By The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 29, 2026 · Next scheduled review: November 2026
Primary sources read for this update: 32 CFR Part 170, including §§170.4, 170.8, 170.9, 170.16, 170.17, 170.18, 170.21, 170.22, and 170.24; DFARS Subpart 204.75 and clauses 252.204-7012, -7019, -7020, and -7021; the Department's July 2026 Implementing Suspension of CMMC Phase II memorandum; CMMC Assessment Process v2.0; NIST SP 800-171 Revision 2 and NIST SP 800-172 (February 2021); the June 18, 2026 Department of Justice LOGZONE release; and the official DoW CMMC FAQ and program pages.
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or Registered Provider Organization (RPO), and with a qualified federal-contracts attorney where contractual interpretation is material.
The CMMC POA&M 180-day rule works like this: if your CMMC Level 2 assessment scores at least 88 of 110 and every unmet requirement is one the rule actually lets you defer, you receive a Conditional CMMC Status. From that Status Date, you have 180 days to fix those items, complete the applicable closeout assessment, and get the closeout result posted to SPRS or CMMC eMASS. Miss it and the Conditional status expires (32 CFR §170.21).
That is the part everybody publishes. Here is the part almost nobody does.
Only 46 of the 110 Level 2 requirements are in the one-point pool that can go on a POA&M. Sixty-three never can. One more — CUI encryption — can, but only in one narrow implementation state. We counted them ourselves, requirement by requirement, by reading the POA&M rule at §170.21 against the point values at §170.24. Three entire security-requirement families contain zero deferrable requirements. A company can score 105 out of 110 and still be barred from a Conditional status, while a company sitting at exactly 88 can receive one.
So the real question is not how many days do I have. It is were my gaps ever deferrable in the first place — and if you already hold a Conditional status, which day is Day 1.
Both answers are below, along with the shorter re-evaluation cutoff that can close before the 180-day clock even starts. Most contractors never hear about that one until it is already gone.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source support for material regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
The fast answers
| Your question | The direct answer |
|---|---|
| How long is the window? | 180 calendar days from the Conditional CMMC Status Date (§170.21(b)) |
| When does it start? | On the date the status results are submitted to SPRS or CMMC eMASS (§170.4) |
| What score do I need first? | A weighted score of at least 88 of 110 — a ratio of 0.8 (§170.21(a)(2)(i)) |
| Is 88 enough by itself? | No. Every open item must also be individually eligible |
| How many Level 2 requirements are in the eligible pool? | 46 one-point requirements, plus one conditional encryption case. 63 never are |
| How many points can I defer at once? | At most 22 points and only if every item is eligible |
| Can Level 1 use a POA&M? | No — not at any time (§170.21(a)(1)) |
| Who runs the closeout? | The OSA (Level 2 Self), an authorized or accredited C3PAO (Level 2 C3PAO), or DCMA DIBCAC (Level 3) |
| Is there a separate pre-POA&M re-evaluation window? | Yes, on the certification path: no later than 10 business days after the active assessment period and only before the Findings Report is delivered (§170.17(c)(2)) |
| Can I get an extension? | The rule provides no extension or tolling mechanism. Do not plan around one |
| Did the July 2026 Phase II suspension stop my clock? | No published amendment or suspension memorandum tolls §170.21 |
| Does reaching Final reset my three years? | No. Final keeps the original Conditional Status Date (§170.4) |
A note on vocabulary, because these get blurred constantly. A POA&M (Plan of Action and Milestones) is the post-assessment list of requirements scored NOT MET. CUI is Controlled Unclassified Information; FCI is Federal Contract Information. SPRS is the Supplier Performance Risk System, where self-assessment results, CMMC status data, and affirmations are recorded. CMMC eMASS is the government-owned system where third-party and government assessment results are recorded before transmission to SPRS. A C3PAO is a CMMC Third-Party Assessment Organization — §170.4 says CMMC, not "Certified." DCMA DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. An OSA is an Organization Seeking Assessment; an OSC is an Organization Seeking Certification. An RPO is a Cyber AB program role expanded as Registered Provider Organization; it is not a term defined in §170.4.
Where the CMMC program actually stands right now
Answer capsule: As of August 29, 2026, the CMMC program remains in Phase I. The original schedule placed Phase I from November 10, 2025 through November 9, 2026 and Phase II beginning November 10, 2026. On July 13, 2026, the Department announced an immediate suspension of the transition to Phase II. No replacement Phase II date has been published. During the suspension, requiring activities may designate only Level 1 (Self) or Level 2 (Self). The POA&M provisions in 32 CFR Part 170 were not changed.
This matters for how you read the rest of this page, so we are stating it up front rather than burying it.
Two things are true at the same time, and most content published before mid-July 2026 only shows you one of them:
| Question | What the codified rule says | Current procurement posture, verified Aug. 29, 2026 |
|---|---|---|
| Does Level 2 (Self) exist? | Yes | Yes — an active Phase I designation |
| Does Level 2 (C3PAO) exist? | Yes, fully codified | New required designations are suspended during the review |
| Does Level 3 (DIBCAC) exist? | Yes, fully codified | New required designations are suspended during the review |
| Does the 180-day rule still exist? | Yes | Yes; no published amendment or memo tolls it |
| Did the suspension automatically erase higher-level clauses already in a solicitation or contract? | No | No. The implementation memo directs formal amendments or modifications |
The July 2026 implementation memorandum goes further than saying "no new designations." It directs contracting activities to amend active solicitations containing Level 2 (C3PAO) or Level 3 requirements. For existing contracts containing those requirements, it directs modification before the next option exercise or the next scheduled administrative modification. Do not assume a clause disappeared merely because the policy changed; look for the actual amendment or contract modification.
There is a practical consequence people are missing. Level 1 permits no POA&M at any time. During the suspension, the only POA&M path a newly designated solicitation can require is Level 2 (Self) — the path most published guidance treats as a footnote. We have written this page accordingly, while keeping the C3PAO and Level 3 paths intact because they remain in the regulation and contractors may already hold statuses under them.
The Department established a CMMC reform review when it announced the suspension. As of the verification date above, the official CMMC page still says Phase II is suspended and Phase I self-assessment requirements remain in place. We will update this page when the Department publishes a replacement schedule or changes the codified POA&M rules. For the full phase timeline, see CMMC deadlines and implementation status.
What is the CMMC POA&M 180-day rule?
Answer capsule: The CMMC POA&M 180-day rule is the closeout deadline at 32 CFR §170.21(b). A POA&M closeout assessment must confirm that every deferred requirement is now MET within 180 days of the Conditional CMMC Status Date. If it does not, the Conditional CMMC Status for that information system expires. The provision took effect December 16, 2024 and has not been amended as of August 29, 2026.
Conditional status is a bridge, not a grace period. That distinction costs people real money, so let's be precise about what it is.
You went through an assessment. You did not pass cleanly. But you scored high enough, and the specific requirements you missed were narrow enough, that the rule lets you carry them on a documented plan while you finish the work. Your status is real. Under the codified DFARS rules, it can support award at Levels 2 and 3 when the solicitation accepts that level, the status is current, and the required affirmation is on file. It shows up in SPRS. And it dies on a specific calendar date unless you close it out.
What Conditional status is not:
- It is not a decision you make. You cannot elect a POA&M after failing an ineligible requirement. Conditional status exists only when the score and item-by-item eligibility rules are satisfied.
- It does not make a NOT MET requirement count as MET. Under §170.24, a requirement on a POA&M is still assessed NOT MET until closeout verifies otherwise.
- It does not cover anything you want it to. That is the whole subject of the eligibility section below.
- It is not available at Level 1 under any circumstances (§170.21(a)(1)).
- It is not permission to let the rest of your assessed environment deteriorate. A current Conditional status requires no changes in compliance since the Status Date and a corresponding affirmation.
One more thing worth saying plainly, because it appears in supplier questionnaires: if you hold a self-assessed Conditional status and tell a prime you are "CMMC certified," you have misstated your position. CMMC does not issue a certificate for a self-assessment. It records a CMMC status in SPRS.
