Here’s a scenario: a CISO at a mid-size defense subcontractor handed their C3PAO assessor a POA&M document on day one of their CMMC Level 2 assessment. Thirty-one open items, organized by domain, each with a remediation timeline and an assigned owner. The work was real, the document was detailed, and the timelines were credible.
The assessor went through it and flagged twelve items immediately. These aren't deferrable to POA&M. These are assessment blockers.
Eight of those twelve were in the SC (System and Communications Protection) and IA (Identification and Authentication) domains — the high-weight controls. They weren't on the POA&M as a workaround. They were on the POA&M because no one had told the contractor that a POA&M isn't valid for those controls. Under 32 CFR 170.21, 3-point and 5-point controls must be fully implemented before an assessor scores them. No exceptions, no conditional pass, and no 180-day grace period.
The assessment paused. Remediation restarted. The November deadline got closer.
What a POA&M Is, and What It Isn't
A Plan of Action & Milestones is a documented remediation plan for security controls you haven't fully implemented at the time of your CMMC assessment. Under CMMC 2.0, a contractor with a few open items can receive a Conditional CMMC Status. This provisional certification gives them 180 days to close those gaps and complete a closeout assessment.
This is an important feature of the program. It acknowledges that real-world compliance programs don't achieve perfection simultaneously. A contractor who has implemented 105 of 110 controls shouldn't fail certification because three remaining gaps are in progress.
The misconception, and it's a costly one, is that POA&M is available for any unmet control. It isn't. The POA&M eligibility rules are specific, published, and non-negotiable. Getting them wrong means showing up to an assessment with open gaps you assumed were deferrable, discovering they're blockers, and either failing outright or postponing at significant cost.
A POA&M is a Grace Period, Not an Exemption
Under CMMC Level 2, you cannot use a paper plan to buy time for major 5-point requirements like encryption or key management. If your high-weight controls aren't fully operational when the auditor walks through the door, your assessment halts immediately. You need technical enforcement, not an aspirational timeline.
The 1-Point Rule: What Qualifies for POA&M
Under 32 CFR 170.21, the POA&M eligibility rule has a clear threshold: only controls with a point weight of 1 under the CMMC Scoring Methodology are eligible for deferral.
Every 3-point and 5-point control must be fully met before the assessor arrives. They are non-deferrable by definition. The assessment cannot proceed to scoring with these controls unimplemented, and no Conditional certificate can be issued if they're open.
Beyond the point-weight rule, six specific 1-point controls are explicitly excluded from POA&M eligibility under 32 CFR 170.21(a)(2)(iii)(A)-(F). These are low-weight controls that the DoD has determined are foundational enough to require full implementation regardless of their scoring value.
The practical result: 63 of 110 NIST SP 800-171 requirements cannot be deferred to a POA&M. The majority of CMMC Level 2 controls need to be done before your C3PAO walks in.
The Controls That Fail Assessments, and Why They're Non-Deferrable
The non-deferrable controls aren't uniformly distributed across domains. They cluster in the areas where compliance failures are most common, which is exactly why they carry 3-point and 5-point weights to begin with.
SC.3.177 — FIPS 140-3 Validated Encryption
Encryption of CUI at rest and in transit using FIPS 140-3 validated cryptographic modules. This is a 5-point control, non-deferrable, and one of the most commonly failed requirements in pre-assessment gap analyses.
The failure mode isn't that contractors haven't heard of FIPS 140-3. It's that they can't demonstrate that the specific cryptographic modules in use — within their actual file storage, collaboration tools, and endpoint encryption — are validated under the FIPS 140-3 standard. "We use BitLocker" or "we use SharePoint" is not sufficient. You need to identify the validated module, reference its CMVP certificate number, and demonstrate that it's actively operating in FIPS-approved mode.
Files that travel outside your primary CUI environment — downloaded to a contractor laptop, forwarded to a subcontractor, synced to a device — are encrypted with whatever the receiving device provides, which may or may not be FIPS-validated. That's the gap most enclave-based architectures leave open.
