Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do teams get wrong about CMMC POA&M…
Cyber Security

What do teams get wrong about CMMC POA&M eligibility?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Cyber Security

A common mistake is assuming any unresolved control can sit in a POA&M. Under the Final Rule, POA&Ms are restricted to certain Level 2 and Level 3 requirements, excluded from Level 1, and barred for several named CUI-related 1-point controls. Teams also underestimate the need to prove eligibility through an SPRS score and documented assessment posture.

Why CMMC POA&M eligibility gets misread

POA&M eligibility is easy to misread because teams often collapse three separate questions into one: whether a control is weak, whether it is allowed to be deferred, and whether the organisation can evidence that status during assessment. cmmc does not treat all gaps equally, so a generic remediation backlog is not the same thing as a permitted POA&M item. That distinction matters because eligibility affects certification planning, assessment readiness, and whether a gap can be accepted at all.

For practitioners, the main failure is assuming remediation latitude exists wherever a finding exists. In reality, the rule set is narrower, and the burden is on the organisation to show that the requirement is both eligible and properly recorded. The underlying control baseline also matters, which is why the control structure itself is part of the eligibility conversation rather than just the security background. Teams that need to cross-check the control context can use the NIST SP 800-53 Rev 5 Security and Privacy Controls as a reference point for how control families and requirements are defined. In practice, many teams discover the difference only after an assessor asks them to justify why a finding was placed on a POA&M rather than corrected or re-scoped.

How the eligibility decision actually works

Teams usually get this wrong by treating POA&M use as a generic exception process. It is not. Eligibility is determined by the CMMC rule itself, the relevant assessment level, and the specific requirement category. If a requirement is not in scope for POA&M treatment, writing it into a remediation tracker does not make it acceptable. The question is not whether the team intends to fix the issue later; the question is whether the framework permits deferred remediation for that exact item.

That means the practitioner workflow has to start with classification, not with scheduling. First identify the control requirement and the assessment level. Then confirm whether the requirement is one of the items that can be deferred, and whether it is barred by the rule because it is a named high-priority CUI-related control or a Level 1 item. Only after that should the team decide whether the item belongs in a POA&M, must be remediated before certification, or requires a different governance decision.

  • Check the assessment level before deciding on remediation path.
  • Verify that the requirement is explicitly eligible, not merely unresolved.
  • Confirm that the evidence set supports the stated posture, including the assessment result and score.
  • Keep the POA&M limited to items that can survive assessor review, not just internal planning.

SPRS posture matters here because it is part of how the organisation demonstrates its assessment standing and not just an administrative field. A weak submission usually reflects a deeper process problem: the team is using the POA&M as a substitute for control ownership, or assuming eligibility can be inferred from urgency. It cannot. The control gap must be both documentable and permitted, and that is where many otherwise capable programmes stumble. Where teams have multiple findings across the same requirement set, the governing issue is often whether they can separate eligible deferred work from ineligible noncompliance cleanly enough to avoid contaminating the whole assessment package.

Where teams overgeneralise the rule

Tighter remediation rules often improve assessment integrity, but they also increase administrative friction, so teams have to balance speed of closure against the risk of using the wrong exception path. The most common overgeneralisation is to assume that any control weakness with an action plan is POA&M-eligible. That is especially risky when the finding sits in a named category that the rule explicitly excludes, because the existence of a remediation owner does not change eligibility.

A second edge case is conflating “assessment deficiency” with “permitted POA&M item.” Those are not synonymous. Guidance can vary in how organisations operationalise the scoring and documentation workflow, but there is no serious consensus that undocumented flexibility is acceptable. If the assessment posture is not clean, the issue is usually not the POA&M entry itself but the organisation’s inability to prove why the item was allowed there in the first place.

Another common mistake is to treat POA&M eligibility as a post-assessment convenience. That approach breaks down when a team is preparing for audit, because eligibility has to be defensible at the time the artefact is reviewed, not reconstructed later from project notes. The rule is narrow by design, and the narrower the allowance, the more important it is to distinguish an eligible deferred item from a control gap that must be fixed before certification.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-03 — Risk Management StrategyPOA&M eligibility is a governance and risk-acceptance decision.
PR.IP-12 — Identity Management, Authentication, and Access ControlPOA&M misuse often reflects weak control ownership and exception handling.
Recommendation — Use GV.RM-03 to define when deferred remediation is acceptable and when it is not. Use PR.IP-12 to ensure access-control gaps are handled through approved governance paths.
CIS Controls v86.1 — Establish and Maintain an Accurate Asset InventoryEligibility depends on knowing which requirements and findings are actually in scope.
Recommendation — Use 6.1 to keep assessment scope and remediation ownership accurately tracked.
NIST SP 800-631.1.2 — Identity Assurance Level SelectionAssessment posture and evidence discipline depend on defined assurance expectations.
Recommendation — Use 1.1.2 to anchor evidence and assurance decisions to a defined posture.

Practitioner Guidance

What to prioritise: Build the eligibility decision before the remediation tracker. The first question should be whether the finding is allowed on a POA&M at all, not how fast it can be closed.

What to verify: Confirm three things for every candidate item: the control’s assessment level, whether the rule permits deferral, and whether the assessment evidence supports the claimed posture. If any one of those is unclear, treat the item as not yet eligible.

Common mistake: Do not let internal project urgency drive POA&M classification. A work item with an owner and due date can still be ineligible, and that mismatch is what assessors notice first.

Practitioner takeaway: POA&M eligibility is a governance decision anchored in the rule set, not a convenience label for unresolved controls, so teams should prove allowance before they plan remediation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org