When exactly does the 180-day clock start?
Answer capsule: The clock starts on the Conditional CMMC Status Date, which 32 CFR §170.4 defines as the date the CMMC Status results are submitted to SPRS or the CMMC instantiation of eMASS. It does not start when the assessment week ends, when the outbrief happens, when remediation begins, or when a contract is awarded. Time between assessment fieldwork and result submission sits outside the 180-day count; the recorded Status Date is the trigger.
Here is the definitive version, straight from the definitions section.
| The date you might be counting from | Does it start the clock? | Why |
|---|---|---|
| Last day of the assessment | No | The rule ties the clock to results submission, not fieldwork |
| Your outbrief or debrief | No | An event, not the defined submission date |
| The day your consultant started remediation | No | An internal project date |
| Your C3PAO's invoice or engagement date | No | A commercial date |
| Contract award date | No | A contract event |
| Results submitted to SPRS (Level 2 Self) | Yes | This creates the Conditional CMMC Status Date |
| Results submitted to CMMC eMASS (C3PAO or DIBCAC) | Yes | This creates the Conditional CMMC Status Date |
| The day you reach Final status | No — and it does not reset anything | §170.4 says no new date is set for a Final that follows a Conditional |
Where to find your actual date
For a Level 2 self-assessment, use the CMMC Status Date in your SPRS record. §170.16(a)(1)(i) requires the record to include the CMMC Level, assessment scope, CAGE code or codes, CMMC unique identifier, overall score, POA&M usage and compliance, and the Status Date.
For a certification assessment, §170.17(a)(1)(i) requires the eMASS record to carry the Status Date plus the C3PAO name, assessment identifier, assessor information, SSP name/date/version, results by objective, and hashed artifact data.
If you cannot find the date, ask your C3PAO for the CMMC Status Date in writing or pull your own SPRS record. Do not estimate. Do not use the assessment week. And do not send screenshots containing contract details or system information to anyone who does not need them.
Put the real date on paper before you plan around it
The free CMMC Readiness Checklist is a 32-point printable Level 2 checklist delivered by email. It covers scope, SSP, SPRS, evidence, and provider decisions. Add your recorded Conditional CMMC Status Date, calculate Day 180, and set an internal Day-120 gate. It is not a government form and it does not pull data from SPRS or eMASS.
Get the CMMC Readiness Checklist →
Do not enter CUI, drawings, export-controlled content, network diagrams, evidence files, or sensitive contract details into any worksheet you share externally.
The shorter clock almost nobody mentions: 10 business days
Answer capsule: Under 32 CFR §170.17(c)(2), a requirement scored NOT MET during a Level 2 certification assessment may be re-evaluated during the assessment and for up to 10 business days after the active assessment period ends — but only while the CMMC Assessment Findings Report has not been delivered. The window closes at the earlier of those two events: report delivery or the end of the 10th business day. Additional evidence must be available, and the change cannot undercut requirements already scored MET.
If your assessment finished within the last 10 business days, read this section before anything else on the page.
Here is why it matters so much. The 180-day rule only helps with requirements you are allowed to defer. Forty-two Level 2 requirements are fixed five-pointers, and MFA and CUI encryption can also score five points when they are not implemented at all. A five-point NOT MET item cannot ride a POA&M. Before the assessment result is finalized, this re-evaluation window may be the only rule-defined opportunity to present additional evidence for an item that would otherwise block Conditional status.
The three conditions in §170.17(c)(2) are cumulative. All three must hold:
- Additional evidence is available to demonstrate the requirement has been MET.
- The change cannot alter or limit the effectiveness of other requirements already scored MET.
- The CMMC Assessment Findings Report has not been delivered.
Condition three is a cutoff, not an extension. If the Findings Report arrives on business day four, the window closes on business day four. If the report has not arrived by business day ten, the regulatory outer limit still closes the window. Do not build a plan around whichever date would be more convenient.
Three questions to put to your C3PAO in writing before assessment week:
- When does the active assessment period formally end for our engagement?
- When do you intend to deliver the CMMC Assessment Findings Report?
- If we produce additional evidence before the earlier cutoff, what is your process for re-evaluating a NOT MET requirement?
One asymmetry we want to flag honestly. We read §170.16 — the Level 2 self-assessment section — in full. It contains no equivalent 10-business-day re-evaluation provision. That is an editorial conclusion from the absence of a provision, not language the rule states. A self-assessor controls when results are submitted, so the practical lesson is simpler: do not post a score built on draft evidence or an environment you have not actually assessed. But do not claim a CMMC status before posting either. The date you submit valid results is the date the clock starts.
Does the July 2026 suspension pause my 180-day clock?
Answer capsule: No published source does. The Phase II suspension announced July 13, 2026 changed which CMMC levels a requiring activity may designate and directed amendments or modifications for affected solicitations and contracts. It did not amend 32 CFR Part 170, and the memorandum does not say that an existing Conditional CMMC Status Date is tolled. If you hold a Conditional status, treat the §170.21 deadline as running unless the government gives you written, situation-specific direction that says otherwise.
We checked this directly rather than inferring it from headlines, because a lot of money rides on it.
What we verified. On August 29, 2026, §170.21 still required successful POA&M closeout within 180 days of the Conditional CMMC Status Date. Its score gate, item restrictions, and expiration language remained in force. Neither the official CMMC program page nor the suspension implementation memorandum published a tolling rule for existing Conditional statuses.
What the suspension actually did. It suspended the transition to Phase II, originally scheduled for November 10, 2026. During the review, requiring activities may designate Level 1 (Self) or Level 2 (Self), but not new Level 2 (C3PAO) or Level 3 requirements. The implementation memorandum also directs amendments to active solicitations and modifications to affected existing contracts before the next option exercise or scheduled administrative modification.
What did not move automatically. DFARS 252.204-7012 still requires adequate security and applicable NIST SP 800-171 implementation independent of whether a solicitation currently designates a C3PAO assessment. SPRS posting and affirmation rules remain in the codified CMMC framework for statuses that apply. And under DFARS 204.7501, a Conditional status is current only while it is not older than 180 days, there have been no changes in compliance since the Conditional Status Date, and the corresponding affirmation is current.
Our editorial conclusion, labeled as such: do not treat the Phase II suspension as free remediation time on an existing Conditional status. The rule has no published pause button. Track the original Status Date, obtain any contract amendment in writing, and close the POA&M on the assumption that Day 180 still means Day 180.
How do you qualify for a Conditional CMMC Status?
Answer capsule: You must satisfy two gates at the same time: score at least 88 of 110, and leave open only requirements the POA&M rule permits. Passing the arithmetic gate does not cure an ineligible gap. Level 1 cannot use a POA&M at all.
The rule is often summarized as "you can pass with an 88." That is wrong in the way that matters most.
Gate 1: the score must be at least 88
§170.21(a)(2)(i) requires a ratio of at least 0.8. At Level 2, the maximum score is 110, so the minimum is 88. That means the largest theoretical point deficit is 22.
But the word theoretical is doing work there. You cannot choose any combination totaling 22. Each open requirement must independently qualify under the next gate.
Gate 2: every unmet requirement must be POA&M-eligible
The default rule is blunt: §170.21(a)(2)(ii) permits only requirements assigned one point under §170.24. Then it names six one-point requirements that are excluded anyway. It separately creates one narrow path for CUI encryption.
| Gap at the end of the assessment | POA&M-eligible? | Why |
|---|---|---|
| Ordinary one-point requirement not on the exclusion list | Potentially yes | Default eligible class under §170.21(a)(2)(ii) |
| Fixed three-point requirement | No | Not assigned one point |
| Fixed five-point requirement | No | Not assigned one point |
| One of the six named excluded one-point requirements | No | Explicitly barred by §170.21(a)(2)(ii) |
| MFA not implemented | No | Scores five points under §170.24 |
| MFA implemented only for some users/systems | No | Scores three points under §170.24 |
| CUI encryption not implemented | No | Scores five points under §170.24 |
| CUI encryption implemented but not FIPS-validated | Potentially yes | One-point treatment, but only if an enforceable federal contract requirement does not prohibit it |
| Current SSP missing | No numeric score can be completed | §170.24(c)(2) says no score is assigned |
The practical result is 46 ordinary eligible requirements, 63 that never qualify, and one conditional encryption case. That count is not a number printed by the Department. It is our requirement-by-requirement reconstruction of the controlling rule. The full list is next.