SC.3.187 — Organization-Controlled Key Management
Your encryption keys must be under your organizational control. If your cloud provider or managed service provider holds the keys and can decrypt your CUI without your active authorization, this control may not be met.
This one consistently catches contractors who assumed that using a major cloud platform satisfied the requirement. Microsoft, Google, and AWS all offer encryption by default, but in many tiers, the default architecture uses provider-managed keys. You need to verify that your key management architecture puts control in your hands, not your vendor's.
Multi-Factor Authentication (IA Domain)
MFA for all privileged access and all access to systems containing CUI. Non-deferrable. The most commonly failed control in pre-assessment gap analyses, according to CMMC practitioners.
The failure pattern: MFA is deployed for some systems and some users, but not all. A single CUI-connected system without enforced MFA is a failed control. A single privileged account without MFA is a failed control. Partial MFA deployment is not a met control under the CMMC assessment methodology.
System Security Plan Completeness
Your SSP must document every system, component, connection, and individual within your CUI boundary. Undocumented assets don't receive the benefit of the controls you've applied to documented assets; they're assessed as gaps. The SSP isn't just paperwork. It defines the scope your assessor examines.
Clearing the 5-Point Hurdles with Theodosian
Because the CMMC scoring math heavily penalizes unmet encryption and key management controls, a contractor's score can plunge below the critical assessment threshold from just a couple of missing components. You cannot defer these 5-point practices to a POA&M. You either have a technical mechanism that enforces them on day one, or you fail.
Theodosian helps remove the risk of a non-deferrable assessment failure by embedding zero-trust data security directly into individual files. Instead of forcing your IT team to engineer complex network boundaries or reconfigure entire legacy platforms to meet rigid auditing guidelines, Theodosian secures your highest-weight requirements right out of the box.
By implementing data-centric protection, you lock down the exact controls that assessors look to fail on day one:
- Compliant Cryptographic Controls (SC.3.177): Every protected file is wrapped in an independent layer of FIPS 140-3 validated encryption. Because the protection travels with the content, your CUI remains under strict cryptographic control whether it is stored on an endpoint, shared in a cloud enclave, or downloaded by a subcontractor.
- True Organizational Key Ownership (SC.3.187): Theodosian relies on a zero-knowledge, decentralized key management model. Your organization holds exclusive control over the root encryption keys—meaning third-party cloud providers or managed services have no technical pathway to decrypt your data.
- Defensible, Assessor-Ready Audit Logs: The system generates persistent, unalterable access logs for every file. When your C3PAO auditor asks for empirical evidence that transaction limits are technically enforced, you can hand over clear cryptographic proof rather than a stack of theoretical policies.
By making files self-defending assets, you shift your compliance strategy away from risky operational workarounds. You secure your most sensitive data at the content level, keep your assessment on track, and ensure your program clears the highest CMMC hurdles before the auditor ever arrives.

The Minimum Score You Need Before Assessment
To receive even a Conditional certificate at assessment, you need a minimum score of 88 out of 110 (approximately 80% of requirements met). Below that threshold, there is no conditional status, no 180-day remediation window, just a failed assessment.
That floor matters because contractors planning their remediation around POA&M flexibility often underestimate how many controls need to be done. If you have 30 open items and assume you can defer them all, you may cross below 88 into failed territory without realizing it, not because your gaps are too large in aggregate, but because enough of your open controls are 3-point and 5-point items that your actual CMMC score at assessment would be below the conditional threshold.
The arithmetic: if your open items include five 5-point controls and three 3-point controls, that's already 34 points subtracted from your score, taking you from 110 down to 76 — below the 88 conditional floor regardless of how many 1-point gaps you've also deferred.
The 180-Day Closeout Reality
A contractor who receives Conditional CMMC Status has 180 days to:
- Close every open POA&M item
- Schedule and complete a closeout assessment
- Receive Final CMMC Status
Under 32 CFR 170.21(b), every open POA&M item must be closed within 180 days of the Conditional CMMC Status Date. If the closeout assessment isn't completed within that window, the Conditional status expires.
