CMMC 3.12.2 (POA&M): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.12.2 · CMMC Practice: CA.L2-3.12.2 · Updated June 2026

    Plain-English answer

    3.12.2 requires you to develop and implement plans of action (POA&Ms) that correct deficiencies and reduce or eliminate vulnerabilities. The word that trips people is implement: a POA&M spreadsheet that never moves doesn't meet the control. You must show owners, milestones, and that items actually close.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment.

    Why it matters

    The POA&M is how you demonstrate continuous improvement and manage residual risk. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology). Note: this control is separate from the CMMC program's conditional-status POA&M rules, which limit what can be deferred and impose a 180-day close window.

    Control lineage

    • CMMC Practice: CA.L2-3.12.2
    • NIST 800-171 Rev. 2: §3.12.2 — develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
    • NIST 800-171A objectives: [a] a plan of action is developed to correct identified deficiencies; [b] a plan of action is developed to reduce or eliminate vulnerabilities; [c] the plan of action is implemented to correct deficiencies; [d] the plan of action is implemented to reduce or eliminate vulnerabilities.

    What the assessor will EXAMINE

    • The POA&M itself — deficiencies/vulnerabilities, owners, milestones, target dates, status.
    • Closure evidence for items marked done (not just a status change).
    • Linkage to the SSP and to scan/assessment findings.
    • The POA&M management policy/process and SSP narrative for 3.12.2.

    What the assessor will INTERVIEW & TEST

    • Interview: "Walk me through a POA&M item from open to closed." — owner, milestones, and the evidence that closed it.
    • Test: Pick a closed item and verify the corrective action was actually implemented.
    • Test: Confirm new findings (from scans/reviews) flow into the POA&M.

    Evidence examples (produce these)

    • A current POA&M with owners, milestones, target dates, and status.
    • Closure provenance for completed items (the artifact that proves the fix).
    • An audit trail of POA&M transitions (open → in progress → closed).
    • POA&M management policy.
    • SSP section 3.12.2 referencing the above.

    Common failure patterns

    • A POA&M that's written but never worked — objectives [c]/[d] fail.
    • Items marked "closed" with no evidence the fix happened.
    • No owners or milestones, so it can't be shown as implemented.
    • Findings from scans/reviews never make it onto the POA&M.

    SPRS impact & POA&M eligibility

    SPRS: 3.12.2 carries a weighted deduction (verify the exact value). Program POA&M rules: distinct from this control — certain high-weighted requirements can't be deferred, you need at least 88 to use one, and conditional status gives 180 days to close. Confirm eligibility against current CMMC rules.

    Assessor-ready summary

    You're good on 3.12.2 when your POA&M lists deficiencies with owners, milestones, and dates; items are actively worked and closed with evidence; new findings flow in; and it ties to the SSP.

    POA&M living in a spreadsheet nobody updates? Athena auto-drafts POA&Ms, assigns owners and SLAs, and auto-closes items when covering evidence lands. See POA&M management →

    Related: 3.12.4 System Security Plan · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.