The six one-point requirements that still cannot go on a POA&M
These are easy to miss because they look eligible in the scoring table. The POA&M section takes them back out:
- AC.L2-3.1.20 — Verify and control/limit connections to and use of external systems.
- AC.L2-3.1.22 — Control CUI posted or processed on publicly accessible systems.
- CA.L2-3.12.4 — Develop, document, and periodically update system security plans.
- PE.L2-3.10.3 — Escort visitors and monitor visitor activity.
- PE.L2-3.10.4 — Maintain audit logs of physical access.
- PE.L2-3.10.5 — Control and manage physical access devices.
The current SSP rule deserves its own warning. If the assessment does not have a current system security plan covering the assessed scope, §170.24(c)(2) says the assessment cannot be completed and no score is assigned. The SSP is not merely another five-point gap.
Which Level 2 requirements can go on a POA&M?
Answer capsule: Forty-six ordinary Level 2 requirements are in the one-point eligible pool. CUI encryption at SC.L2-3.13.11 is a 47th conditional case only when encryption is implemented but not FIPS-validated and no enforceable federal contract requirement prohibits that treatment. The remaining 63 requirements cannot be deferred.
We built the list below by taking every Level 2 requirement assigned one point in §170.24, then removing the six express exclusions in §170.21. We verified the identifiers against NIST SP 800-171 Revision 2, the CMMC-controlling Level 2 baseline as of August 29, 2026.
The 46 ordinary POA&M-eligible Level 2 requirements
| Family | Eligible requirement IDs | Count |
|---|---|---|
| Access Control (AC) | 3.1.3, 3.1.4, 3.1.6, 3.1.7, 3.1.8, 3.1.9, 3.1.10, 3.1.11, 3.1.14, 3.1.15, 3.1.21 | 11 |
| Awareness and Training (AT) | 3.2.3 | 1 |
| Audit and Accountability (AU) | 3.3.3, 3.3.4, 3.3.6, 3.3.7, 3.3.8, 3.3.9 | 6 |
| Configuration Management (CM) | 3.4.3, 3.4.4, 3.4.9 | 3 |
| Identification and Authentication (IA) | 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.11 | 7 |
| Incident Response (IR) | 3.6.3 | 1 |
| Maintenance (MA) | 3.7.3, 3.7.6 | 2 |
| Media Protection (MP) | 3.8.4, 3.8.5, 3.8.6, 3.8.9 | 4 |
| Physical Protection (PE) | 3.10.6 | 1 |
| Risk Assessment (RA) | 3.11.3 | 1 |
| System and Communications Protection (SC) | 3.13.3, 3.13.4, 3.13.7, 3.13.9, 3.13.10, 3.13.12, 3.13.13, 3.13.14, 3.13.16 | 9 |
| Total | 46 |
The three security families with zero eligible requirements
This is one of the most useful planning facts in the rule, and we have not found it assembled this way in the regulatory text:
| Family | Requirements in the family | POA&M-eligible | What that means |
|---|---|---|---|
| Personnel Security (PS) | 2 | 0 | Either PS gap blocks Conditional status |
| Security Assessment (CA) | 4 | 0 | All CA requirements are fixed higher-point items or expressly excluded |
| System and Information Integrity (SI) | 7 | 0 | Any SI gap blocks Conditional status |
Physical Protection is nearly as unforgiving: only PE.L2-3.10.6 is eligible. The visitor-escort, physical-access-log, and access-device requirements are one-point items but specifically excluded. The other PE requirements carry higher point values.
The one conditional case: CUI encryption
SC.L2-3.13.11 is not a normal yes/no POA&M item. §170.24 gives it three scoring states:
| Implementation state | Score impact | Can it support Conditional status? |
|---|---|---|
| Encryption not implemented | -5 | No |
| Encryption implemented, but not using FIPS-validated cryptography | -1 | Potentially yes, subject to the contract condition below |
| Encryption implemented using FIPS-validated cryptography | 0 | MET |
§170.21(a)(2)(iii) permits the one-point state only when the use of non-FIPS-validated cryptography is not prohibited by an enforceable Federal Government contract provision. That is a contract-specific legal and technical question, not a loophole to assume.
The 63 requirements that can never be deferred
The blocked population consists of:
- 42 fixed five-point requirements under §170.24;
- 14 fixed three-point requirements;
- six expressly excluded one-point requirements listed above; and
- one adjustable requirement — MFA at IA.L2-3.5.3 — whose deficient implementation scores three or five points, never one.
That totals 63. CUI encryption is kept separate because one implementation state can score one point.
This is why "we only missed a few controls" tells you almost nothing. A single blocked requirement is enough to make Conditional status unavailable. Conversely, several one-point gaps can be eligible if the weighted score remains at least 88 and all other conditions hold.
Before you pay for an assessment, classify every known gap
A useful internal register needs more than a list of incomplete controls. For each known gap, record:
- requirement ID;
- current MET / NOT MET evidence position;
- §170.24 point value;
- whether §170.21 expressly excludes it;
- whether the gap is technical, documentary, scoping, or evidence-related;
- owner and planned completion date;
- whether remediation changes the assessment scope or undermines another MET requirement; and
- the source used for the classification.
That is the point where a generic gap assessment stops being enough. You need somebody who understands both the requirement and the assessment consequence.
Not sure whether your open items are ordinary one-pointers or assessment blockers?
Use Find My CMMC Path → to identify the provider category that fits your level, scope, timeline, and current blocker. It is an editorial routing tool, not a certification decision. Do not submit CUI or sensitive evidence.
Why this distinction mattered in a June 2026 False Claims Act settlement
Answer capsule: The Department of Justice announced a $507,144 settlement with LOGZONE on June 18, 2026 over allegations that included an SPRS Basic Assessment score of -170 and failure to implement certain NIST SP 800-171 controls. The matter was not a CMMC assessment, and the company denied liability. Its relevance here is narrower: the difference between an ordinary open item and a foundational security failure can become a contract-representation and enforcement issue, not just an assessment-planning issue.
We are keeping the boundaries tight because this case is easy to overstate.
According to the Department of Justice release, the settlement resolved allegations; it was not a finding after trial, and LOGZONE did not admit liability. DOJ alleged that the contractor submitted a -170 Basic Assessment score in SPRS and failed to implement certain controls required by NIST SP 800-171 and its contracts.
The settlement amount was $507,144. An earlier draft of this page described part of that amount as restitution. The DOJ source does not support that characterization, so it has been removed.
What the case does — and does not — prove
It does not prove that a contractor with a Conditional CMMC status committed fraud. It does not interpret §170.21. It does not tell a C3PAO how to score your evidence. And it does not convert every missed deadline into False Claims Act liability.
It does show why the language around scores and status has to be exact. DFARS 252.204-7019 and 252.204-7020 connect NIST SP 800-171 assessment information in SPRS to contract eligibility and government access. 252.204-7012 separately requires adequate security and applicable NIST SP 800-171 implementation for covered contractor information systems.
Our cross-rule comparison, clearly labeled as editorial analysis: the DOJ release described alleged missing capabilities in areas that the CMMC Level 2 scoring model treats as high-value requirements. That does not mean LOGZONE underwent CMMC, violated §170.21, or had a CMMC POA&M. It means the government can treat an inaccurate cybersecurity representation as more than a readiness problem.
