Skip to main content
Category: Authorization & Accreditation

Plan of Action and Milestones

Also known as: POA&M, POAM, POA and M, Plan of Actions and Milestones, Corrective Action Plan
Simply put

A Plan of Action and Milestones (POA&M) is a document that lists known security weaknesses in a system and describes the specific steps, resources, and target dates for fixing them. It functions as a corrective action plan, tracking each identified deficiency and how it will be addressed over time. In most implementations, system owners and security personnel create and maintain the POA&M as part of managing a system's security posture.

Formal definition

A POA&M is a document that identifies tasks needing to be accomplished to remediate identified security weaknesses, deficiencies, and risks, detailing the resources required to complete the plan's elements, the milestones for meeting those tasks, and scheduled completion dates for those milestones. In the NIST-based Risk Management Framework, the POA&M is associated with security control CA-5, and in FedRAMP implementations, CA-5 generally requires cloud service providers to develop a POA&M to document remediation plans for correcting weaknesses and deficiencies. In practice, business/system owners and Information System Security Officers (ISSOs) typically create and maintain POA&Ms, and the document is treated as a living artifact subject to ongoing update through continuous monitoring rather than a one-time deliverable. Readers should note that specific control identifiers, formatting, and submission requirements vary by revision and by agency or program tailoring, and should verify the applicable current authoritative text (for example, the relevant NIST publication or FedRAMP guidance) for precise obligations.

Why it matters

The POA&M is central to how risk is managed transparently within the Risk Management Framework and authorization processes. Rather than requiring that every security weakness be resolved before a system operates, the framework generally allows known deficiencies to be documented, prioritized, and tracked toward remediation. The POA&M is the artifact that makes this possible, giving authorizing officials a clear picture of outstanding risks and the plans to address them so they can make informed risk-based authorization decisions. Without a well-maintained POA&M, weaknesses can go untracked, remediation can stall, and an authorizing official may lack the visibility needed to accept or reject residual risk responsibly.

A common and consequential mistake is treating the POA&M as a one-time deliverable produced only at assessment or authorization. In practice, it is a living artifact updated through continuous monitoring, and an Authority to Operate is time-bound and contingent on the ongoing management of the risks the POA&M captures. It is also important to remember that documenting a weakness in a POA&M is not the same as fixing it; the POA&M reflects remediation intent and schedule, not completed security. Confusing the existence of a corrective action plan with actual risk reduction is a distinction experienced practitioners insist on maintaining.

Because specific control identifiers, formatting expectations, and submission requirements vary by revision and by agency or program tailoring, the POA&M's exact obligations differ across contexts. FedRAMP implementations, DoD systems under the RMF, and civilian agency systems under FISMA may each impose distinct expectations on how POA&Ms are structured, updated, and reviewed. Readers should verify the applicable current authoritative text for their specific program rather than assuming a single uniform standard applies everywhere.

Who it's relevant to

System and Business Owners
Business and system owners are typically responsible for creating and maintaining the POA&M, ensuring that identified weaknesses are documented and that remediation resources, milestones, and target dates are realistic and kept current. They rely on the POA&M to demonstrate that outstanding risks are being actively managed.
Information System Security Officers (ISSOs)
ISSOs commonly work alongside system owners to develop and update POA&Ms, tracking each deficiency and its remediation status. Because the POA&M is a living artifact tied to continuous monitoring, ISSOs play a central role in keeping entries accurate as weaknesses are discovered, remediated, or closed.
Authorizing Officials
Authorizing officials use the POA&M to understand the residual risks associated with a system before granting or continuing an authorization. Because an Authority to Operate is time-bound and dependent on ongoing risk management, the POA&M informs risk-based decisions throughout the system's lifecycle, not only at the initial authorization.
Cloud Service Providers in FedRAMP
Under FedRAMP implementations, security control CA-5 generally requires cloud service providers to develop a POA&M documenting remediation plans for correcting weaknesses and deficiencies. CSPs should confirm the specific formatting and submission expectations against current FedRAMP guidance, and should not assume a FedRAMP-oriented POA&M automatically satisfies DoD or other program requirements.
Assessors and Auditors
Assessors and auditors review POA&Ms to evaluate whether identified weaknesses are being tracked and remediated according to documented milestones. They should be careful to distinguish assessment findings from authorization decisions, and to recognize that a documented remediation plan reflects intent rather than completed security.

