Skip to content
    August 16, 2026| Top Floor Team| 9 min read

    CMMC POA&M Rules: What You Can Defer, and for How Long

    32 CFR 170.21 allows a Conditional CMMC Status with open plan of action and milestones (POA&M) items only when the assessment score divided by the total number of Level 2 security requirements is at least 0.8, which is 88 of 110. Within that, only 1-point requirements may be deferred, with two carve-outs that run in opposite directions: six named requirements can never be on a POA&M whatever their point value, and one 3-point requirement, SC.L2-3.13.11 CUI encryption, may be deferred in the single case where encryption is employed but is not FIPS-validated. Closure must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. At Level 1, a POA&M is not permitted at any time.

    The practical translation is the opposite of how the 80 percent figure usually gets quoted. It does not mean you can walk into an assessment 20 percent undone. It means you can walk in essentially done, with a short list of low-weight items and a hard clock.

    Key takeaways

    • Conditional CMMC Status with open POA&M items requires a score of at least 0.8 of the total, which is 88 of 110, and every remaining gap has to be a deferrable one.
    • Only 1-point requirements may be deferred, plus one 3-point exception: SC.L2-3.13.11, and only where encryption is employed but is not FIPS-validated. That defers the validation status, not the encryption.
    • Six requirements can never be deferred whatever their weight, and none of them is expensive: external connections, control of publicly posted information, the system security plan, escorting visitors, physical access logs, and managing physical access devices.
    • The 180-day clock covers the closeout assessment, not just your remediation, and it starts at the Conditional CMMC Status Date. Book the closeout the day the status is issued.
    • At Level 1 a POA&M is not permitted at any time. All 15 requirements have to be met, so the outcome is binary.

    The eligibility test, and why 80 percent is misleading

    The threshold is arithmetic on the score: at least 0.8 of the total. With 110 Level 2 requirements, that is 88 points.

    Because the scoring method subtracts 5, 3, or 1 per unmet requirement, missing 22 points is not the same as missing 22 requirements. Four or five 5-point misses will put you under the line on their own. And since the 5-point items are ineligible for a POA&M anyway, an organization sitting at exactly 88 because of high-weight gaps does not qualify for conditional status at all: the gaps that dragged it there are the gaps that cannot be deferred.

    So the eligibility test and the deferral test have to be read together. You need the score, and you need every remaining gap to be a deferrable one.

    What may be deferred

    Requirements weighted at 1 point, other than the six exclusions below. In practice these tend to be documentation, review-cadence, and process requirements rather than technical controls.

    Plus exactly one 3-point item, and only in one condition. SC.L2-3.13.11, which requires FIPS-validated cryptography to protect CUI, may go on a POA&M where encryption is employed but is not FIPS-validated. Note the shape of that exception, because it is easy to over-read: it is not permission to defer encryption. It is permission to defer the *validation* status of encryption you already have running. An organization with no encryption of CUI has a 5-point-consequence problem, not a POA&M item.

    What may never be deferred

    Six Level 2 requirements are excluded from a POA&M regardless of their point value:

    • AC.L2-3.1.20, external connections
    • AC.L2-3.1.22, control of publicly posted information
    • CA.L2-3.12.4, the system security plan
    • PE.L2-3.10.3, escorting visitors
    • PE.L2-3.10.4, physical access logs
    • PE.L2-3.10.5, managing physical access devices

    Look at that list and the design intent is clear. Three of the six are physical-security practices that require a procedure and a logbook rather than a purchase. Two concern what leaves your network and what you publish. And CA.L2-3.12.4 is the System Security Plan, without which an assessment cannot meaningfully happen at all, since the plan is what the assessor assesses against.

    The unifying feature is that none of them are expensive. The regulation is not deferring the hard items and holding the line on the easy ones by accident; it is saying that if you have not done the cheap procedural work, you are not ready for a conditional status.

    The 180-day clock, and what happens when it runs out

    Closure of every POA&M item has to be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. Two things follow.

    The clock starts at the status date, not when you get around to it, and it covers the closeout assessment rather than just your remediation. So the working timeline is: remediate, produce evidence, schedule an assessor, and have the closeout assessment completed, all inside 180 days. If the remediation itself takes 150 days, the schedule has already failed.

    And a conditional status is conditional. It is not a certification with an asterisk that quietly matures. Treat it as a bridge with an expiry, and plan the closeout on the day you receive the conditional status rather than in month five.

    Level 1 has no POA&M at all

    32 CFR 170.21 states that a POA&M is not permitted at any time for Level 1 self-assessments. All 15 FAR 52.204-21 requirements have to be met.

    This surprises people who assume the lower level must be the more forgiving one. It is more forgiving in volume, at 15 requirements instead of 110, and less forgiving in structure, because there is no partial path. If you are a Level 1 organization, your assessment outcome is binary.