The practical rule is simple: never translate "we have a remediation plan" into "we meet the requirement," never translate a self-assessed status into a certification, and never leave a stale or inaccurate score in SPRS because the contract team assumes cybersecurity records are only technical paperwork.
Do I want a Conditional CMMC Level 2 Status?
Answer capsule: Conditional status is useful when the remaining gaps are narrow, eligible, owned, and realistically closeable inside 180 days. It is a bad strategy when the open items reveal architecture, scope, identity, logging, incident-response, personnel-security, or SSP problems that should have been solved before assessment.
There is nothing inherently irresponsible about a POA&M. The rule created one because perfect timing is not always possible. The mistake is treating Conditional status as the plan instead of a controlled exception.
Conditional status can make sense when
- the assessment boundary is stable;
- the SSP is current enough for the assessment to be completed;
- the weighted score is comfortably above 88;
- every open requirement has been classified against §170.21;
- the fixes do not require rebuilding the enclave;
- owners and funding are committed before the Status Date;
- evidence can mature before the scheduled closeout; and
- a missed deadline will not strand an option, award, or subcontract.
Conditional status is the wrong target when
- "we will figure out scope after the assessment";
- "our consultant says they can put anything on a POA&M";
- "we are at 88, so we pass";
- "the assessor can tell us what to build";
- "the suspension probably pauses our deadline";
- "we can always extend the POA&M"; or
- "we will schedule the closeout in month six."
The damaging admission is that some contractors reach Conditional status because their readiness process did not distinguish a one-point miss from an assessment blocker. They got lucky enough to receive a status, then discovered they had built no operating plan to close it.
Conditional status is best understood as borrowed schedule with a fixed maturity date. The question is not whether 180 days sounds generous. The question is whether your remediation, evidence, quality review, assessor scheduling, and posting all fit inside it with margin.
A decision test before you accept the risk
Answer these five questions without optimism:
- Could every open item be completed and evidenced by Day 120 if one key person left?
- Is the closeout authority identified, available, and conflict-free?
- Would the plan still work if a procurement or cloud dependency slipped 30 days?
- Does an award, option, or subcontract depend on remaining current through Day 180?
- Would senior leadership sign the required affirmation based on the current facts?
A "no" does not automatically mean stop. It means the risk belongs in an executive decision, not inside a consultant's project plan.
What does a good CMMC POA&M look like?
Answer capsule: A good CMMC POA&M is requirement-specific, evidence-driven, owned, funded, and scheduled backward from closeout. It does not say only "implement control." It explains the deficiency, corrective action, dependencies, milestone dates, evidence that will prove MET, and who will independently verify it before the assessor returns.
The regulation defines a POA&M as a document that identifies tasks needing to be accomplished, assigns resources, and includes milestones and completion dates. That minimum is not enough to run a six-month closeout under pressure.
Use a work package at this level:
| Field | What belongs there | Weak version to reject |
|---|---|---|
| Requirement | Exact CMMC/NIST identifier and assessment objective | "Access control" |
| Deficiency | What was NOT MET in the assessed environment | "Policy issue" |
| Corrective action | Technical, procedural, and documentary work needed | "Fix settings" |
| Owner | One accountable person, not a department | "IT" |
| Dependencies | Procurement, identity, licensing, architecture, policy, training | Blank |
| Milestones | Dated intermediate outputs, not one final date | "Complete by Day 180" |
| Evidence plan | Artifacts, interviews, demonstrations, samples, and retention | "Screenshot" |
| Independent review | Who will challenge the evidence before closeout | Same implementer signs off alone |
| Closeout authority | OSA, named C3PAO, or DIBCAC path | "Assessor TBD" |
| Contract consequence | Award, option, flowdown, or representation affected | "None" without contract review |
Build to the assessment objective, not the control title
A policy can exist while the practice is absent. A tool can be deployed while the configuration is wrong. A screenshot can show one user while the requirement applies to hundreds. A ticket can prove work was requested, not completed.
For each open requirement, map evidence to the applicable assessment objectives and methods. Ask what the assessor must examine, interview, or test to conclude MET. Then generate evidence during ordinary operation rather than staging it on the day of closeout.
Keep the POA&M out of places it does not belong
Do not use a CMMC POA&M to conceal a scope dispute, substitute for a current SSP, or carry a requirement that §170.21 bars. Do not write sensitive CUI into a commercial project-management system merely because the remediation team uses it. Record enough to control the work without exposing contract data, network details, credentials, or evidence to people who do not need access.
The internal quality question
Before scheduling closeout, hand the evidence package to someone who did not implement the fix and ask:
Could an authorized assessor determine MET from this package without relying on our intent, oral explanation, or knowledge of what the team meant to configure?
If the answer is no, the work is not finished.
The full 180-day operating plan
Answer capsule: Treat Day 120 as the internal finish line, Day 150 as the closeout target, and Day 180 as the legal cliff. Remediation alone is not closeout. You still need final evidence, internal quality review, assessor availability, the applicable closeout assessment, result submission, and the required affirmation workflow.
Here is the operating cadence we would use for a contractor whose award or option depends on the status.
| Window | What must be true by the end of it | Failure signal |
|---|---|---|
| Day 0–15 | Status Date and Day 180 confirmed; every open item mapped to owner, requirement, score, evidence, dependency, and closeout path; budget released | Nobody owns the date or the POA&M still uses vague milestones |
| Day 15–45 | Design decisions complete; procurement started; policy and technical work underway; C3PAO closeout capacity discussed | Core architecture still undecided or long-lead purchases not ordered |
| Day 45–90 | Technical and procedural remediation substantially implemented; evidence collection running; affected staff trained | Teams are still debating scope or relying on future screenshots |
| Day 90–120 | Every deferred requirement internally tested; evidence package complete enough for an independent quality review | "Implemented" exists without durable evidence |
| Day 120–150 | Corrective work from internal review complete; closeout assessment performed or underway; posting dependencies confirmed | Closeout has not been scheduled |
| Day 150–180 | Closeout result submitted; SPRS/eMASS status checked; affirmation workflow completed; prime/contracting communications handled | Any critical action is still waiting on an outside calendar |
Day 0 is an evidence event, not a project kickoff
The assessment already happened. The open items should not be discoveries. On Day 0, convert every NOT MET requirement into a controlled work package with:
- requirement and assessment objective;
- exact implementation gap;
- system or enclave owner;
- technical dependency;
- policy/procedure dependency;
- planned completion date;
- evidence to be generated;
- independent reviewer;
- closeout assessor or authority; and
- contract or option consequence if late.
If the POA&M says only "implement policy," "configure logging," or "train users," it is not operating at assessment depth.
Day 120 is the internal deadline
Why 120? Not because the regulation says so. It does not. This is our operational recommendation after separating the work into four different failure modes: remediation, evidence, assessment availability, and government-system posting.
A fix that works technically can still fail because:
- the policy was approved after the evidence period;
- the screenshot does not identify the assessed asset;
- the sample is not representative;
- the control is performed manually but no record exists;
- the evidence proves a tool is licensed, not configured;
- the change altered the scope or weakened another requirement; or
- the assessor cannot get to you before Day 180.
Finishing the technical work on Day 175 is not finishing the closeout.
Day 150 is the closeout target
Thirty days of margin is not generous when an independent provider, eMASS/SPRS workflow, affirmation, and contract communications may all be involved. Schedule backward from Day 150 even though the rule gives you 180.
Day 180 is not when you start asking for help
By Day 180, the closeout assessment must have confirmed all POA&M items MET and the results must be submitted through the applicable system. §170.21(b) does not create an extension because a vendor is late, an assessor is booked, a cloud migration slipped, a key employee left, or a contract modification is pending.
Who performs the CMMC POA&M closeout assessment?