Inside POA&M

Identified Weakness or Deficiency
A description of each security control weakness, unmet requirement, or vulnerability identified during assessment, continuous monitoring, or audit that has not yet been fully remediated.
Associated Control or Requirement
A reference to the specific control or requirement (for example, from a NIST SP 800-53 baseline or the NIST SP 800-171 requirements applicable to CUI) that the weakness relates to. Practitioners should confirm the mapping against the applicable revision of the governing publication.
Planned Remediation or Corrective Actions
A description of the tasks or milestones the organization intends to complete to correct or mitigate the identified weakness.
Resources Required
An indication of the resources, such as funding, personnel, or technology, estimated as necessary to complete the corrective actions, as required in most implementations.
Scheduled Completion Date and Milestones
Target dates for completing remediation, generally broken into interim milestones so progress can be tracked over time.
Status and Point of Contact
The current status of each corrective action and, in most implementations, an assigned responsible party or point of contact accountable for the remediation effort.

Common questions

Answers to the questions practitioners most commonly ask about POA&M.

Does having an approved POA&M mean the associated weaknesses are already resolved?
No. A POA&M documents planned corrective actions for identified deficiencies; it is a management and tracking tool, not evidence of remediation. Open items on a POA&M generally represent accepted, deferred, or in-progress risks rather than closed findings. The weaknesses remain until the corrective actions are completed and verified, and the POA&M is updated to reflect closure. Treating an entry as resolved simply because it appears on the plan is a common error that reviewers and assessors will flag.
Does a POA&M with open items automatically prevent an Authority to Operate (ATO)?
Not necessarily. In most RMF-based implementations, an authorizing official may grant an ATO while certain weaknesses remain open, provided the residual risk is documented and accepted and the items are tracked to closure through the POA&M. The decision rests with the authorizing official based on the risk determination, so open POA&M items and authorization are not mutually exclusive. That said, agency- or program-specific policy may limit which types or severities of open items are acceptable, and readers should confirm the applicable authorization requirements against current guidance.
What information does a POA&M entry typically capture for each weakness?
Implementations vary, but a POA&M entry generally identifies the specific weakness or deficiency, the associated security control or requirement, the responsible party or point of contact, the resources required, planned milestones with target completion dates, and the current status. Some formats also record the source of the finding and the risk level. Because required fields differ by agency, program, and applicable template, verify the exact format expected against the current authoritative source or contractual requirement.
How often should a POA&M be reviewed and updated?
A POA&M is generally treated as a living document reviewed and updated on a recurring basis as part of continuous monitoring, and updated whenever milestones are completed, dates change, or new weaknesses are identified. The specific cadence is set by agency or program policy rather than a single universal interval, so confirm the required review frequency against the applicable guidance and authorization conditions.
Who is responsible for maintaining and tracking the POA&M?
Responsibility generally falls to the system owner or information system security personnel, with oversight roles such as the authorizing official and, in DoD RMF contexts, roles supporting the security authorization process. Individual entries typically name a responsible party or point of contact for each corrective action. Because role titles and delegation differ across federal civilian, DoD, and contractor environments, confirm the accountable roles against your organization's governance structure and applicable policy.
What happens when a POA&M milestone completion date is missed?
A missed milestone generally requires the POA&M to be updated to reflect a revised target date and a documented rationale, and it may prompt reassessment of the associated residual risk. Persistent or unexplained slippage can affect the authorizing official's ongoing risk acceptance and continuous monitoring posture. The specific handling of overdue items, including any escalation or reauthorization implications, depends on agency or program policy that should be verified against current authoritative sources.

Common misconceptions

A POA&M is simply paperwork that satisfies an auditor and can be filed and forgotten once submitted.
A POA&M is intended to be a living management tool tracked through continuous monitoring. Open items generally require active remediation, periodic status updates, and follow-through against milestone dates rather than a one-time submission.
Having open POA&M items means a system cannot receive or retain an authorization.
In many implementations an authorizing official may accept residual risk and grant an Authority to Operate (ATO) with an active POA&M, provided the risk is acceptable and remediation is planned. Note that an ATO is time-bound and subject to continuous monitoring, and specific tolerance for open items varies by agency, framework, and applicable revision, readers should verify against the current authoritative guidance.
Documenting a weakness in a POA&M is equivalent to fixing it.
A POA&M records and schedules corrective action; it does not by itself remediate the underlying weakness. Compliance documentation is not the same as security, and the deficiency remains an open risk until the corrective actions are actually completed and verified.

Best practices

Assign a clear point of contact and responsible owner to each POA&M item so accountability for remediation is unambiguous.
Set realistic, milestone-based completion dates and track interim progress rather than relying on a single distant deadline.
Prioritize remediation based on the risk and impact of each weakness rather than treating all items as equally urgent.
Update POA&M status regularly as part of continuous monitoring, and close items only after corrective actions are verified as effective.
Map each weakness precisely to the applicable control or requirement and confirm the mapping against the current revision of the governing publication.
Confirm the specific POA&M format, content, and submission expectations against the current authoritative guidance and any agency- or contract-specific requirements, since these can vary across frameworks and revisions.