POA&MPlan of Action and Milestones
A document identifying security weaknesses, the planned remediation actions, required resources, and scheduled completion dates for achieving full compliance.
Related Terms
NIST SP 800-171
The NIST standard for protecting CUI in non-federal systems. Revision 2 — the revision DoD assesses — specifies 110 security requirements and forms the basis of CMMC Level 2 and DFARS 252.204-7012 compliance.
SPRS
The Supplier Performance Risk System score (-203 to 110) reflecting a contractor's self-assessed compliance with NIST SP 800-171. Required for DoD contracts involving CUI.
CMMC
A DoD framework requiring defense contractors to meet specific cybersecurity standards before handling federal contract information.
Related Guides
Check Your CMMC Readiness
Run our free compliance tools to see where your organization stands.
Audit Your Tech Stack FreeTalk this gap analysis through with a founder
This Plan of Action and Milestones explainer is the start, not the answer. Book a 25-minute fit call with a founder who builds and runs the platform, and find out whether we are the right people to help you close the gaps.
Book a 25-minute fit callRelated: how much CMMC certification costs — DoD’s own priced figures