Answer capsule: The closeout authority follows the original assessment path. The OSA closes a Level 2 self-assessment POA&M; an authorized or accredited C3PAO closes a Level 2 certification POA&M; DCMA DIBCAC closes a Level 3 POA&M.
| Original path | Who performs closeout | Where the result is recorded |
|---|---|---|
| Level 2 Self | The OSA | SPRS |
| Level 2 C3PAO | An authorized or accredited C3PAO | CMMC eMASS, then transmitted to SPRS |
| Level 3 DIBCAC | DCMA DIBCAC | CMMC eMASS, then transmitted to SPRS |
For a Level 2 self-assessment, the organization is responsible for determining that every POA&M item is MET, posting the result in SPRS, retaining the supporting evidence, and completing the applicable affirmation. That does not turn a self-assessment into a certification.
For the certification path, the C3PAO is making an assessment determination, not validating that a consultant completed its project plan. It needs evidence sufficient to support MET for each open requirement. The current official CMMC FAQ says certification-path POA&M closeout in eMASS can be finalized only once during the 180-day window; if an item remains NOT MET, the Conditional status terminates and a new assessment is required. That is program guidance rather than text in §170.21, so check the current FAQ and engagement process.
For Level 3, DCMA DIBCAC controls the closeout process. A commercial advisor can help prepare the organization, but cannot substitute for the government assessment.
Ask the closeout authority to identify the required evidence package, submission steps, and scheduling lead time in writing. "We'll circle back in month five" is not a closeout plan.
Can I change C3PAOs for the closeout assessment?
Answer capsule: Yes. The current CMMC Assessment Process allows a different authorized or accredited C3PAO to perform the closeout. The replacement C3PAO assumes responsibility for the Final determination and must complete its own documented organizational and individual conflict-of-interest review. Switching can solve an availability problem, but it does not extend Day 180.
The ability to switch is valuable when the original provider has no capacity, the relationship has broken down, or the contractor needs competitive pricing. It is not a frictionless transfer.
A replacement C3PAO will need enough information to stand behind its own conclusion, including the assessment record, open requirement list, scope, SSP context, remediation evidence, and any dependencies affecting requirements previously scored MET. It may charge for onboarding or validation work the original provider would not repeat.
Can the firm that remediated you also assess you?
Do not reduce the answer to "never" or "always."
32 CFR §170.9 bars a C3PAO from assessing an OSC if the C3PAO, the C3PAO's owners, or an external party under common control provided consulting services to that OSC within the previous three years. §170.8 imposes parallel restrictions on CMMC assessors and instructors, including restrictions tied to consulting and training. The result depends on the legal entities, ownership/control, services, timing, and assigned personnel.
That is narrower and more accurate than saying every firm that ever touched remediation is automatically disqualified. It is serious enough that you should resolve organizational and individual conflicts before signing the assessment engagement or replacement closeout.
What can a C3PAO promise?
Not an outcome. The Cyber AB CMMC Assessment Process prohibits guarantees, warranties, or promises tied to an assessment result. A provider may explain process, availability, scope assumptions, evidence expectations, and price. It cannot sell you a passing score.
What if you disagree with the result?
The current CAP directs the OSC to use the C3PAO's appeals process first. After receiving the C3PAO's written appeal decision, the OSC may appeal to The Cyber AB within 15 business days. The Cyber AB's decision is final under that process. Do not assume an appeal tolls the §170.21 clock.
Five questions before you switch
- Are you currently authorized or accredited for the work, under the exact legal entity in the engagement?
- What assessment records and evidence do you require before accepting the closeout?
- What conflict review will you conduct, and when will you confirm it in writing?
- What closeout date can you commit to before Day 150?
- What happens if onboarding reveals a scope or evidence problem?
Switch because the alternative path is stronger, not because a new provider hints it will score more generously.
What does a CMMC POA&M closeout cost?
Answer capsule: The regulation does not publish a fee schedule. Cost depends on the assessment path, number and complexity of open requirements, scope, evidence quality, assessor travel or remote-work assumptions, and whether the original provider or a new C3PAO performs the closeout. Ask for closeout pricing before the original assessment and separate remediation fees from assessment fees.
Any article that gives you a universal government-set price is making it up. The government did not set one.
What you can price is the work stack:
| Cost component | Who may charge it | What to ask for |
|---|---|---|
| Remediation design and implementation | Internal team, MSP/MSSP, RP/RPO, specialist vendor | Fixed scope, dependencies, exclusions, evidence deliverables |
| Evidence packaging and readiness review | Internal team or independent readiness provider | Requirement-level output, not a generic "assessment prep" label |
| C3PAO closeout assessment | Original or replacement C3PAO | Fixed fee or rate card, scheduling assumptions, travel, rescheduling, eMASS work |
| Legal/contract interpretation | Qualified counsel | Narrow question and written work product where material |
| Government closeout | DCMA DIBCAC at Level 3 | Government process; separate internal support costs may remain |
| Affirmation and SPRS administration | Senior affirming official and internal support | Internal owner, access, evidence retention, and verification process |
§170.22 separately lists affirmation upon Conditional status, upon Final status, following a POA&M closeout assessment, and annually after Final. The regulation does not say whether a successful closeout and the resulting Final status require one or two electronic submission actions; confirm the current SPRS workflow rather than inventing a signature count from the list.
Five quote questions that expose a weak closeout proposal
- Is remediation included, excluded, or prohibited because of conflict-of-interest rules?
- Is the quote tied to the number of open requirements, days, or a fixed closeout scope?
- Who owns eMASS or SPRS submission and who verifies it happened?
- What happens if your assessor becomes unavailable inside the window?
- What evidence package must be complete before the closeout date?
Compare the total decision, not just the C3PAO line item. A cheap closeout quote that assumes perfect evidence can become the most expensive option when it forces a late provider switch.
For broader pricing context, see CMMC certification cost and CMMC cost drivers.
What happens if I miss the CMMC 180-day deadline?
Answer capsule: The Conditional status expires. The rule provides no extension, pause, waiver, or partial-credit mechanism for unfinished POA&M items. A contractor that still needs the status must complete a new assessment after fixing the gaps. The contract consequence depends on the requirement in the solicitation or contract and on any amendment or modification issued under the July 2026 suspension guidance.
§170.21(b)(3) is not subtle: if the POA&M closeout assessment is not successfully completed within 180 days of the Conditional CMMC Status Date, the Conditional status expires. For Level 3, §170.21(c)(3) uses the same consequence.
That creates four separate consequences contractors often collapse into one.
1. Your CMMC status consequence
The Conditional status is no longer current. Finishing the remediation on Day 181 does not revive it. The regulation says a new assessment is required to achieve the CMMC Status after expiration.
2. Your award or option consequence
DFARS 204.7503 requires the contracting officer to verify the required current CMMC status and current affirmation in SPRS before award, exercising an option, or extending the period of performance when the requirement applies. If the contract requires a status you no longer hold, the problem is not merely administrative.
The July 2026 suspension adds a contract-specific branch, not a universal pardon. For affected Level 2 (C3PAO) or Level 3 requirements, the implementation memo directs the Government to amend an active solicitation or modify an existing contract before the next option exercise or scheduled administrative modification. Until you receive that document, do not assume the existing requirement has been removed.
3. Your prime-contractor consequence
A prime may have flowed a CMMC requirement into a subcontract or conditioned continued eligibility on a current status. The exact remedy depends on the subcontract language. Notify the correct contract channel before a status lapse becomes a surprise, but do not make unsupported legal admissions. Have counsel review material notices.
4. Your representation consequence
An expired status is not current. Do not continue describing it as current in a bid, questionnaire, portal, or communication to a prime. State the exact Level, assessment type, scope, status, Status Date, and expiration. Update any prior representation that has become inaccurate through the correct contract channel.
What to do when a miss becomes likely
Do not spend the last month pretending the schedule is still green. By Day 120, if a blocker remains:
- get a written requirement-level assessment of the blocker;
- confirm C3PAO or government closeout availability;
- identify any contract award, option, or subcontract date that depends on the status;
- notify counsel and the responsible contracts executive;
- ask the contracting channel what written amendment or modification exists, if the suspension is relevant; and
- plan the new assessment path if the deadline cannot be saved.
