How Common Are CMMC POA&Ms? | Lazarus Alliance

How Common Are CMMC POA&Ms?

Frequency, Typical Counts, and What They Mean for Level 2 Status

Based on N = 47 completed formal Level 2 assessments  •  January 2025 – June 2026  •  Updated August 2026

74%
Assessments with
≥1 POA&M (35 of 47)
3
Median POA&M Items
When Present
180 days
Typical Close-Out
Window
Normal
Not a Failure —
Expected Outcome
Quick Answer
POA&Ms are common. In the Lazarus Alliance dataset of N = 47 formal CMMC Level 2 assessments, 74% (35 of 47) resulted in at least one Plan of Action and Milestones item. When POA&Ms were present, the median number of items was 3. A limited, well-scoped POA&M with timely close-out is a normal path to Final Level 2 status — not a failed assessment.
August 2026 Regulatory Context
On 13 July 2026 the Department of War suspended CMMC Phase II requirements pending a 60-day reform review. Phase I self-assessment requirements and DFARS 252.204-7012 remain in effect. Voluntary C3PAO assessments continue. Primary sources: DoW Release · Memo 26-P-1023 · DoD CIO CMMC.

1. What a POA&M Is in CMMC Level 2

A Plan of Action and Milestones (POA&M) documents practices that are not fully met at the time of assessment and the organization’s plan to remediate them. Under the CMMC program rule, certain findings can be placed on a POA&M and still allow a Conditional Level 2 status, provided the items are closed within the allowed window (typically 180 days) to achieve Final status.

POA&Ms are not the same as a failed assessment. They are a structured mechanism for residual risk that is acknowledged, time-bounded, and trackable.

2. Observed Frequency (N = 47)

MetricValueDenominator / Notes
Assessments with ≥1 POA&M item74% (35 of 47)Full formal Level 2 assessments
Assessments with zero POA&M items26% (12 of 47)
Median number of POA&M items (when present)3Among the 35 assessments with findings
Typical close-out expectationWithin 180 daysTo move from Conditional to Final status

POA&M Presence (N = 47)

3. Most Common POA&M Categories

When residual findings were placed on a POA&M, they most often fell into these areas (aligned with the top residual findings overall):

  1. Multifactor authentication gaps (IA.L2-3.5.3) — incomplete coverage for privileged or remote paths
  2. Logging completeness and review (AU.L2-3.3.1 / 3.3.2)
  3. Configuration baselines and change control (CM.L2-3.4.1 / 3.4.2)
  4. Vulnerability management / flaw remediation cadence (SI.L2-3.14.x)
  5. Media protection and sanitization evidence (MP.L2-3.8.x)

These categories also dominate the broader list of common assessment findings. Addressing them during readiness is the highest-leverage way to reduce both residual findings and POA&M volume.

4. Conditional vs. Final Status

A limited POA&M typically results in a Conditional Level 2 (C3PAO) status. Organizations that close the POA&M items within the allowed window and provide clear remediation evidence generally achieve Final Level 2 (C3PAO) status without further delay.

In the observed set, organizations that treated POA&M close-out as a project (owner, due date, evidence package) moved to Final status reliably. Those that deferred remediation or produced weak close-out evidence experienced longer timelines.

5. What a “Good” POA&M Looks Like

  • Specific — tied to a named practice and a concrete gap
  • Time-bounded — clear milestone dates within the allowed window
  • Owned — named responsible party
  • Evidence-ready — the planned remediation will produce assessable artifacts
  • Limited in scope — not a laundry list of fundamental control failures

Assessors and the program distinguish between a small number of well-scoped residual items and a POA&M that effectively defers core implementation. The former is normal; the latter raises risk and extends timelines.

6. Practical Implications for Organizations

  • Do not treat “zero POA&M” as the only success metric. 74% of assessments in this dataset had at least one item.
  • Budget time for close-out. Build the 180-day window into project plans rather than treating Final status as automatic.
  • Pre-empt the top categories. MFA, logging, baselines, and vulnerability management account for a disproportionate share of POA&M items.
  • Keep remediation evidence as clean as assessment evidence. Close-out packages that lack context or timestamps create avoidable friction.
  • Enclaves help. Smaller, well-defined boundaries correlated with fewer residual findings and cleaner POA&M profiles.

7. Related Benchmark Metrics

  • Median formal assessment duration: 17 business days
  • Required additional evidence during assessment: 89% (42 of 47)
  • Average evidence volume: ~1,920 artifacts
  • Enclave vs enterprise: 66% / 34%

Full aggregate data: 2026_CMMC_Benchmark_Aggregate_Data.csv

8. Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Authorized CMMC C3PAO leadership; A2LA-accredited FedRAMP 3PAO; PCI DSS QSA firm principal.

How to Cite
Peters, M. D. (2026). How Common Are CMMC POA&Ms? Lazarus Alliance, Inc. Data drawn from the 2026 CMMC Assessment Benchmark Report (N = 47).

9. About Lazarus Alliance

Lazarus Alliance is an authorized CMMC Third-Party Assessment Organization (C3PAO, CPN 10251), an A2LA-accredited FedRAMP 3PAO, a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580  •  [email protected]
https://lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized assessments and do not guarantee individual outcomes.

Data Source

This analysis is based on the 2026 CMMC Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 47 completed formal CMMC Level 2 C3PAO assessments conducted between January 2025 and June 2026.

Additional Analysis

  1. How Long Does a CMMC Level 2 Assessment Take?
  2. 7 Most Common CMMC Level 2 Assessment Findings
  3. How Much Evidence Does a CMMC Assessment Require?
  4. CMMC Enclave vs Enterprise: What 47 Assessments Show

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.