How Common Are CMMC POA&Ms?
Table of Contents
ToggleFrequency, Typical Counts, and What They Mean for Level 2 Status
Based on N = 47 completed formal Level 2 assessments • January 2025 – June 2026 • Updated August 2026
≥1 POA&M (35 of 47)
When Present
Window
Expected Outcome
On 13 July 2026 the Department of War suspended CMMC Phase II requirements pending a 60-day reform review. Phase I self-assessment requirements and DFARS 252.204-7012 remain in effect. Voluntary C3PAO assessments continue. Primary sources: DoW Release · Memo 26-P-1023 · DoD CIO CMMC.
1. What a POA&M Is in CMMC Level 2
A Plan of Action and Milestones (POA&M) documents practices that are not fully met at the time of assessment and the organization’s plan to remediate them. Under the CMMC program rule, certain findings can be placed on a POA&M and still allow a Conditional Level 2 status, provided the items are closed within the allowed window (typically 180 days) to achieve Final status.
POA&Ms are not the same as a failed assessment. They are a structured mechanism for residual risk that is acknowledged, time-bounded, and trackable.
2. Observed Frequency (N = 47)
| Metric | Value | Denominator / Notes |
|---|---|---|
| Assessments with ≥1 POA&M item | 74% (35 of 47) | Full formal Level 2 assessments |
| Assessments with zero POA&M items | 26% (12 of 47) | |
| Median number of POA&M items (when present) | 3 | Among the 35 assessments with findings |
| Typical close-out expectation | Within 180 days | To move from Conditional to Final status |
POA&M Presence (N = 47)
3. Most Common POA&M Categories
When residual findings were placed on a POA&M, they most often fell into these areas (aligned with the top residual findings overall):
- Multifactor authentication gaps (IA.L2-3.5.3) — incomplete coverage for privileged or remote paths
- Logging completeness and review (AU.L2-3.3.1 / 3.3.2)
- Configuration baselines and change control (CM.L2-3.4.1 / 3.4.2)
- Vulnerability management / flaw remediation cadence (SI.L2-3.14.x)
- Media protection and sanitization evidence (MP.L2-3.8.x)
These categories also dominate the broader list of common assessment findings. Addressing them during readiness is the highest-leverage way to reduce both residual findings and POA&M volume.
4. Conditional vs. Final Status
A limited POA&M typically results in a Conditional Level 2 (C3PAO) status. Organizations that close the POA&M items within the allowed window and provide clear remediation evidence generally achieve Final Level 2 (C3PAO) status without further delay.
In the observed set, organizations that treated POA&M close-out as a project (owner, due date, evidence package) moved to Final status reliably. Those that deferred remediation or produced weak close-out evidence experienced longer timelines.
5. What a “Good” POA&M Looks Like
- Specific — tied to a named practice and a concrete gap
- Time-bounded — clear milestone dates within the allowed window
- Owned — named responsible party
- Evidence-ready — the planned remediation will produce assessable artifacts
- Limited in scope — not a laundry list of fundamental control failures
Assessors and the program distinguish between a small number of well-scoped residual items and a POA&M that effectively defers core implementation. The former is normal; the latter raises risk and extends timelines.
6. Practical Implications for Organizations
- Do not treat “zero POA&M” as the only success metric. 74% of assessments in this dataset had at least one item.
- Budget time for close-out. Build the 180-day window into project plans rather than treating Final status as automatic.
- Pre-empt the top categories. MFA, logging, baselines, and vulnerability management account for a disproportionate share of POA&M items.
- Keep remediation evidence as clean as assessment evidence. Close-out packages that lack context or timestamps create avoidable friction.
- Enclaves help. Smaller, well-defined boundaries correlated with fewer residual findings and cleaner POA&M profiles.
7. Related Benchmark Metrics
- Median formal assessment duration: 17 business days
- Required additional evidence during assessment: 89% (42 of 47)
- Average evidence volume: ~1,920 artifacts
- Enclave vs enterprise: 66% / 34%
Full aggregate data: 2026_CMMC_Benchmark_Aggregate_Data.csv
8. Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Authorized CMMC C3PAO leadership; A2LA-accredited FedRAMP 3PAO; PCI DSS QSA firm principal.
How to Cite
Peters, M. D. (2026). How Common Are CMMC POA&Ms? Lazarus Alliance, Inc. Data drawn from the 2026 CMMC Assessment Benchmark Report (N = 47).
9. About Lazarus Alliance
Lazarus Alliance is an authorized CMMC Third-Party Assessment Organization (C3PAO, CPN 10251), an A2LA-accredited FedRAMP 3PAO, a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized assessments and do not guarantee individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Data Source
This analysis is based on the 2026 CMMC Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 47 completed formal CMMC Level 2 C3PAO assessments conducted between January 2025 and June 2026.
Additional Analysis
- How Long Does a CMMC Level 2 Assessment Take?
- 7 Most Common CMMC Level 2 Assessment Findings
- How Much Evidence Does a CMMC Assessment Require?
- CMMC Enclave vs Enterprise: What 47 Assessments Show
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