The worst outcome is not always the expiration itself. It is an expiration paired with an inaccurate representation that the contractor still holds a current status.
Your status affects an award, option, or subcontract — and the path is no longer obvious
The Defense Compliance Report can route a qualified inquiry to an appropriate provider category. We do not certify companies, decide assessment outcomes, or ask you to upload CUI.
Request a CMMC provider match →
Some listed or matched providers may compensate us. Compensation does not change the regulatory standard, and submitting the form does not guarantee availability, price, certification, or any assessment result.
What reaching Final CMMC Level 2 actually changes
Answer capsule: Final status means every applicable requirement in the assessed Level 2 scope has been scored MET and the POA&M closeout is complete. It does not reset the three-year status period. The original Conditional CMMC Status Date remains the controlling date.
This is the second clock trap in the rule.
§170.4 says successful completion of a POA&M closeout does not result in a new date. The status changes from Conditional to Final; the anchor date does not.
Example:
| Event | Date | What it controls |
|---|---|---|
| Conditional results submitted | January 12, 2026 | Status Date and 180-day anchor |
| Internal Day-120 target | May 12, 2026 | Editorial operating target, not a regulatory date |
| POA&M closeout completed | June 2, 2026 | Changes status to Final if all conditions are met |
| Day 180 | July 11, 2026 | Outside regulatory closeout point |
| Final status expiration | January 11, 2029 | Three years from the original Status Date, not from June 2 |
The exact dates shown in SPRS/eMASS control. The example illustrates the no-reset principle rather than replacing the system record.
One date creates four planning deadlines
A contractor should derive at least four dates from one recorded Status Date:
- Day 180 — the outside closeout deadline.
- Internal remediation deadline — we recommend Day 120.
- Internal closeout target — we recommend Day 150.
- Final-status expiration — three years from the original Status Date.
There is also the annual affirmation cadence under §170.22. Treat that as a recurring governance obligation, not a reason to alter the original status date.
The practical mistake is easy to make: a team closes the POA&M five months after assessment, celebrates a "new" Final certification, and schedules reassessment three years from closeout. That planning date is late by five months.
What Final status does not prove
Final status applies to the assessed CMMC level, assessment type, scope, and information system. It does not certify the whole enterprise if only an enclave was assessed. It does not replace incident-reporting or safeguarding obligations in DFARS 252.204-7012. It does not guarantee that every future solicitation will accept the same assessment type. And it does not survive material noncompliance merely because the three-year date has not arrived.
How does the POA&M rule differ at CMMC Level 3?
Answer capsule: Level 3 uses the same 180-day closeout window but a different score gate and requirement set. A contractor must first hold a Final Level 2 (C3PAO) status for the same assessment scope or a larger scope. The Level 3 assessment then covers 24 selected requirements from NIST SP 800-172 (February 2021), each worth one point. At least 20 must be MET, and seven named requirements can never be deferred.
§170.18 makes Final Level 2 (C3PAO) a prerequisite. The Level 3 scope may be the same as or a subset of that Level 2 scope. DCMA DIBCAC performs the Level 3 assessment and closeout.
| Level 3 question | Rule |
|---|---|
| Maximum Level 3 score | 24 |
| Minimum score for Conditional | 20 |
| Maximum ordinary open items | 4, but only if every item is eligible |
| Closeout deadline | 180 days from the Conditional Level 3 Status Date |
| Closeout authority | DCMA DIBCAC |
| Level 2 prerequisite | Final Level 2 (C3PAO), same or larger scope |
The seven Level 3 requirements that cannot go on a POA&M are listed in §170.21(c)(2)(ii):
- IR.L3-3.6.1e
- IR.L3-3.6.2e
- RA.L3-3.11.1e
- RA.L3-3.11.4e
- RA.L3-3.11.6e
- RA.L3-3.11.7e
- SI.L3-3.14.3e
Every selected Level 3 requirement is worth one point under §170.24, but these seven are expressly removed from POA&M eligibility. That means "four open items" is not a complete rule. One blocked Level 3 item still defeats Conditional status.
Which NIST SP 800-172 version controls CMMC Level 3?
The CMMC rule incorporates the February 2021 publication of NIST SP 800-172 for the selected Level 3 requirements. NIST published SP 800-172 Revision 3 in 2025, but that newer publication does not automatically replace the version incorporated into 32 CFR Part 170. As of August 29, 2026, the Department had not amended the CMMC rule to substitute Revision 3.
The same version-control principle applies at Level 2. NIST SP 800-171 Revision 3 is NIST's current publication, and NIST withdrew Revision 2 from its current-publication catalog. But CMMC Level 2 still uses NIST SP 800-171 Revision 2 because that is the version incorporated into the controlling CMMC rule. Do not redesign your CMMC scoring model around Revision 3 unless and until the Department changes the rule or an enforceable contract separately requires it.
For level selection and assessment-type distinctions, see CMMC Level 1 vs. Level 2 vs. Level 3.
Who do I actually need to hire — and what do I ask?
Answer capsule: Start with the decision blocking you, not with a generic search for "a CMMC company." Readiness interpretation, technical remediation, certification assessment, contract interpretation, and managed operations are different purchases. The wrong category can add cost, delay closeout, and create conflicts.
| Your immediate problem | Provider category to consider | Core output | What that role should not claim |
|---|---|---|---|
| We do not know whether our gaps are eligible | RP/RPO or experienced readiness advisor | Requirement-level eligibility and evidence map | A guaranteed C3PAO result |
| We need to implement controls | MSP/MSSP or specialist implementer | Technical configuration, process implementation, durable evidence | That implementation work is assessment approval |
| We need a Level 2 certification closeout | Authorized/accredited C3PAO | Closeout assessment and Final determination | A predetermined passing score |
| We need contract-language interpretation | Qualified federal-contracts counsel | Written legal/contract analysis | That a commercial opinion binds the Government |
| We need Level 3 closeout | DCMA DIBCAC, with internal/advisory support as needed | Government closeout assessment | That a private provider can substitute for DIBCAC |
| Our current provider created a conflict | Independent C3PAO or advisor outside the restricted relationship | COI-safe assessment or advice | That a different internal team automatically cures common control |
| Our deadline affects an award or option | Contracts lead, counsel, readiness lead, and applicable assessor | Coordinated status and contract action plan | That the suspension automatically rewrites the contract |
For deeper role boundaries, see who to hire first for CMMC and CMMC provider categories.
The three documents to request before you sign
- Statement of work separating readiness, remediation, and assessment activities.
- Conflict-of-interest representation identifying related entities, owners, subcontractors, and assigned assessors.
- Closeout schedule and fee terms showing what happens if Conditional status is issued.
The trust test for any provider
Ask the provider to separate three statements:
- The regulation says — with the section and exact source.
- Our assessment judgment is — based on the evidence seen so far.
- Our remediation recommendation is — based on risk, cost, and timing.
When those blur together, a contractor can spend six figures fixing the wrong thing or enter an assessment believing a discretionary judgment is guaranteed.
Verify the current program role
Use The Cyber AB Marketplace to verify the legal entity, role, and current status. Then confirm who will actually perform the engagement. Marketplace presence is a point-in-time program-status check, not a guarantee of fit, availability, price, or outcome.
Our methodology explains how providers are evaluated and how commercial relationships are handled. Our editorial standards and corrections policy explain how regulatory claims and updates are reviewed.
A better first call
Instead of asking, "Can you get us certified?" ask:
We have [insert CMMC UID], a Conditional Status Date of [insert Status Date], a closeout deadline of [insert closeout deadline], and [number] open requirements. Which services can you provide without creating an assessment conflict, what evidence do you need to price the work, and what outcome do you explicitly not guarantee?
That question forces the provider to show its role, schedule, and boundaries before it sells you certainty it cannot own.
Not sure which category fits the problem?
Use Find My CMMC Path → for the low-friction route, or request a provider match → when a real procurement decision is already active.
