{"data":{"id":"us/32-cfr-170.21","jurisdiction":"us","citation":"32 CFR 170.21","heading":"Plan of Action and Milestones requirements.","body":"(a) POA\u0026M. For purposes of achieving a Conditional CMMC Status, an OSA is only permitted to have a POA\u0026M for select requirements scored as NOT MET during the CMMC assessment and only under the following conditions:\n(1) Level 1 self-assessment. A POA\u0026M is not permitted at any time for Level 1 self-assessments.\n(2) Level 2 self-assessment and Level 2 certification assessment. An OSA is only permitted to achieve the CMMC Status of Conditional Level 2 (Self) or Conditional Level 2 (C3PAO), as appropriate, if all the following conditions are met:\n(i) The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8;\n(ii) None of the security requirements included in the POA\u0026M have a point value of greater than 1 as specified in the CMMC Scoring Methodology set forth in § 170.24, except SC.L2-3.13.11 CUI Encryption may be included on a POA\u0026M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3; and\n(iii) None of the following security requirements are included in the POA\u0026M:\n(A) AC.L2-3.1.20 External Connections (CUI Data).\n(B) AC.L2-3.1.22 Control Public Information (CUI Data).\n(C) CA.L2-3.12.4 System Security Plan.\n(D) PE.L2-3.10.3 Escort Visitors (CUI Data).\n(E) PE.L2-3.10.4 Physical Access Logs (CUI Data).\n(F) PE.L2-3.10.5 Manage Physical Access (CUI Data).\n(3) Level 3 certification assessment. An OSC is only permitted to achieve the CMMC Status of Conditional Level 3 (DIBCAC) if all the following conditions are met:\n(i) The assessment score divided by the total number of CMMC Level 3 security requirements is greater than or equal to 0.8; and\n(ii) The POA\u0026M does not include any of following security requirements:\n(A) IR.L3-3.6.1e Security Operations Center.\n(B) IR.L3-3.6.2e Cyber Incident Response Team.\n(C) RA.L3-3.11.1e Threat-Informed Risk Assessment.\n(D) RA.L3-3.11.6e Supply Chain Risk Response.\n(E) RA.L3-3.11.7e Supply Chain Risk Plan.\n(F) RA.L3-3.11.4e Security Solution Rationale.\n(G) SI.L3-3.14.3e Specialized Asset Security.\n(b) POA\u0026M closeout assessment. A POA\u0026M closeout assessment is a CMMC assessment that assesses only the NOT MET requirements that were identified with POA\u0026M in the initial assessment. The closing of a POA\u0026M must be confirmed by a POA\u0026M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA\u0026M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.\n(1) Level 2 self-assessment. For a Level 2 self-assessment, the POA\u0026M closeout self-assessment shall be performed by the OSA in the same manner as the initial self-assessment.\n(2) Level 2 certification assessment. For Level 2 certification assessment, the POA\u0026M closeout certification assessment must be performed by an authorized or accredited C3PAO.\n(3) Level 3 certification assessment. For Level 3 certification assessment, DCMA DIBCAC will perform the POA\u0026M closeout certification assessment.","path":["Title 32—National Defense","Subtitle A—Department of Defense","CHAPTER I—OFFICE OF THE SECRETARY OF DEFENSE","SUBCHAPTER G—DEFENSE CONTRACTING","PART 170—CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM","Subpart D—Key Elements of the CMMC Program"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-32.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:25:30Z","sha256":"1d4b36eb5c97b66a4b18c4439001f0b2b3356b2c6d3d1281b67169c4c2ca3f39","source_id":"us-cfr","stale":true,"prev":"us/32-cfr-170.20","next":"us/32-cfr-170.22"},"notice":"GroundRules: Original legal text. Not legal advice."}
