Updated September 30, 2026
Under CMMC Level 2, you can leave a gap open only if it's worth 1 point, it isn't one of six named exceptions, and your score is still 88 or higher. You then have 180 days to close every item, and if you don't, your status expires.
A POA&M, short for plan of action and milestones, is the list of security gaps you haven't fixed yet, with a date and an owner for each. CMMC, the Defense Department's cybersecurity program for its suppliers, lets you be awarded a contract with a few gaps still on that list. The rule that decides which gaps is 32 CFR 170.21, and it's shorter and stricter than most people assume. A lot of companies keep a POA&M with forty items on it and believe they're covered. Under CMMC, most of those forty items don't belong there, and having them on a list earns nothing.
How many requirements can go on a POA&M?
Forty-seven, out of 110. Here's where that number comes from.
Level 2 is scored against the 110 requirements in NIST SP 800-171, the federal standard for protecting controlled unclassified information (CUI: the drawings, specs and technical data the government marks as sensitive). You start at 110 and lose 1, 3 or 5 points for each requirement you haven't met (32 CFR 170.24). The rule lists 42 requirements worth 5 points and 14 worth 3. Two more, multi-factor login (3.5.3) and encryption (3.13.11), cost 3 or 5 depending on how far along you are. Everything else, 52 requirements, is worth 1.
The POA&M rule then says no item on the plan can be worth more than 1 point. There's one exception: if you encrypt CUI but the encryption isn't FIPS-validated, meaning it hasn't passed the government's cryptography testing program, 3.13.11 costs 3 points and can still go on the plan.
Then it removes six requirements by name, whatever their point value:
- 3.1.20, controlling connections to outside systems, like personal devices or a partner's network
- 3.1.22, controlling what gets posted on public systems such as your website
- 3.10.3, escorting and watching visitors
- 3.10.4, keeping logs of who physically entered
- 3.10.5, managing keys, badges and door codes
- 3.12.4, the system security plan (SSP), the document describing your environment and how each requirement is met
Take those six out of the 52 one-pointers and you have 46. Add encryption-without-FIPS and you have 47. Anything else that's open, you have to fix before you can claim any status at all.
Why the 88 rule bites sooner than you'd think
The first condition in 170.21 is that your score divided by 110 must be at least 0.8. That's 88 points. Combine that with the 1-point rule and the math gets tight fast: you can carry at most 22 points of gaps. That's 22 one-point items, or non-FIPS encryption plus 19 one-pointers. Nothing more.
Two shops show how this plays out.
The first scored 90. Its gaps: 15 one-point items, plus 3.3.1, audit logging, worth 5 because nobody ever turned on logging on the file server. Comfortably above 88. But audit logging can't go on the POA&M, so this shop has no CMMC status at all until logging runs. SPRS, the DoD website where you post your score, enforces exactly this: if a requirement can't be on a POA&M, "the Status Type will be No CMMC Status regardless of score" (SPRS CMMC quick entry guide).
The second scored 89. All 21 of its gaps are 1-point items, like screen lock after inactivity (3.1.10), limits on failed logins (3.1.8) and the login security notice (3.1.9), and none of them is on the excluded list. It qualifies for Conditional status. The lower score gets the contract.
If your gaps are mostly 1-point items but there are 30 of them, you're at 80, and you're out too. Close eight and you're back to 88.
What the plan doesn't do
It doesn't earn points. The scoring rule says a POA&M "is not a substitute for a completed requirement," and a requirement not implemented is NOT MET "whether described in a POA&M or not" (170.24(c)(2)(i)(6)). Your score counts what's done. The POA&M only decides whether the gaps you have are the kind the government will tolerate for 180 days.
That's also why you can't put a 3-point requirement on the plan and call it Conditional. One requirement deserves a closer look here. Requirement 3.12.2 says you must "develop and implement plans of action" for deficiencies (NIST SP 800-171 Rev. 2). It's worth 3 points. So if you have no working plan-of-action process, you can't list "build a plan-of-action process" on your plan of action. That one has to exist before you claim anything.
A POA&M is not your to-do list
The rule draws a line between two documents that most companies keep in the same spreadsheet.
The POA&M belongs to an assessment. It lists the requirements you scored NOT MET, and every item on it must close within 180 days.