Do not submit CUI or sensitive evidence. Some providers may compensate us for introductions or placement. No provider can buy a favorable assessment result or editorial conclusion.
How we verified the 46 / 63 / 1 classification
This section is here so another researcher, contractor, assessor, or AI system can reproduce the conclusion instead of trusting a marketing graphic.
Step 1: identify the controlling Level 2 baseline
32 CFR §170.14 ties CMMC Level 2 to the 110 security requirements in NIST SP 800-171 Revision 2. NIST has since published Revision 3, but Part 170 has not been amended to make Revision 3 the CMMC Level 2 scoring baseline. Verification date: August 29, 2026.
Step 2: reconstruct the scoring classes
We read §170.24(c) and classified all 110 requirements:
- 42 fixed five-point requirements;
- 14 fixed three-point requirements;
- 52 fixed one-point requirements;
- MFA at IA.L2-3.5.3, adjustable between five and three points when NOT MET; and
- CUI encryption at SC.L2-3.13.11, adjustable between five and one point when NOT MET.
Those categories account for all 110 requirements: 42 + 14 + 52 + 1 + 1 = 110.
Step 3: apply the POA&M gate
§170.21(a)(2)(ii) permits one-point requirements but excludes six named one-point requirements. Therefore:
- 52 fixed one-point requirements
- minus six express exclusions
- equals 46 ordinary eligible requirements.
The 63 never-eligible requirements are:
- 42 fixed five-point;
- 14 fixed three-point;
- six excluded one-point; and
- MFA, which has no one-point deficient state.
42 + 14 + 6 + 1 = 63.
CUI encryption remains separate because one deficient state is worth one point and may qualify under the contract condition in §170.21(a)(2)(iii). That produces the 46 / 63 / 1 framework.
Step 4: cross-check family totals and exceptions
We mapped the 46 IDs back to the 14 NIST SP 800-171 families and totaled them. The family counts sum to 46. Personnel Security, Security Assessment, and System and Information Integrity contain no eligible IDs. We separately checked the six named Level 2 exclusions and seven named Level 3 exclusions against §170.21.
Step 5: separate regulation from operating guidance
We used the eCFR and Acquisition.gov for controlling regulatory and contractual text. We used the Cyber AB CAP for assessment-process mechanics such as changing C3PAOs and appeals. We used the Department's CMMC FAQ and program page for current implementation guidance, including the Phase II suspension and the statement that certification-path POA&M closeout in eMASS can be finalized only once during the 180-day window. That one-shot closeout statement is current official guidance; it is not text written into §170.21 itself.
Step 6: apply a date stamp
Every version-sensitive conclusion on this page was rechecked on August 29, 2026. That includes:
- the unchanged text of 32 CFR Part 170;
- Phase I status and Phase II suspension;
- the July 2026 suspension implementation memorandum;
- NIST SP 800-171 Revision 2's continued CMMC-controlling role;
- the February 2021 SP 800-172 reference for Level 3;
- Cyber AB CAP v2.0 process references; and
- current Acquisition.gov text for DFARS 252.204-7012, -7019, -7020, and -7021.
Limits of the reconstruction
This classification tells you which requirements are legally in the potential POA&M pool. It does not decide whether your evidence proves a requirement MET, whether your scope is correct, whether a contract provision makes the encryption exception unavailable, or whether an assessor will accept a particular implementation. Those are case-specific determinations.
We welcome corrections supported by a primary source. Use the corrections policy to report one.
CMMC POA&M 180-day rule FAQ
Can Level 1 use a POA&M?
No. §170.21(a)(1) says POA&Ms are not permitted for CMMC Level 1 self-assessments. All 15 Level 1 requirements must be MET to achieve Level 1 Final status.
Is a score of 88 automatically enough for Conditional Level 2?
No. Eighty-eight is the weighted-score floor. Every unmet requirement must also be eligible under §170.21. A score above 88 can still fail the eligibility gate because one open three-point, five-point, or expressly excluded one-point requirement is enough to block Conditional status.
What is the maximum number of points I can leave open?
Twenty-two, because 110 minus the minimum score of 88 equals 22. That is only a mathematical ceiling. You cannot use those 22 points on ineligible requirements, and 46 ordinary requirements plus one narrow encryption state are the only possible Level 2 POA&M pool.
How many Level 2 requirements can go on a POA&M?
Forty-six ordinary one-point requirements are potentially eligible. SC.L2-3.13.11 can be a 47th conditional case when encryption is implemented but not FIPS-validated and the enforceable contract condition permits it. Sixty-three Level 2 requirements never qualify.
Can a five-point requirement go on a POA&M if my total score is still above 88?
No. The score gate and the item gate are separate. A fixed five-point requirement is ineligible even when the total remains above 88. The same is true of fixed three-point requirements.
Can MFA go on a POA&M?
No deficient MFA state is worth one point. Under §170.24, not implementing MFA is a five-point deduction; partial implementation is a three-point deduction. Either state blocks Conditional status.
Can CUI encryption go on a POA&M?
Only in the narrow one-point state: encryption is implemented, but the cryptography is not FIPS-validated, and an enforceable Federal Government contract provision does not prohibit that treatment. No encryption at all is a five-point gap and cannot be deferred.
Can the system security plan go on a POA&M?
No. CA.L2-3.12.4 is one of the six one-point requirements expressly excluded from POA&M eligibility. More fundamentally, §170.24(c)(2) says that if a current SSP covering the assessed scope is not provided, the assessment cannot be completed and no score is assigned.
Are draft policies or working papers enough to prove MET?
Not merely because they exist. §170.24(c)(3) says draft documents, working papers, and unofficial or unapproved policies do not constitute final evidence. Evidence must support the applicable assessment objectives in the assessed environment.
Does the 180-day clock use calendar days or business days?
Calendar days. The separate re-evaluation provision at §170.17(c)(2) expressly uses business days; §170.21 uses days. Use the exact Status Date shown in SPRS/eMASS and confirm the deadline in the applicable record or with the assessment authority rather than relying on a rough month count.
Does the clock begin when the assessment ends?
No. It begins on the Conditional CMMC Status Date — the date the results are submitted to SPRS or CMMC eMASS. The end of fieldwork, outbrief, Findings Report, remediation kickoff, award date, and invoice date are not the defined trigger.
Does the 10-business-day re-evaluation window always last 10 business days?
No. On the certification path, it ends at the earlier of Findings Report delivery or the end of the 10th business day after the active assessment period. It also requires additional evidence and a change that does not alter or limit the effectiveness of another requirement already scored MET.
Is there an equivalent 10-business-day rule for a Level 2 self-assessment?
We found no equivalent provision in §170.16. That is an editorial conclusion from the section's text, not an affirmative sentence in the rule. The OSA must still assess honestly and submit accurate results; controlling the submission date is not permission to claim an unearned status.
Can the same C3PAO perform the POA&M closeout?
Yes, if it remains authorized or accredited and no conflict or other restriction prevents the work. A different C3PAO may also perform the closeout under the current Cyber AB CAP, but it assumes responsibility for the Final determination and must conduct its own documented conflict-of-interest review.
Can the consultant that remediated us perform our assessment?
Possibly not, depending on the relationship. §§170.8 and 170.9 impose three-year conflict restrictions tied to consulting, training, ownership, common control, and assigned personnel. Resolve both organizational and individual conflicts against the actual legal entities and services; do not rely on a provider's casual "different team" assurance.
Can a C3PAO guarantee we will pass the closeout?
No. The Cyber AB CAP prohibits guarantees, warranties, or promises tied to an assessment result. A credible provider can state its process, assumptions, evidence requirements, availability, and price — not predetermine the assessor's conclusion.
Can I appeal a C3PAO assessment result?
Yes. Under the current CAP, use the C3PAO's appeal process first. After the C3PAO issues a written appeal decision, the OSC may appeal to The Cyber AB within 15 business days. The Cyber AB decision is final under that process. Do not assume an appeal pauses the 180-day deadline.
Can I submit the certification-path closeout more than once during the 180 days?
