Learn about the SPRS score for conditional certification, which controls cannot be placed on a POA&M, the impact if they are not closed on time, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.
Table of Contents
What is a POA&M in the context of a CMMC certification assessment?
Summary: In the CMMC certification context, a Plan of Action and Milestones (POA&M) is a formal document generated at the conclusion of a C3PAO assessment that identifies specific security control deficiencies found during the assessment, specifies the remediation actions the organization will take to address each deficiency, assigns responsible parties, and establishes target completion dates, serving as the basis for Conditional Level 2 certification when specific eligibility conditions are met.
The certification-context POA&M is distinct from a pre-assessment compliance POA&M. Before a C3PAO assessment, organizations use POA&Ms as internal project management tools to track gap remediation with no externally mandated deadline. After a C3PAO assessment, the POA&M carries strict program rules: it can only contain deficiencies for controls weighted at 1 point; the resulting SPRS score must be 88 or above; and all items must be closed within 180 days of the Final Findings Briefing.
The C3PAO retains oversight responsibility for verifying POA&M closure, the organization cannot self-certify that items have been addressed. POA&M items are submitted to eMASS alongside the assessment findings and are visible to the DoD as part of the conditional certification record. Failure to close all items within 180 days causes the Conditional certification to lapse, requiring a full new assessment.
What SPRS score must I achieve to receive Conditional CMMC Level 2 certification?
Summary: To receive Conditional CMMC Level 2 certification following a C3PAO assessment, an organization must achieve a minimum SPRS score of 88 out of 110, with all deficiencies limited exclusively to controls weighted at 1 point, no deficiencies in controls weighted at 3 or 5 points are permissible for Conditional certification eligibility.
A score of 88 represents approximately 80 percent compliance with all 110 NIST SP 800-171 Rev 2 controls. The score of 88 is not arbitrary, the DoD calculated it as the threshold below which remaining deficiencies, even limited to 1-point controls, represent too many fundamental security gaps to award any certification status.
Organizations scoring between 88 and 109 can receive Conditional status. Organizations scoring 110 receive Final certification immediately with no POA&M. Organizations scoring below 88 receive no certification, they must remediate, retest, and undergo a new assessment. The SPRS score of 88 for Conditional certification eligibility applies to C3PAO-conducted assessments; for Level 2 self-assessment SPRS entries submitted before formal C3PAO assessment, organizations can post scores below 88 as an accurate representation of their current posture, but those entries reflect non-certified compliance status, not a certification level.
Which controls cannot be placed on a POA&M and will result in automatic certification failure?
Summary: Controls weighted at 3 or 5 points in the SPRS scoring methodology cannot be placed on a POA&M under CMMC Level 2,if any 3-point or 5-point control is found NOT MET during a C3PAO assessment, the result is a failed assessment with no Conditional certification available, regardless of the overall SPRS score.
The 5-point controls represent the most critical security requirements whose absence directly enables major network exploitation or CUI theft. Common 5-point controls include: multi-factor authentication for local access to privileged accounts (IA domain); multi-factor authentication for network access to privileged accounts (IA domain); and FIPS-validated cryptography (SC domain control 3.13.10, SC.L2-3.13.11).
The 3-point controls represent requirements with specific and significant but more contained security effects. If any of these controls are NOT MET, the assessment is a failure and the contractor must fully implement the deficient control, gather verification evidence, and schedule a new complete assessment. Pre-assessment focus on verifying that all 3-point and 5-point controls are fully implemented is the highest-priority risk mitigation step before engaging a C3PAO.
How long does my organization have to close POA&M items after receiving Conditional certification?
An organization that receives Conditional CMMC Level 2 certification has exactly 180 days from the date of the Final Findings Briefing to implement all POA&M items, gather verifying evidence, and have the C3PAO confirm closure, failure to close all items within this window causes the Conditional certification to lapse.
The 180-day period is not extendable and does not restart upon any milestone, it runs from the date the C3PAO delivers the Final Findings Briefing regardless of subsequent activities. Organizations should immediately begin implementing POA&M remediation following the briefing, treating day 0 as the moment findings are delivered. C3PAO verification of POA&M closure requires the organization to provide evidence that each deficient control is now fully implemented to the same standard as a MET finding.
The C3PAO will examine, and in some cases re-test, the remediated controls. Sufficient time must be built into the 180-day window for the C3PAO to schedule and complete verification activities before the deadline. Organizations should aim to have all POA&M items remediated and evidence gathered no later than day 150, preserving 30 days for C3PAO verification and eMASS submission.
What happens to my Conditional certification status if POA&M items are not closed on time?
Summary: If an organization fails to close all POA&M items and obtain C3PAO verification within 180 days of the Final Findings Briefing, the Conditional CMMC Level 2 certification lapses and the organization’s CMMC status in SPRS reverts to no valid certification, making the organization ineligible for any DoD contract awards requiring Level 2 C3PAO certification until a new complete assessment is successfully passed.
The Conditional certification lapse has immediate contract consequences. Contracting officers can verify certification status in SPRS, a lapsed certification is visible and disqualifies the organization from award eligibility for applicable contracts. Prime contractors who verified a subcontractor’s Conditional certification before awarding a subcontract must address the compliance gap in their supply chain oversight.
The organization must schedule a new complete C3PAO assessment from the beginning since there is no abbreviated re-assessment for previously assessed controls. Given C3PAO scheduling lead times of 3 to 12 months in 2026, a lapsed Conditional certification can result in 12 to 18 months of ineligibility before a new Final certification is obtained. To avoid this outcome, organizations should treat every POA&M item as a critical-path remediation task and maintain weekly status tracking against the 180-day deadline from day one.
What is the difference between a pre-assessment gap analysis POA&M and a post-assessment C3PAO POA&M?
Summary: A pre-assessment gap analysis POA&M is a voluntary, internally managed planning document used to track compliance remediation before a formal assessment, with no externally imposed deadline, no program-mandated format, and no Cyber AB visibility, while a post-assessment C3PAO POA&M is a formal, eMASS-recorded document subject to strict program rules including 180-day closure requirements and mandatory C3PAO verification.
Pre-assessment gap analysis POA&M: Created during the compliance preparation phase to document identified control gaps and track remediation progress. It is an internal project management tool, not a regulatory artifact. It can include any control, including 3-point and 5-point controls, and can remain open indefinitely without program consequences. It informs the organization’s readiness assessment and helps prioritize remediation spending.
Post-assessment C3PAO POA&M: Created only when a C3PAO assessment finds NOT MET controls qualifying for Conditional certification (score ≥88, all deficiencies are 1-point controls only). It is submitted to eMASS, visible to the DoD, and subject to 180-day mandatory closure. The C3PAO must independently verify closure of each item. Organizations sometimes confuse the two documents, leading to misplaced confidence when entering a C3PAO assessment having managed a gap analysis POA&M informally.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties