Skip to main content
Compliance & ATO

POA&M rules: what you can defer and what you cannot

A plan of action is not a grace period and it is not a negotiation. It is a narrow, rule-bound door with three gates on it, and the requirements most firms want to push into next year are the ones the rule specifically refuses to let them push. Knowing that early changes what you build first.

Engineering perspective — and read 32 CFR 170.21 yourself Written by engineers who build and evidence these environments, not by lawyers or certified assessors. The operative text is the program rule at 32 CFR part 170, the DFARS clauses on acquisition.gov, and the published assessment guides. The exact enumeration of which requirements may and may not appear on a plan of action lives in the rule, it has been amended before, and no article — including this one — is a substitute for reading it. Where we describe the shape of a rule rather than quoting it, we say so.

Deferral is a narrow door, and the narrowness is deliberate

Almost everybody arrives at this subject hoping for the same thing. They have counted their gaps, seen the expensive ones, and want to know how many can be written down as “planned” so that award is not blocked while the work finishes. That hope is reasonable, and the program does contain a mechanism for it. What surprises people is the shape of the mechanism. It was designed by people who anticipated exactly that hope, and it is built so the cheap gaps can be deferred and the expensive ones cannot. Once you understand that inversion, planning gets much easier, because the sequencing question answers itself.

Three gates stand between a gap and a deferral. Your overall assessment score has to already be high. The specific requirement has to be one the rule permits on a plan. And the clock that starts when you are granted a conditional status is fixed, short, and does not renew. Fail any one of the three and the plan is not available for that item, no matter how sensible your reasoning is or how sympathetic the assessor.

You are probably here because

  • You have a gap list and a contract date and they do not fit together
  • Somebody told you that a plan of action buys 180 days and you want to know what it actually buys
  • Your score is in the nineties and you are trying to work out whether that is enough
  • You are trying to decide what to fund this quarter and what can wait

If you only read one section, read the second gate. It is the one that reorders most funding plans.

Two different documents share the same name

Before the gates, clear up a naming collision that causes real confusion in real projects.

The plan that accompanies your system security plan. Under the safeguarding clause, DFARS 252.204-7012, a contractor implementing the NIST SP 800-171 requirements documents its implementation in a system security plan and tracks unimplemented requirements in a plan of action. This is an ordinary security management artifact. It has existed since well before the certification program, it lives with your own documentation, and it is the thing a government-led assessment team will read alongside your plan. Related to it is the self-assessment score you post in the Supplier Performance Risk System under the assessment clauses, which asks not only for the score but for the date by which you expect to reach full implementation.

The plan that produces a conditional certification status. This one is a creature of the program rule. It exists only in connection with a Level 2 assessment, it is bounded by the gates below, and it converts a result that would otherwise be a failure into a time-limited conditional status. It is the one people mean when they ask what they can defer.

Both are legitimate. They answer to different rules and different readers, and a firm that keeps a single spreadsheet for both will eventually present the wrong one to the wrong audience. Keep the internal management plan honest and complete, and treat the certification plan as a formal, minimal, tightly argued subset.

Gate one: the score has to already be high

The assessment methodology behind the score is arithmetic rather than judgment. You begin at the full count of requirements — 110 at Level 2 — and subtract for each one not implemented. The subtractions are weighted: the requirements the Department considers most consequential cost more when missing than the administrative ones do. That is why two firms with the same number of open gaps can post very different scores, and why chasing the count of findings rather than their weight is a waste of a quarter.

The rule then sets a floor. A plan of action is available only when your assessment score reaches a defined proportion of the total — eighty percent, which at Level 2 works out to 88 of 110. Below that floor, there is no conditional status to be had. The assessment result stands as it is.

Two implications matter more than they sound. First, the floor is measured on the weighted score, not on the count of open items, so closing several one-point administrative gaps may not move you as far as closing a single heavily weighted one. Second, a firm sitting well below the floor is not in a deferral conversation at all. It is in a remediation conversation, and the honest advice is to stop optimising the paperwork and go fix the environment.

Gate two: the items you want to defer are the ones you cannot

Here is the inversion. The rule does not let a plan of action carry the heavily weighted requirements. Those have to be met at the time of assessment. It then goes further and names a small number of specific lower-weighted requirements that also may not be deferred — the two that come up in nearly every conversation are multifactor authentication and the use of validated cryptography to protect controlled information.