The current official CMMC FAQ says a certification-path POA&M closeout assessment in eMASS can be finalized only once during the 180-day window. If any POA&M requirement remains NOT MET, the Conditional status terminates and a new assessment is required. That is current program guidance, not wording found in §170.21 itself. Confirm the current FAQ and your C3PAO's process before scheduling.
Does the July 2026 Phase II suspension extend an existing POA&M deadline?
No published amendment or memorandum says it does. The suspension changed designation and contracting instructions, not the text of §170.21. Treat an existing Status Date as controlling unless the Government provides authoritative written direction for your specific status.
What if my solicitation or contract still says Level 2 (C3PAO) or Level 3?
Look for a formal amendment or modification. The July 2026 implementation memo directs amendments to active solicitations and modifications to affected contracts before the next option exercise or scheduled administrative modification. A policy announcement by itself does not rewrite the document in your file.
Does Final status create a new three-year period?
No. The original Conditional CMMC Status Date remains the date for the Final status. Successful closeout changes the status, not the date.
How many affirmations are required when I close the POA&M?
§170.22 identifies affirmation triggers upon Conditional status, upon Final status, following a POA&M closeout assessment, and annually after Final. The regulation does not say whether a successful closeout and the resulting Final status require one or two separate electronic submission actions. Do not invent a signature count from the list; confirm the current SPRS workflow.
Who can sign the affirmation?
A senior company official responsible for ensuring compliance with the applicable CMMC requirements and who has authority to affirm continuing compliance. The signer is making a representation about the assessed environment, not merely acknowledging that a consultant completed work. Confirm the current role and SPRS access requirements before the deadline.
What has to be posted to SPRS for a Level 2 self-assessment?
§170.16 requires the result to include the CMMC Level, assessment scope, CAGE code or codes, CMMC unique identifier, overall score, POA&M use and compliance, and Status Date, followed by affirmation. SPRS operating screens and training materials may collect additional fields. Use the current system instructions rather than an old screenshot.
Does employee count change whether a requirement can go on the POA&M?
No. Employee Count appears in current SPRS operational input for NIST/CMMC records, but §170.21 does not use employee count to determine the 88-point floor, 46/63/1 classification, or 180-day deadline. It is an administrative data field, not a POA&M eligibility test.
Does NIST SP 800-171 Revision 3 control my CMMC Level 2 score now?
No, not under the current CMMC rule. NIST's current publication is Revision 3, but 32 CFR Part 170 still incorporates Revision 2 for CMMC Level 2. A separate contract may create other obligations, so review the actual clause and solicitation.
Does NIST SP 800-172 Revision 3 control CMMC Level 3?
No, not under the current rule. Part 170 uses the selected requirements from the February 2021 SP 800-172 publication. Revision 3 does not automatically enter CMMC merely because NIST published it.
Can I change the assessment scope while closing the POA&M?
Do not assume you can. CMMC status attaches to the assessed information system and scope. Material architecture or boundary changes can affect evidence, requirements previously scored MET, and the validity of the existing status. Coordinate with the applicable assessor and contracts/compliance advisors before making a scope change inside the window.
Can I use a POA&M for ordinary DFARS 252.204-7012 compliance outside CMMC?
CMMC's §170.21 eligibility and status mechanics are specific to CMMC. DFARS 252.204-7012 and the NIST SP 800-171 DoD Assessment Methodology have their own contractual and scoring context. Do not transfer the CMMC 46/63/1 framework into a non-CMMC representation without checking the controlling clause and guidance.
Is Conditional Level 2 (Self) the same as a CMMC certificate?
No. A self-assessment produces a CMMC status in SPRS. It does not produce a CMMC certificate from a C3PAO. State the level, assessment type, scope, and status accurately.
Can I tell a prime we are "CMMC compliant" while Conditional?
Use the exact recorded status instead: Level, assessment type, Conditional or Final, scope, Status Date, expiration, and CMMC UID where appropriate. "Compliant" can conceal whether the status is self-assessed, conditional, out of scope, or expired. The contract should drive what representation is required.
Where can I check whether a C3PAO or RPO is current?
Use The Cyber AB Marketplace and verify the legal entity, role, and current status. Then confirm who will perform the engagement and whether any conflict exists. A Marketplace listing does not guarantee availability, quality, price, or outcome.
Need help closing a CMMC POA&M before Day 180?
You do not need another generic readiness call. You need the next decision resolved:
- Is the Status Date correct?
- Are all open requirements actually eligible?
- Is the problem remediation, evidence, scope, assessor capacity, contract language, or some combination?
- Which provider role can solve that problem without creating a conflict?
- What must be complete by Day 120 and assessed by Day 150?
The Defense Compliance Report's Find My CMMC Path tool can route you to the provider category that matches the decision. For a higher-intent situation tied to an award, option, or active closeout, use the CMMC provider request form.
Do not submit CUI, FCI, drawings, export-controlled information, credentials, network diagrams, evidence artifacts, or sensitive contract details. We are not the Department of Defense, DCMA DIBCAC, The Cyber AB, a C3PAO, or your legal counsel. Some providers may compensate us for introductions or placement; sponsored or commercial relationships are labeled where applicable. No payment buys a favorable editorial conclusion or assessment outcome.
What to remember before you leave this page
The CMMC POA&M rule is not "score 88 and get six months."
It is four mechanisms working together:
- A weighted score gate: at least 88 of 110 for Level 2.
- An item-by-item eligibility gate: 46 ordinary requirements can potentially be deferred, 63 never can, and one encryption case is conditional.
- A fixed status clock: 180 calendar days from the date results are submitted to SPRS or CMMC eMASS.
- A closeout and representation process: all POA&M items must be confirmed MET, results posted, and the applicable affirmation handled before the status can safely support the next contract decision.
Add the pre-status trap on the certification path: the re-evaluation window closes at the earlier of Findings Report delivery or 10 business days after the active assessment period.
Add the current procurement reality: Phase II is suspended, but the POA&M rule is not. Affected solicitations and contracts need actual amendments or modifications. Existing status clocks do not stop because the policy review is underway.
And add the date most teams lose: reaching Final does not reset your three-year period. The original Conditional Status Date stays with you.
The smart operating rule is simpler than the regulation: classify every gap before assessment, record the real Status Date, finish by Day 120, close by Day 150, and treat Day 180 as a cliff.
Resolve the provider decision before the clock becomes the emergency
Find the right CMMC path → or request a provider match →.
Independent editorial routing. No CUI submission. No certification guarantee. Commercial relationships are disclosed.
Primary sources and update record
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program
- 32 CFR §170.4 — Definitions
- 32 CFR §170.8 — CMMC assessor and instructor requirements
- 32 CFR §170.9 — C3PAO requirements
- 32 CFR §170.16 — Level 2 self-assessment and affirmation
- 32 CFR §170.17 — Level 2 certification assessment and affirmation
- 32 CFR §170.18 — Level 3 certification assessment and affirmation
- 32 CFR §170.21 — POA&M requirements
- 32 CFR §170.22 — Affirmation requirements
- 32 CFR §170.24 — CMMC scoring methodology
- DFARS Subpart 204.75
- DFARS 252.204-7012
- DFARS 252.204-7019
- DFARS 252.204-7020
- DFARS 252.204-7021
- DoD/DoW CMMC Program
- Implementing Suspension of CMMC Phase II memorandum, July 2026
- The Cyber AB CMMC Assessment Process v2.0
- The Cyber AB Marketplace
- NIST SP 800-171 Revision 2
- NIST SP 800-172, February 2021
- Department of Justice LOGZONE settlement release, June 18, 2026
Update record: This page was checked against the sources above on August 29, 2026. We rechecked the CMMC phase posture, suspension implementation instructions, POA&M and scoring text, Level 2 and Level 3 version references, DFARS status-verification clauses, Cyber AB closeout/appeal mechanics, and the LOGZONE settlement amount and allegation language. See our editorial standards, methodology, and corrections policy.
