the master item register. Technical owners can run the changes, and evidence owners can prepare records, but the master register must reconcile score, eligibility, scope, schedule, proof, review, finalization, and affirmation.
Current CMMC Timing in July 2026
The Department of Defense CMMC program page states that Phase II was suspended on July 13, 2026 while Phase I self assessments remain. That timing matters, but it does not erase current contract duties or make a contractor assessment ready.
Read each solicitation and award. Confirm current DFARS clauses, the requested status, the assessment level, flowdowns, SPRS duties, and NIST SP 800-171 obligations. A program pause can change when a certification status appears in a contract. It does not change the work needed to protect CUI or prove an existing representation.
The operating standard is decisive: no gap enters the CMMC closeout plan until the rule permits it, an owner can finish it, and the evidence can survive review before day 180.
Research Sources and Caveats
- 32 CFR 170.21: CMMC Level 2 rules
- Federal Register: CMMC Program final rule
- Department of Defense: current CMMC program page
- Department of Defense: CMMC frequently asked questions
- DFARS 252.204-7021
- Department of Defense: CMMC Assessment Guide Level 2
- NIST SP 800-171A
The research package separates public observations from GS analyst ratings and includes formulas, sensitivity results, source limitations, figure data, and editable graphics. The model is a planning aid. It does not replace the current rule, contract, assessor instructions, or professional advice.
Frequently Asked Questions About CMMC POA&M Rules
What is a CMMC POA&M?
A CMMC plan of action and milestones records certain unmet Level 2 requirements that the program allows a contractor to close after receiving conditional status. It is not available at Level 1, and it does not make every Level 2 gap deferrable.
What score is required for a CMMC Level 2 POA&M?
The current Level 2 rule requires at least 80 percent of the 110 available points, which means a minimum score of 88. The score floor is only the first test. Each unmet requirement must also pass the item eligibility rules.
How long does a contractor have to close a CMMC POA&M?
A conditional Level 2 status lasts no more than 180 days. The contractor must close every accepted item and complete the applicable closeout process within that period or the conditional status expires.
Can a three point or five point CMMC requirement go on a POA&M?
Generally no under the current Level 2 rule. The rule provides a narrow exception for SC.L2-3.13.11 when encryption is used but is not FIPS validated. Contractors should verify the current codified rule and their assessment facts before relying on that exception.
Does the July 2026 Phase II suspension remove CMMC duties?
No. The Department of Defense states that Phase II was suspended on July 13, 2026 while Phase I self assessments remain. Existing contract clauses, NIST SP 800-171 duties, SPRS representations, and current solicitation terms still require separate review.