A Plan of Action & Milestones is the least glamorous document in the CMMC stack and the one most likely to be requested by a prime with no warning. It's also structurally simple — a table of what's not done, who owns it, and when it will be — which is exactly why the failures are so visible: gap lists with no dates, dates with no owners, and "ongoing" written in the milestone column. Here's the template that works, filled rows included. (New to the POA&M entirely? Start with the explainer; this post is the build guide.)

The Columns a Defensible POA&M Needs

ColumnWhat goes in itThe mistake to avoid
Item #A stable ID you can reference from the SSP and status meetingsRenumbering every revision
ControlThe NIST SP 800-171 requirement ID (e.g., SC.L2-3.13.11)Grouping several controls into one vague row
WeaknessPlain statement of what's missing, specific to your environmentRestating the requirement instead of the gap
PointsThe control's DoD weight (1, 3, or 5) — this is your prioritization columnOmitting it and fixing easy 1-pointers first
OwnerA named person, even in a five-person shop"IT" is not an owner
ResourcesBudget, tooling, or outside help requiredPretending remediation is free — assessors read this column for realism
MilestonesInterim, dated steps for anything longer than a monthOne milestone that just repeats the completion date
Completion dateThe date you're committing to — feeds the SPRS field directly"Ongoing," "TBD," or a date nobody believes
StatusOpen / in progress / completed, with the completion evidence notedClosing items without recording what proved them closed

Two Example Rows, Filled In

Item 7 · SC.L2-3.13.11 · 5 points. Weakness: CUI at rest on three engineering laptops is encrypted with BitLocker in a non-FIPS mode. Owner: J. Rivera. Resources: none — configuration change plus re-encryption window. Milestones: enable FIPS-compliant algorithms via GPO (Aug 22); re-encrypt and verify all three devices (Sep 5). Completion: Sep 5, 2026. Status: in progress.

Item 12 · CA.L2-3.12.1 · 5 points. Weakness: no recurring internal assessment of control effectiveness has been performed. Owner: D. McLain. Resources: 8 hours/quarter. Milestones: adopt quarterly review checklist (Aug 29); complete first review cycle (Oct 3). Completion: Oct 3, 2026. Status: open.

Note what makes these work: the weakness names real systems, the points column justifies why these two jumped the queue, and each date is one someone agreed to. Six honest columns beat sixteen empty ones.

The Two Rulebooks — Don't Mix Them Up

POA&M confusion almost always comes from blending two regimes that share the document but not the rules:

The planning consequence: if certification is in your future, sequence remediation so the un-POA&M-able controls are done first. A contractor who spends the pause closing 5-pointers arrives at the restart already eligible; one who parked MFA on a POA&M arrives ineligible by rule.

A POA&M that builds and maintains itself

CMMC Map derives your POA&M from your actual assessment — every unmet control, weighted and dated — and closes items automatically when the underlying control status changes. Free to assess; the generated documents are $149/month.

See your gap list — free →
Free to assess · No credit card · Documents $149/mo

Maintenance Is the Actual Deliverable

A POA&M is evidence of management, and management is recurring: review it monthly, move milestones with a note when reality moves, record what evidence closed each item, and keep superseded versions. When your posture improves, update your SPRS score — a rising score with a shrinking POA&M is the single best supplier-risk story you can show a prime, and it costs nothing but the honesty of keeping both current.