    What a POA&M item actually has to contain

    A plan of action is a document an assessor reads, not a spreadsheet of intentions. Each item should carry six things.

    The requirement, by its identifier rather than by a paraphrase. The assessment objectives not met, because NIST SP 800-171A breaks each requirement into objectives and a requirement is rarely wholly absent. The remediation, described specifically enough that someone other than the author could execute it. An owner who is a person rather than a department. A completion date that sits inside the window with room for evidence collection and the closeout assessment. And the evidence that will demonstrate closure, decided in advance rather than assembled afterwards.

    That last item is the one that separates a plan that closes from a plan that slips. Deciding at the outset that closure looks like a specific configuration export, a specific policy version, and a specific ticket makes the closeout assessment a verification exercise instead of a second investigation.

    One distinction worth keeping straight. A plan of action in the self-assessment and SPRS context is a management tool for tracking your own gaps, and organizations have kept them for years under DFARS 252.204-7012. A POA&M in the conditional-status context is a regulated instrument with eligibility rules and a 180-day clock attached. They can contain the same rows. They do not carry the same consequences, and treating the second like the first is how a conditional status expires.

    How this should change what you do

    Plan to arrive finished. The realistic use of a POA&M is a short list of low-weight items that slipped, not a project plan. Any readiness engagement that budgets a POA&M as a phase has misread the rule.

    Do the six exclusions early and cheaply. Visitor escort procedure, physical access log, access-device management, external-connection controls, a public-posting review process, and a written System Security Plan. None of those need capital. All of them can block a conditional status.

    Write the SSP first, not last. It is excluded from deferral, and it is also the document that makes everything else assessable. Our note on running the self-assessment covers why the objective-level view matters here.

    Schedule the closeout at the start. Book it when the conditional status is issued, not when the remediation feels close.

    What the Phase 2 suspension does to this

    Nothing about the rules above. 32 CFR 170.21 is part of the program rule, which remains in force. What the July 13, 2026 suspension of Phases 2 through 4 changed is the timing of the contractual trigger for the certification assessments these POA&M rules govern, which is a scheduling question rather than a substantive one. If you are working out what is still owed today, our piece on the suspension separates the two.

    The one practical implication: an organization that would have relied on a POA&M to make a November 2026 date now has time to close those items properly instead. That is the best use of the pause we can think of.

    Where Top Floor fits

    Most of the POA&M problems we are asked to fix are not technical. They are that nobody read 170.21 closely enough to notice the six exclusions, so the plan deferred an item that could never be deferred. Our CMMC work reads the deferral eligibility of every open gap before an assessment is booked, which is a half-day exercise that occasionally saves a cycle.

    Where the same team is also carrying commercial framework obligations, running them together through compliance as a service usually costs less than running two programs.

    If your gaps are mostly 5-point technical items, we will tell you that a POA&M is not your route and that the honest answer is engineering time.

    How to decide this week

    List every open gap with its point weight and mark each one deferrable or not, using the rule above: 1-point items yes, the six named exclusions no, SC.L2-3.13.11 only if encryption is running but unvalidated.

    Add up the score you would present. If it is below 88 of 110, conditional status is not available and the question is which high-weight items to close first.

    Then check the six exclusions specifically, because they are cheap, they are commonly missed, and any one of them open is a stop.

    Frequently asked questions

    What is the 80 percent rule for CMMC POA&Ms?

    To be eligible for a Conditional CMMC Status with open POA&M items, 32 CFR 170.21 requires the assessment score divided by the total number of Level 2 security requirements to be at least 0.8, which works out to 88 of 110. It is not permission to leave 20 percent of the work undone, because only 1-point requirements may be deferred and the six named exclusions may not be deferred at all, so an organization that reaches 88 by way of high-weight gaps still does not qualify.

    Which CMMC requirements can never go on a POA&M?

    Six Level 2 requirements are excluded regardless of point value: AC.L2-3.1.20 external connections, AC.L2-3.1.22 control of publicly posted information, CA.L2-3.12.4 the system security plan, PE.L2-3.10.3 escorting visitors, PE.L2-3.10.4 physical access logs, and PE.L2-3.10.5 managing physical access devices. In addition, only requirements weighted at 1 point are deferrable, with a single exception at SC.L2-3.13.11.

    Can FIPS-validated encryption be on a POA&M?

    Only in one situation. SC.L2-3.13.11, which requires FIPS-validated cryptography to protect CUI, may be included on a POA&M where encryption is employed but is not FIPS-validated, which 32 CFR 170.21 treats as a 3-point value. That is a deferral of the validation status of encryption you are already running, not permission to defer encryption itself.

    How long do I have to close a CMMC POA&M?

    Closure must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. The clock covers the assessment and not just your remediation work, so the practical schedule has to fit remediation, evidence collection, assessor scheduling, and the closeout assessment itself inside the window. Level 1 self-assessments are different again: a POA&M is not permitted at any time.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.