POA&M in CMMC: What You Can Defer and What You Cannot
Quick answer: you can only defer requirements worth 1 point, plus exactly one exception. 32 CFR 170.21 is far narrower than most people assume, and the exception has a deadline attached that a Mac fleet can miss through no fault of its own.
What is a POA&M worth under CMMC?
Less than it used to be. A plan of action buys you a Conditional CMMC Status, not a pass. 32 CFR 170.21(a)(1) removes it entirely at Level 1: "a POA&M is not permitted at any time for Level 1 self-assessments."
At Level 2, three conditions must all be satisfied before any POA&M is permitted. Miss one and there is no Conditional status to have.
The first is arithmetic. Your assessment score divided by the total number of Level 2 security requirements must be greater than or equal to 0.8. With 110 requirements that means a score of 88 or better before anything goes on the plan.
Which requirements can you defer?
Only the cheap ones. 32 CFR 170.21(a)(2)(ii) bars any requirement with "a point value of greater than 1 as specified in the CMMC Scoring Methodology."
That is a harder bar than the version repeated in most summaries. People say five-point requirements cannot be deferred. The rule says anything above one point cannot be deferred, which sweeps in every three-point requirement as well.
So the deferrable set is the one-point requirements, and one carve-out.
Which requirements can you never defer?
Six are named outright in 32 CFR 170.21(a)(2)(iii), regardless of point value:
- AC.L2-3.1.20 External Connections
- AC.L2-3.1.22 Control Public Information
- CA.L2-3.12.4 System Security Plan
- PE.L2-3.10.3 Escort Visitors
- PE.L2-3.10.4 Physical Access Logs
- PE.L2-3.10.5 Manage Physical Access
Note the third one. The System Security Plan can never be placed on a POA&M. There is no version of a CMMC Level 2 assessment where an incomplete SSP is something you promise to finish later. It is the one artifact that has to be right on the day.
Everything above one point is also barred. Multifactor authentication at IA.L2-3.5.3 is a common misunderstanding here. It carries partial credit, so people assume it is deferrable. It is not named in 170.21 and it scores above one point either way, so it cannot go on the plan.
Partial credit and POA&M eligibility are different mechanisms. Confusing them is expensive.
Why is SC.L2-3.13.11 the only exception?
Because encryption validation depends on somebody else's timeline, and the rule acknowledges it. 32 CFR 170.21(a)(2)(ii) carves out CUI encryption "if encryption is employed but it is not FIPS-validated, which would result in a point value of 3."
Read the condition precisely. The exception attaches to a posture, not to the requirement. Encryption employed but unvalidated is the three-point case and it is deferrable. Encryption not employed at all is the five-point case, and the carve-out does not reach it.
The scoring behind that sits at 32 CFR 170.24. Three points are subtracted where encryption is employed but not FIPS-validated, five where it is not employed. The same section gives multifactor authentication the same treatment: three points where it covers only remote and privileged users, five where it covers nobody.
One thing partial credit does not do is change the finding. Under 170.24, MET requires that all applicable objectives are satisfied. A three-point score is still NOT MET.
What happens if you miss the 180 days?
The status expires. 32 CFR 170.21(b) requires that closing a POA&M "must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date." For a Level 2 certification that closeout has to be performed by an authorized or accredited C3PAO.
Here is where Mac fleets should pay attention. The encryption exception lets you defer a FIPS validation gap. It does not let you wait one out. If your platform's cryptographic module is sitting in a validation queue, the only way to close that POA&M is for the module to become validated or for you to move to one that already is.
That is a real risk on a newly released operating system, and it is worth checking before you standardise on one. We cover the current Apple certificate position in FIPS-validated encryption for CUI, and the scoping side in Mac asset classification for CMMC.
Sources
- 32 CFR 170.21(a)(1), (a)(2)(i), (a)(2)(ii), (a)(2)(iii), (b)
- 32 CFR 170.24(b) assessment findings and (c)(2) scoring
- 32 CFR 170.17(a)(1)(ii)(B)
Verified against primary sources on August 1, 2026. Point values and eligibility should be confirmed against the current rule text before you rely on them. This is not legal advice.
Member discussion