As part of CMMC compliance efforts, organizations must understand the mechanisms available to identify, manage and address cybersecurity gaps. Three critical concepts every organization should understand are Temporary Deficiencies, Enduring Exceptions and Operational Plans of Action (POA&Ms).
The Operational Plan of Action and Milestones (POA&M) is the formal corrective action plan that ties everything together. It documents known deficiencies, sets milestones for remediation and provides a clear timeline for closure. The Department of War (DoW) includes POA&Ms in CMMC 2.0, recognizing that no system is perfect and that some government contractors may need additional time to remediate identified gaps.
Think of these mechanisms as a tiered approach to managing compliance gaps:
A temporary deficiency feeds into a POA&M. An enduring exception lives in the SSP with its compensating control. Both require documentation, accountability and ongoing review.
Jason Spencer is a Cybersecurity Consultant with more than a decade of experience in security assessments, compliance and risk management. Since beginning his cybersecurity career in 2010, he has specialized in network security, wireless security, vulnerability management and regulatory compliance assessments across commercial, banking and federal environments. Jason has extensive experience conducting NIST 800-171 and CMMC assessments, having led and participated in more than 100 assessments since 2017. He is a Certified CMMC Professional (CCP) and also supports organizations with NIST 800-53, HITRUST, DFARS, HIPAA and PCI compliance initiatives. Additionally, Jason has served as a Qualified Security Assessor (QSA) since 2019 and is trained on PCI DSS 3.2.1 and 4.0.1. His technical expertise includes perimeter, network, wireless and firewall security assessments, database auditing, workstation reviews, social engineering and security operations support within both Network Operations Center (NOC) and Security Operations Center (SOC) environments. Jason holds a Bachelor of Arts degree in Geology with teacher certification and maintains several industry certifications, including CISSP. He has also presented at Converge in Anaheim, California.