Read the exact enumeration in the rule rather than trusting any secondary source, this article included; it is the kind of list that gets amended and that vendors quote from memory. But the design intent is not in doubt, and it is worth stating plainly: the deferral mechanism is available for items that are cheap, administrative and quick, and unavailable for the items that take money, procurement time and architecture work. Nobody gets to defer their way past encryption, identity, or the boundary itself.

The plan of action covers the work you could finish in a month anyway. It does not cover the work that takes two quarters and a purchase order. Plan the two quarters first.

This has an immediate consequence for sequencing, and it is the practical payoff of the whole article. Fund the heavily weighted, non-deferrable items first, even when they are the least satisfying to work on and the hardest to show progress against. Multifactor authentication across every access path, validated cryptographic modules everywhere controlled information sits or moves, a boundary you can actually describe, and the access controls that enforce it. The tidy documentation gaps that make a gap list look long can wait, because those are precisely the ones a plan of action was built to hold.

GateThe rule, in shapeWhat it means on Monday
Score floorA plan is available only at or above eighty percent of the total — 88 of 110 at Level 2Below the floor there is no deferral conversation. Remediate, then reassess.
Excluded requirementsHeavily weighted requirements may not be deferred, plus a short named list of othersFund identity, encryption and boundary work first. They are not deferrable.
Closeout periodA fixed period, 180 days, from the conditional status dateAnything with a lead time longer than about four months is not a plan item.
Closeout assessmentThe plan is closed by an assessment, not by your assertionBook the closeout work when you get the conditional status, not near the end.
Level 1No plan of action mechanismAll fifteen requirements met, or the self-assessment does not pass.
AffirmationA named senior official affirms, and affirms again annuallySomebody's name is on this. Make sure they have read it.

Gate three: 180 days, and the clock does not care

A conditional status runs for a fixed 180 days from the date it is granted. Within that window the open items have to be closed and a closeout assessment performed. If they are not, the conditional status expires rather than converting, and the consequences flow from whatever the contract says about maintaining the required status.

Three things about that window are worth internalising. It is not renewable, so treating it as a first attempt is a mistake. It is closed by an assessment rather than by your own declaration, which means it depends on somebody else's availability and you should arrange that at the start of the window rather than in month five. And the assessor market has capacity limits that have been publicly discussed by the Department for years, so availability is a real constraint rather than an administrative formality.

The practical rule we use is simple. If an item has a procurement lead time, a vendor dependency, or a change that touches how people do their daily work, it does not belong on a plan of action even if the rule technically permits it. Six months sounds generous until you subtract a purchasing cycle, a pilot, a rollout to people who did not ask for it, and the assessment itself.

How realistic is it to close this inside 180 days? — our read

Writing a missing policy or procedure
95
Turning on and evidencing an existing platform feature
88
Formalising access reviews and separation of duties
78
Standing up log collection and someone to read it
55
Replacing an unsupported system on a production floor
20
Migrating a tenant and re-training everyone who uses it
12

Our judgment from building these environments, not a survey. The bottom two rows are the work that has to be finished before the assessment, not after it.

Level 1 has no door at all

Firms that only ever receive federal contract information sit at Level 1, which carries the fifteen basic safeguarding requirements found in FAR 52.204-21 and is satisfied by an annual self-assessment with an affirmation. There is no deferral mechanism here. All fifteen are met or the self-assessment does not pass.

That reads as harsh and is actually kind. Fifteen requirements are a weekend of honest work for most small firms, and there is no scoring arithmetic to reason about. If you are at Level 1 and you are reading an article about deferral, the useful move is to stop reading and go close the fifteen. You almost certainly do not need outside help for that, and anybody selling you a program for it is selling you a program you do not need.

What a conditional status actually buys

It buys eligibility, on a clock, in exchange for a commitment somebody signs. It does not buy an opinion that your environment is fine. It does not buy you room to argue with a contracting officer. And it does not quietly become permanent if nobody follows up, which is the assumption we see most often in firms that have lived with ordinary security findings for years and are used to plans that roll.

The affirmation deserves particular attention because it is the part people skim. A named senior official affirms that the requirements are met, and affirms again on an annual cadence. That is a personal attestation about a technical state of affairs, made by somebody who usually cannot verify it personally. The practical protection is unglamorous: give that person a short, honest, current summary they can actually stand behind, tell them what is open and why, and never let the first time they read the plan be the day they sign it.

Rows that get a plan rejected

Assuming the item is eligible and the score clears the floor, the row still has to be readable by somebody deciding whether to agree with it. The failures are consistent.