An expired Conditional status means your CMMC certificate is no longer valid. Contracts that require CMMC Level 2 certification from November 10, 2026 onward are impacted directly.
The 180 days isn't a soft deadline. It's a hard cutoff with a documented expiration. That means the POA&M items you defer need to be genuinely completable within six months — not aspirationally plannable, but actually achievable given your remediation capacity, budget, and assessor availability for the closeout.
Getting a conditional pass on a complex set of 1-point gaps and then failing to close them within 180 days produces a worse outcome than not getting certified at all. You've spent the assessment budget, told your prime contractor you're certified, and then had that certification lapse mid-contract.
Building a POA&M That Survives an Assessment
A POA&M is a compliance document that an assessor will scrutinize. Every item on it needs to meet specific criteria under the CMMC assessment process:
Eligible controls only: Every item on your POA&M must be a 1-point control and must not be one of the six explicitly excluded 1-point controls under 32 CFR 170.21(a)(2)(iii). If a 3-point or 5-point control appears on your POA&M, it's a blocker, not a deferred item.
Realistic milestones: Milestone dates need to be credible and achievable within 180 days. A POA&M item that shows "remediate by November 2026" submitted to assessment in September 2026 gives you roughly 60 days of your 180-day window on day one.
Actual resource allocation: POA&M items need assigned owners and documented resources. "TBD" or "pending budget approval" on a POA&M item may be flagged as insufficiently committed during assessment review.
No aggregated items: Each unmet control should appear as a discrete item. Bundling multiple unmet requirements into a single POA&M entry makes it harder to demonstrate closure at the closeout assessment.
Document what's actually done: Controls that are partially implemented but scored as "Not Met" should have their current state documented alongside the remaining gap. This gives the closeout assessor a clear baseline and reduces the scope of closeout review.
Build an Airtight Score Before the Assessor Arrives
Don't let non-deferrable 5-point gaps sink your CMMC assessment and push you past your enforcement deadlines. By securing your Controlled Unclassified Information directly at the file level, you can confidently turn critical assessment blockers into automated, auditor-validated compliance victories.
FAQs: CMMC Level 2 POA&M
Can I submit my POA&M to SPRS along with my CMMC score?
Your SPRS submission includes your NIST 800-171 self-assessment score and must reference an associated SSP. The POA&M doesn't go into SPRS directly, but your submitted score should reflect your actual implementation status — including the gap represented by your open POA&M items. An inflated SPRS score that doesn't account for unmet controls is a False Claims Act exposure.
What happens if I fail my CMMC assessment outright?
A failed assessment — either because your score is below 88 or because non-deferrable controls aren't met — means you don't receive a CMMC certificate in any form. You'll need to remediate the blocking gaps and schedule a new assessment. Given current C3PAO waitlists of 6–9 months, a failed assessment that requires rescheduling may push your certification past the November 10, 2026, Phase 2 enforcement deadline.
Are there POA&M templates approved by the DoD?
The DoD has published POA&M guidance within the CMMC Assessment Process documentation. There is no single mandatory template, but the required fields are specified. Many RPOs and C3PAOs provide standardized templates that meet assessment requirements.
Can a conditional certificate be used to fulfill a contract CUI requirement?
Generally, yes — a Conditional CMMC Status satisfies the CMMC Level 2 requirement for contract performance while the 180-day remediation period is active. However, the specific contract clause will determine what's acceptable, and some primes have flowdown requirements that specify Final CMMC Status.
What if I discover a non-deferrable control gap the week before my assessment?
Postpone the assessment. The cost of postponement is significant: rescheduling C3PAO slots, delayed certification, potential contract impact. But a failed assessment with a non-deferrable blocker produces those same outcomes plus the cost of the failed assessment itself. If SC.3.177, SC.3.187, or MFA aren't implemented, those need to be addressed before the C3PAO arrives.