POA&Ms should be treated as a narrow remediation bridge, not a replacement for compliance. Under the Final Rule, contractors must still build an SSP, meet most NIST SP 800-171 controls, and reserve POA&Ms for eligible non-critical gaps. The safest approach is to limit open items, assign clear ownership, and close every approved POA&M within the 180-day window.
Why CMMC POA&Ms are a governance tool, not a compliance shortcut
For defence contractors, a POA&M only makes sense when it documents a limited, approved gap and the work needed to close it. The control objective still has to exist in the environment, because the CMMC model is built around evidence of implemented practice rather than intent alone. That is why teams should treat POA&Ms as a managed exception path, not a way to defer foundational security indefinitely.
That distinction matters because a POA&M can obscure whether a control failure is temporary, bounded, and actively being remediated, or whether it reflects a deeper implementation problem that should stop certification progress. If the gap is broad, repeated, or tied to a core access, configuration, logging, or protection control, it is no longer just a paperwork issue. The risk is that the organisation starts managing attestations instead of security outcomes. In practice, many contractors discover that the problem was not the POA&M itself but the habit of using it to rationalise unfinished control deployment.
When a POA&M is legitimate, it should be specific enough that an assessor can see the exact gap, the owner, the due date, and the evidence that will prove closure. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it reinforces the idea that controls are implemented capabilities, not administrative placeholders.
How a defensible POA&M process works in practice
A sound POA&M process starts with classification. The contractor first determines whether the gap is eligible for a POA&M under the applicable CMMC conditions, then separates that gap from controls that must be fully in place before the environment can be treated as compliant. That distinction is operationally important because not every weakness belongs in a remediation plan. Some gaps are too central to the security boundary, too broad in scope, or too closely tied to trust, access, or protection requirements to be left open.
Once a gap is accepted, the POA&M should be written as a control-specific remediation record. It should name the failed practice, the affected system boundary, the owner responsible for closure, the milestone dates, and the evidence required to demonstrate completion. A useful POA&M is not a narrative about why work is hard. It is a tracked commitment to a verifiable outcome. That is also where many teams go wrong: they track the document, but not the control state.
- Limit the number of open items so the plan remains reviewable and genuinely actionable.
- Use the POA&M to show remediation progress, not to justify indefinite operation with a known gap.
- Keep the SSP and the POA&M consistent so the stated control boundary matches the actual environment.
- Close out the item with evidence, not just a status update or managerial assertion.
The practical test is whether the POA&M is reducing exposure while the work is underway. If it is merely extending the life of a missing safeguard, then the organisation has shifted from remediation to substitution. ISO/IEC 27002:2022 Information Security Controls is a useful parallel reference for treating controls as operational capabilities rather than documentation artefacts. This guidance breaks down when the open item is so central that business pressure starts overriding the technical reality of whether the control is actually present.
Where POA&Ms become dangerous, and how to keep them narrow
Tighter use of POA&Ms often increases short-term administrative friction, because teams must justify each exception and prove that the gap is genuinely bounded. That trade-off is worthwhile when the alternative is letting a remediation list become a standing substitute for control implementation.
The main edge case is the recurring or systemic gap. If the same weakness keeps reappearing across projects, sites, or systems, the problem is usually not a single missed task but a weak implementation model, poor ownership, or under-resourced control deployment. In that situation, the issue should be treated as a programme-level failure rather than a routine POA&M item. Another edge case is scope creep. A narrow approved gap can expand quietly when related dependencies are added, inherited, or reconfigured, which is why the boundary must be rechecked whenever the environment changes.
There is also a governance trade-off in relying on POA&Ms during assessment preparation. A contractor can appear organised while still carrying too many unresolved gaps, especially if the tracking process is not tied to real technical verification. The safest posture is to keep the open list short, tie each item to a clear closure path, and review whether the remaining gap is still eligible each time the plan is updated. If eligibility is doubtful, the right answer is not to stretch the POA&M. It is to fix the control or pause the claim of readiness.
In practice, the most common failure is not malicious abuse but quiet normalisation: teams get used to open items and stop treating them as exceptions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC — Supply Chain Risk Management | POA&Ms affect governance of remediation and supplier assurance. |
| Recommendation — Use governance controls to ensure POA&Ms do not replace implemented security outcomes. | ||
| CIS Controls v8 | CIS 17 — Incident Response Management | POA&M overuse can hide unresolved control weakness and prolong exposure. |
| Recommendation — Track and close remediation items with clear ownership and evidence of completion. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Contractor compliance depends on trustworthy control evidence and verified implementation state. |
| Recommendation — Verify the asserted state of controls before accepting compliance claims. | ||
| NIST AI RMF | GOVERN — AI risk governance | Governance discipline is needed when exception processes could outlive their purpose. |
| Recommendation — Define exception governance so temporary remediation paths cannot become permanent substitutes. | ||
Practitioner Guidance
What to prioritise: Focus first on whether each open item is truly eligible for a POA&M under the contract’s CMMC scope. If the gap affects a core safeguard, the right decision is usually remediation acceleration, not exception management.
What to verify: Verify that every approved item has a specific owner, an evidence-based closure target, and a date that fits the allowed remediation window. The plan should prove progress toward control operation, not merely document intent.
Common mistake: Treating the POA&M as a standing buffer for slow implementation is the fastest way to dilute compliance. Once the organisation starts relying on open items as normal operating state, the control programme has already weakened.
Practitioner takeaway: A POA&M is defensible only when it preserves the difference between a temporary exception and an unimplemented control; if that line blurs, the contractor is managing paperwork instead of security.
Related resources from NHI Mgmt Group
- How should security teams use compliance benchmarks without confusing them with real control maturity?
- How should security teams use AI in fraud and identity defence without losing control?
- How should security teams use trust signals without turning them into proof?
- How should security teams use AI without turning it into a control dependency?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org