If you’ve spent any time preparing for NIST 800-171 or DFARS 70-12 compliance, you’ve probably come across the terms POA&M and OPA. While they may sound similar, they serve very different purposes during the certification or self-attestation process. Knowing when each one applies—and just as importantly, when it doesn’t—can help organizations avoid unnecessary delays, misunderstandings, or even outright non-compliance.
In this blog, we’ll break down the differences between Plans of Action and Milestones (POA&Ms) and Operational Plans of Action (OPAs), explain when each is appropriate, and highlight how they fit into the broader CMMC assessment process. Whether you’re getting ready for your first assessment or refining your compliance program, understanding these documents is an important step toward a smoother path to certification.
What is A POA&M?
According to the 32 CFR 170.21 Plan of Action and Milestone (POA&M) are for purposes of achieving a Conditional CMMC Status, an Organization Seeking Assessment (OSA) is only permitted to have a POA&M for select requirements scored as NOT MET during the CMMC assessment and only under the following conditions:
- Level 1 self-assessment.
- Level 2 self-assessment and Level 2 certification assessment.
- Level 3 certification assessment.
- None of the security requirements included in the POA&M have a point value of greater than 1 as specified in the CMMC Scoring Methodology set forth in § 170.24, except SC.L2-3.13.11 CUI Encryption may be included on a POA&M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3; and None of the following security requirements are included in the POA&M:
- AC.L2-3.1.20 External Connections (CUI Data).
- AC.L2-3.1.22 Control Public Information (CUI Data).
- CA.L2-3.12.4 System Security Plan.
- PE.L2-3.10.3 Escort Visitors (CUI Data).
- PE.L2-3.10.4 Physical Access Logs (CUI Data).
- PE.L2-3.10.5 Manage Physical Access (CUI Data).
POA&Ms follow a specific closeout requirement set in that same section of the 32 CFR
“A POA&M closeout assessment is a CMMC assessment that assesses only the NOT MET requirements that were identified with POA&M in the initial assessment. The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.”
What is an OPA?
According to the CMMC CIO FAQ, Operational Plan of Actions (OPAs) are measures implemented to manage risks or vulnerabilities, such as applying patches, addressing temporary deficiencies, or performing routine system maintenance. OPAs are not tied to a specific timeline for completion and are typically used to address vulnerabilities or deficiencies that arise after the initial implementation of security requirements.
When Should You use them
Once again using the CMMC CIO FAQ, when a significant change occurs in an information system that affects the satisfaction of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 security requirements, the appropriate course of action—whether to create a POA&M or an OPA—depends on the nature and timing of the change. If the significant change introduces a temporary deficiency or vulnerability after the system was initially compliant, an OPA may be created to document the remediation plan. However, if the significant change is identified during a CMMC assessment and results in a security requirement being assessed as NOT MET, a POA&M must be created to address the gap within the 180-day remediation window.
For more clarification on what a “Significant Change” means, please refer to our white paper, CMMC Recertification—What Constitutes a “Significant Change” That Would Require a Second C3PAO Assessment.
Final Thoughts
Understanding the difference between POA&Ms and OPAs is more than just learning another CMMC acronym—it can have a direct impact on your assessment readiness and certification timeline. Knowing when each document is appropriate helps organizations address gaps correctly, communicate effectively with assessors, and avoid unnecessary setbacks during the assessment process.
If you’re preparing for a CMMC assessment and have questions about POA&Ms, OPAs, or your overall compliance strategy, the team at 112Cyber is here to help. Our Certified CMMC Assessors and compliance experts have guided organizations through every stage of the certification journey. Contact us today to discuss your CMMC goals and learn how we can help you achieve certification with confidence.