Plan of Action and Milestones
A Plan of Action and Milestones (POA&M) is a document that lists known security weaknesses in a system and describes the specific steps, resources, and target dates for fixing them. It functions as a corrective action plan, tracking each identified deficiency and how it will be addressed over time. In most implementations, system owners and security personnel create and maintain the POA&M as part of managing a system's security posture.
A POA&M is a document that identifies tasks needing to be accomplished to remediate identified security weaknesses, deficiencies, and risks, detailing the resources required to complete the plan's elements, the milestones for meeting those tasks, and scheduled completion dates for those milestones. In the NIST-based Risk Management Framework, the POA&M is associated with security control CA-5, and in FedRAMP implementations, CA-5 generally requires cloud service providers to develop a POA&M to document remediation plans for correcting weaknesses and deficiencies. In practice, business/system owners and Information System Security Officers (ISSOs) typically create and maintain POA&Ms, and the document is treated as a living artifact subject to ongoing update through continuous monitoring rather than a one-time deliverable. Readers should note that specific control identifiers, formatting, and submission requirements vary by revision and by agency or program tailoring, and should verify the applicable current authoritative text (for example, the relevant NIST publication or FedRAMP guidance) for precise obligations.
Why it matters
The POA&M is central to how risk is managed transparently within the Risk Management Framework and authorization processes. Rather than requiring that every security weakness be resolved before a system operates, the framework generally allows known deficiencies to be documented, prioritized, and tracked toward remediation. The POA&M is the artifact that makes this possible, giving authorizing officials a clear picture of outstanding risks and the plans to address them so they can make informed risk-based authorization decisions. Without a well-maintained POA&M, weaknesses can go untracked, remediation can stall, and an authorizing official may lack the visibility needed to accept or reject residual risk responsibly.
A common and consequential mistake is treating the POA&M as a one-time deliverable produced only at assessment or authorization. In practice, it is a living artifact updated through continuous monitoring, and an Authority to Operate is time-bound and contingent on the ongoing management of the risks the POA&M captures. It is also important to remember that documenting a weakness in a POA&M is not the same as fixing it; the POA&M reflects remediation intent and schedule, not completed security. Confusing the existence of a corrective action plan with actual risk reduction is a distinction experienced practitioners insist on maintaining.
Because specific control identifiers, formatting expectations, and submission requirements vary by revision and by agency or program tailoring, the POA&M's exact obligations differ across contexts. FedRAMP implementations, DoD systems under the RMF, and civilian agency systems under FISMA may each impose distinct expectations on how POA&Ms are structured, updated, and reviewed. Readers should verify the applicable current authoritative text for their specific program rather than assuming a single uniform standard applies everywhere.
Who it's relevant to
Inside POA&M
Common questions
Answers to the questions practitioners most commonly ask about POA&M.