CMMC ANSWER ENGINE

Which CMMC controls can NOT be on a POA&M?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14
Quick answer. Level 1 allows no POA&M, ever. Level 2 (Self or C3PAO Certification) earns Conditional Status only if all three of these are true: score at least 88 of 110, every POA&M item is a 1-point practice (with one carve-out for FIPS), and none of the six named L2 practices appear on the POA&M.

Level 1: no POA&M, ever

Every L1 practice must be MET at the time of the self-assessment. There is no POA&M path at Level 1.

Level 2: three conditions for Conditional Status

Under 170.21(a)(2), all three of the following must be true. Miss any one and Conditional Status is not available:

  1. Score at least 0.8. The assessment score divided by 110 must be greater than or equal to 0.8, which means 88 of 110.
  2. Point-value cap, with one carve-out. No POA&M item may have a point value greater than 1 in the CMMC Scoring Methodology (32 CFR 170.24). The one carve-out: SC.L2-3.13.11 (CUI Encryption) may be on a POA&M at point value 3 if encryption is employed for CUI but the cryptographic module is not FIPS-validated.
  3. Six named practices excluded. Even though they are 1-point practices, the six in the table below may never be on a POA&M.

The six L2 practices that can never be on a POA&M

PracticeTitle
AC.L2-3.1.20External Connections (CUI Data)
AC.L2-3.1.22Control Public Information (CUI Data)
CA.L2-3.12.4System Security Plan
PE.L2-3.10.3Escort Visitors (CUI Data)
PE.L2-3.10.4Physical Access Logs (CUI Data)
PE.L2-3.10.5Manage Physical Access (CUI Data)

Why MFA is effectively excluded even though it isn't in the named six

MFA (IA.L2-3.5.3) is a 5-point practice. The point-value cap in (a)(2)(ii) excludes any practice greater than 1 point, so MFA is excluded by the cap, not by name. The practical effect is the same: MFA must be MET at assessment.

The FIPS carve-out

FIPS-validated cryptography (SC.L2-3.13.11) is normally a 5-point practice. The rule carves out one specific case where it may be on a POA&M at point value 3: encryption is in use for CUI, but the cryptographic module is not FIPS-validated. You still lose 3 points against the 88 floor.

The carve-out only applies if encryption is in use. If no encryption is employed at all, the practice is fully NOT MET and the carve-out does not apply.

Closeout assessment (within 180 days)

A POA&M closeout assessment only re-evaluates the items that were on the POA&M. It must be completed within 180 days of the Conditional CMMC Status Date, or the Conditional Status expires. Who performs the closeout depends on the assessment type:

  • Level 2 self-assessment: the OSA closes its own POA&M in the same manner as the initial self-assessment.
  • Level 2 certification assessment: the C3PAO that performed the initial assessment closes it.

How to use this when planning

  1. Identify your gaps through an internal readiness assessment before the formal assessment.
  2. Score each gap using the CMMC Scoring Methodology (32 CFR 170.24) to know its point value.
  3. For each gap, run the screen: is it a 1-point practice? Is it on the named-six list? Does the FIPS carve-out apply?
  4. Sum the POA&M-eligible deductions. If the result is below 88, you cannot pass even with the POA&M allowance. Remediate to MET before the assessment.
  5. Build a 180-day closeout plan for every POA&M item, with assigned owners and evidence to be produced.

Common errors

  • Listing a 3-point or 5-point practice on a POA&M (other than the FIPS carve-out). The (a)(2)(ii) point-value cap excludes them.
  • Missing one of the six named L2 exclusions. They are 1-point practices the rule still excludes from the POA&M, so the point-value test alone will not catch them.
  • Treating the FIPS carve-out as a license to skip FIPS. The carve-out only applies if encryption is in use. Missing encryption is fully NOT MET.
  • POA&M items at L1. Not allowed at any time.

Sources

  • 32 CFR Part 170 — § 170.21(a)(2) POA&M restrictions — link
  • 32 CFR 170.21 Plan of Action and Milestones requirements (eCFR, current as of 5/14/2026) — (a)(1) L1; (a)(2) L2 with named-six in (a)(2)(iii); (b) closeout — link
  • CMMC Assessment Process (CAP) v2.0 — POA&M evaluation and closeout assessment — link
  • CMMC 101 Brief (Nov 2025) — link
  • DoD Assessment Methodology for NIST SP 800-171 v1.2.1 — link
  • DoW CIO CMMC Frequently Asked Questions (Revision 2.3, May 2026) — C-Q7 and C-Q10 — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CAP v2.0 (Dec 2024)
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.