The operational plan of action is the ongoing list required by 3.12.2. The CMMC rule defines it as the record of "temporary vulnerabilities and temporary deficiencies," such as a patch that's needed, and says it "does not identify a timeline for remediation and is not the same as a POA&M" (32 CFR 170.4).
The difference matters at scoring time. A temporary deficiency that shows up after a control was working, and that's tracked on the operational plan with reviews and progress, is scored MET (170.24(b)(1)(ii)). Say a laptop's encryption module falls out of FIPS validation after an update. That's a temporary deficiency, and the rule uses almost exactly that example. A control you never finished rolling out is not a temporary deficiency. It's a gap, and it's NOT MET.
The same rule covers things you'll never fix. An "enduring exception" is a system where full compliance isn't feasible, like test equipment or a CNC controller that runs an old operating system. Describe it in the SSP along with its mitigations and it's assessed as MET. It doesn't go on the POA&M at all.
So before you write a single POA&M item, sort your open list three ways: temporary deficiencies go on the operational plan, enduring exceptions go in the SSP, and only the true gaps that pass the eligibility test go on the POA&M.
The 180 days
The clock starts on your CMMC Status Date, the date your Conditional result is entered in SPRS. Within 180 days you must fix every POA&M item, run a closeout self-assessment of just those items "in the same manner as the initial self-assessment," and post the result in SPRS (32 CFR 170.16). Your Affirming Official, the senior person who signs for the company, then affirms again in SPRS (32 CFR 170.22).
Two details catch people. First, the Status Date doesn't reset when you go from Conditional to Final. The rule says "A new date is not set for a Final that follows a Conditional" (170.4). Your three-year clock until the next full self-assessment started on day one of the 180. Second, the closeout checks only the POA&M items. The other 100 or so requirements aren't re-checked then, but the affirmation you sign says you've implemented and "will maintain" all of them.
If you were certified by a C3PAO, an accredited third-party assessment firm, the closeout has to be done by a C3PAO too. During the current pause, new contracts only ask for self-assessments, so most small shops are on the self path. What the pause changed →
What happens if you miss the 180 days?
Your Conditional status expires. SPRS's own guide says a Conditional Level 2 self-assessment "is valid for 180 days." There is no extension in the rule.
Section 170.16 spells out the rest. If the status expires during a contract, "standard contractual remedies will apply," and you're "ineligible for additional awards" that require Level 2 (Self) or higher for that system until you achieve a new status. In practice that means a new self-assessment, not a late closeout. The contract clause says the same thing from the other side: a contractor with Conditional status shall "successfully close out a valid plan of action and milestones" to reach Final (DFARS 252.204-7021(d)(5)).
"Standard contractual remedies" is deliberately open. It covers what a contracting officer can already do with a contractor who isn't meeting a contract term. You don't want to learn the specifics in your own case.
There's also a quieter risk. The government can send DCMA's assessors (DIBCAC) to check any time, and their results "take precedence over any pre-existing CMMC Status" (170.16). An expired plan with half the items still open is the worst thing they could find.
Plan the 180 days backward
Leave the last 30 days for the closeout self-assessment and the SPRS entry. Leave the 30 before that for the fixes to run, because a control turned on the day before has no history to show. That gives you about 120 days to do the work. If an item can't realistically be closed in 120 days, it shouldn't be on the plan. Fix it first and claim status later.
Write each item so a stranger could check it. "Configure session lock" is a task. "All 14 workstations in scope lock after 15 minutes idle, enforced by Intune policy, verified by export" is something you can close and prove. What evidence counts → · Conditional vs. Final status →
Common questions
Can a 3-point item ever go on the POA&M? Only one: 3.13.11, when you encrypt CUI but the encryption isn't FIPS-validated. Partial multi-factor login (3.5.3 at 3 points) can't.
Can I use a POA&M at Level 1? No. The rule says a POA&M "is not permitted at any time for Level 1 self-assessments."
Can I extend the 180 days? The rule has no extension. Changing a date in your own spreadsheet doesn't change the one in SPRS.
Does closing the POA&M restart my three years? No. Final keeps the Conditional Status Date.
What if I find a new gap after I'm Final? If it's a temporary deficiency in a control that was working, track it on your operational plan of action. If the control never really worked, your affirmation is wrong, and that's a different conversation.
