Level 1: no POA&M, ever
Every L1 practice must be MET at the time of the self-assessment. There is no POA&M path at Level 1.
Level 2: three conditions for Conditional Status
Under 170.21(a)(2), all three of the following must be true. Miss any one and Conditional Status is not available:
- Score at least 0.8. The assessment score divided by 110 must be greater than or equal to 0.8, which means 88 of 110.
- Point-value cap, with one carve-out. No POA&M item may have a point value greater than 1 in the CMMC Scoring Methodology (32 CFR 170.24). The one carve-out: SC.L2-3.13.11 (CUI Encryption) may be on a POA&M at point value 3 if encryption is employed for CUI but the cryptographic module is not FIPS-validated.
- Six named practices excluded. Even though they are 1-point practices, the six in the table below may never be on a POA&M.
The six L2 practices that can never be on a POA&M
| Practice | Title |
|---|---|
| AC.L2-3.1.20 | External Connections (CUI Data) |
| AC.L2-3.1.22 | Control Public Information (CUI Data) |
| CA.L2-3.12.4 | System Security Plan |
| PE.L2-3.10.3 | Escort Visitors (CUI Data) |
| PE.L2-3.10.4 | Physical Access Logs (CUI Data) |
| PE.L2-3.10.5 | Manage Physical Access (CUI Data) |
Why MFA is effectively excluded even though it isn't in the named six
MFA (IA.L2-3.5.3) is a 5-point practice. The point-value cap in (a)(2)(ii) excludes any practice greater than 1 point, so MFA is excluded by the cap, not by name. The practical effect is the same: MFA must be MET at assessment.
The FIPS carve-out
FIPS-validated cryptography (SC.L2-3.13.11) is normally a 5-point practice. The rule carves out one specific case where it may be on a POA&M at point value 3: encryption is in use for CUI, but the cryptographic module is not FIPS-validated. You still lose 3 points against the 88 floor.
The carve-out only applies if encryption is in use. If no encryption is employed at all, the practice is fully NOT MET and the carve-out does not apply.
Closeout assessment (within 180 days)
A POA&M closeout assessment only re-evaluates the items that were on the POA&M. It must be completed within 180 days of the Conditional CMMC Status Date, or the Conditional Status expires. Who performs the closeout depends on the assessment type:
- Level 2 self-assessment: the OSA closes its own POA&M in the same manner as the initial self-assessment.
- Level 2 certification assessment: the C3PAO that performed the initial assessment closes it.
How to use this when planning
- Identify your gaps through an internal readiness assessment before the formal assessment.
- Score each gap using the CMMC Scoring Methodology (32 CFR 170.24) to know its point value.
- For each gap, run the screen: is it a 1-point practice? Is it on the named-six list? Does the FIPS carve-out apply?
- Sum the POA&M-eligible deductions. If the result is below 88, you cannot pass even with the POA&M allowance. Remediate to MET before the assessment.
- Build a 180-day closeout plan for every POA&M item, with assigned owners and evidence to be produced.
Common errors
- Listing a 3-point or 5-point practice on a POA&M (other than the FIPS carve-out). The (a)(2)(ii) point-value cap excludes them.
- Missing one of the six named L2 exclusions. They are 1-point practices the rule still excludes from the POA&M, so the point-value test alone will not catch them.
- Treating the FIPS carve-out as a license to skip FIPS. The carve-out only applies if encryption is in use. Missing encryption is fully NOT MET.
- POA&M items at L1. Not allowed at any time.
Sources
- 32 CFR Part 170 — § 170.21(a)(2) POA&M restrictions — link
- 32 CFR 170.21 Plan of Action and Milestones requirements (eCFR, current as of 5/14/2026) — (a)(1) L1; (a)(2) L2 with named-six in (a)(2)(iii); (b) closeout — link
- CMMC Assessment Process (CAP) v2.0 — POA&M evaluation and closeout assessment — link
- CMMC 101 Brief (Nov 2025) — link
- DoD Assessment Methodology for NIST SP 800-171 v1.2.1 — link
- DoW CIO CMMC Frequently Asked Questions (Revision 2.3, May 2026) — C-Q7 and C-Q10 — link