A plan of action and milestones — the POA&M — is how a security programme records what it has not fixed yet, and it is the artifact that decides whether an authorizing official signs. It is also the one most organizations treat as a formality, which is exactly why assessors read it first.
This guide covers what a POA&M has to contain, where it is required in 2026 and where it has been retired, and the three habits that turn it from a live plan into a graveyard.

What a plan of action and milestones is
A POA&M is the register of known security weaknesses, what will be done about each one, who owns it, what it will cost and when it will be closed. It exists because no system is ever fully remediated at the moment somebody has to decide whether to operate it — the question is not whether weaknesses exist but whether the residual risk is acceptable and shrinking.
That framing explains its two audiences. Management uses it to allocate remediation resources. An authorizing official, assessor or customer uses it to judge whether the programme is under control — and a plan full of items overdue by a year answers that question in the wrong direction.
What each entry needs
| Field | What it holds, and why it matters |
|---|---|
| Identifier | A stable reference so assessment findings and the plan can be tied together |
| Weakness | What is actually wrong, in terms somebody outside the team can act on |
| Source | Where it was found — assessment, scan, audit, incident, self-identification |
| Affected control | The control the weakness sits against, so coverage gaps aggregate |
| Risk rating | Severity after any compensating control, not the raw scanner score |
| Remediation plan | What will be done, specifically enough to be checked |
| Milestones with dates | The intermediate points — the part that makes it a plan |
| Owner and resources | A named role and what it will take, including money |
| Status and completion date | Open, ongoing, completed — with the evidence of closure |
The milestone row is what separates a POA&M from a findings list. A single “remediate by December” with nothing in between cannot be managed, because nobody discovers it is failing until December.
Where a plan of action and milestones is required — and where it is not
- Federal systems under the NIST RMF. The plan of action and milestones is a core input to the authorization decision, and continuous monitoring keeps it current between authorizations. Our guide to the NIST RMF covers where it sits in the seven steps.
- NIST SP 800-171 and CMMC. Contractors record unimplemented requirements in a POA&M, and under CMMC only certain requirements are POA&M-eligible, with a defined closeout window rather than an open-ended one. A plan is not a substitute for implementation.
- 🔴 FedRAMP, no longer. Under the Consolidated Rules for 2026 the POA&M was retired along with the System Security Plan; the Security Decision Record now carries the position on each rule, including the reason and resulting customer risk where a rule is not followed. See what replaced the FedRAMP SSP.
Outside those regimes nothing compels a POA&M, and ISO 27001 does not use the term — but the same information appears as the risk treatment plan and the corrective action record. If you run both, keep one register and map it, rather than maintaining two lists that will disagree.
Three habits that kill a POA&M
Dates that move without a decision. A milestone that slips should require somebody with authority to accept a longer exposure. When completion dates are edited silently, the plan stops being a commitment and the trend becomes invisible.
Scanner output pasted in wholesale. A thousand rows from a vulnerability scan is not a plan of action and milestones; it is an input to one. Aggregate to the weakness, state the systemic fix, and keep the raw output as evidence.
No closure evidence. “Completed” with no artifact means the item is unverifiable, and an assessor will treat it as open. Record what proves the fix — a configuration export, a rescan, a test result — against the closing entry.
Making it useful to the people who read it
Three practices make a plan of action and milestones useful to the people who read it between a document that supports a decision and one that undermines it:
- Report the movement. Opened, closed, overdue and average age this period. A static count of open items tells nobody whether the programme is winning.
- Separate accepted risk from unfinished work. A weakness the organization has decided to live with is a risk acceptance with an owner and a review date, not a POA&M item that will sit open forever.
- Tie every entry to a control. When ten entries land on the same control family, the finding is not ten weaknesses — it is one systemic gap, and it should be funded as such.
Frequently asked questions
What does POA&M stand for?
Plan of action and milestones — the register of known security weaknesses with the remediation plan, owner, resources and dates for each.
Is a POA&M still required for FedRAMP?
No. The Consolidated Rules for 2026 retired both the POA&M and the System Security Plan for the provider package; the Security Decision Record now carries that information.
How long can an item stay open?
It depends on the regime. Some set explicit closure windows and limit which requirements may be deferred at all; where no window is set, the risk rating and the authorizing official’s tolerance decide it.
Who owns the POA&M?
A single owner maintains the register; each entry has its own remediation owner in the business or engineering team. Security owning every line means nothing outside security is committed.
Can we use it instead of implementing a control?
Only temporarily and only where the regime allows deferral. A plan of action and milestones documents a gap being closed, not a decision to leave it open.
Where this leaves you
Treat the plan of action and milestones as a management instrument, not a compliance exhibit. Write entries somebody outside the team can act on, put real milestones between now and the completion date, require a decision when a date moves, and record the evidence that closed each item. Then report the movement rather than the count — and check which regime you are in, because FedRAMP has retired the artifact while 800-171 and CMMC still turn on it.
References
- NIST SP 800-37 Revision 2 — the Risk Management Framework and the role of the plan of action and milestones in authorization.
- NIST SP 800-171 Revision 3 — the CUI protection requirements that contractors track against.
More on cyber risk management
- The plan of action and milestones — you are here
- The NIST RMF and its seven steps
- The cybersecurity risk register
- What replaced the FedRAMP SSP
Register templates, risk scoring and remediation tracking are in the NIST Cyber Risk Management Toolkit, or start with the free ISO templates.