A restated requirement instead of a finding. “Implement multifactor authentication” tells the reader nothing. What is actually true today, on which systems, for which accounts, is the row.

A date with no work behind it. Every date in a plan should be traceable to a purchase, a person, or a change that is already in motion. Dates that are round numbers of months from the assessment are read exactly as what they are.

No compensating measure. The question a reader asks after “when” is “and what protects the information until then.” A row that does not answer it invites the conclusion that nothing does.

No owner. A named person or office, not a department and not a vendor category. We have written separately about what a defensible plan row looks like line by line, and the discipline transfers directly.

If you are below the floor

Say it plainly, internally, on the day you know it. A firm below the score floor with a contract date in front of it has a sequencing problem and a budget problem, and both get worse the longer they are described as a documentation problem. The options are real but they are all uncomfortable: shrink the environment so fewer systems have to meet the requirements, get the controlled information out of your hands entirely by having the prime hold it, or move the date.

Shrinking the boundary is usually the move that changes the most and the one most firms consider last. It is a design decision rather than a compliance decision, which is why it tends to sit outside the compliance lead's authority and needs an executive to make it.

Where this goes wrong

  • Planning around deferral before checking the excluded list — and finding out the expensive items were never eligible
  • Counting open items instead of weighted points, so effort goes to the cheapest gaps
  • Treating 180 days as a first attempt rather than a fixed, non-renewable window
  • Arranging the closeout assessment in month five, when assessor availability is a real constraint
  • One spreadsheet serving as both the internal plan and the certification plan
  • Rows that restate the requirement instead of describing what is actually true today
  • An affirming official who reads the plan the day they sign it
  • Assuming a conditional status rolls forward the way ordinary security findings often do

Before you rely on a plan of action

  • Confirm the current text of 32 CFR 170.21 rather than a summary of it
  • Score with the weighted methodology, and know your number before the assessment
  • Mark every gap as deferrable or not deferrable before you build a budget
  • Fund identity, encryption and boundary work first, on the assumption it is not deferrable
  • Test every candidate row against a four-month delivery reality, not six
  • Give every row a named owner, a real date, and the measure protecting the data meanwhile
  • Arrange closeout coverage at the start of the window
  • Brief the affirming official well before there is anything to sign
  • Check whether the program still pins the revision of SP 800-171 you are building to

Bottom line

A plan of action is a real mechanism and a narrow one. It requires a score already close to complete, it excludes the requirements that cost the most to satisfy, and it runs on a fixed 180-day clock closed by somebody else's assessment. Used well, it covers the last handful of administrative items while the substantive work finishes. Used as a strategy, it fails, because the strategy assumes a door that the rule deliberately did not build. The planning move that follows is the useful one: find out today which of your gaps are ineligible for deferral, and fund those first.

Frequently asked questions

What score do we need before a plan of action is available?

At least eighty percent of the total, which at Level 2 means 88 of the 110 requirements' worth of weighted points. The score is weighted rather than a simple count, so closing several minor gaps may move you less than closing one significant one. Below the floor there is no conditional status available, and the honest next step is remediation rather than paperwork.

Which requirements can never go on a plan?

The heavily weighted ones as a class, plus a short list of specifically named others — multifactor authentication and the use of validated cryptography are the two that arise constantly. The exact enumeration is in the program rule and has been amended before, so read 32 CFR 170.21 in its current form rather than any secondary summary, including this one.

Can the 180 days be extended?

Plan on no. The window runs from the date the conditional status is granted, and closing it requires a closeout assessment rather than your own declaration. Arrange the closeout coverage at the beginning of the window. Any item with a purchasing cycle or a rollout to end users behind it should be finished before the original assessment, not planned into the window.

Is the plan we keep internally the same as the one for certification?

No, and keeping one document for both causes trouble. The internal plan that accompanies your system security plan is an ordinary management artifact and should be complete and honest. The certification plan is a bounded, formal subset governed by the program rule. Different readers, different rules, different consequences for a sloppy row.

We are at Level 1. How many can we defer?

None. Level 1 has no plan-of-action mechanism: all fifteen basic safeguarding requirements have to be met for the self-assessment to pass. The good news is that fifteen requirements are genuinely achievable in-house for most small firms using the free published guidance, and a program sold to you for that scope is a program you do not need.

1 business day response

Want a second read on which gaps are actually deferrable?

Send the gap list and the score, and we will mark which items look ineligible for a plan of action and which look closeable inside the window. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
CMMCPOA&MSPRSNIST SP 800-171