Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

How Do I Implement NIST 800-171 R3 03.12.02 Plan of Action and Milestones?

NIST 800-171 R3 03.12.02 Plan of Action and Milestones at a Glance

  • Family: 03.12 Security Assessment and Monitoring (CA)
  • Requirement ID: 03.12.02 Plan of Action and Milestones
  • Assessment Objectives (AOs): Five (5) determination statements
  • Organization-Defined Parameters (ODPs): None (0). This requirement contains no organization-defined values
  • Source NIST 800-53 R5 Control: CA-05
  • NIST 800-171 R3 Kill Chain Phase: Phase 5b, Document The CUI and/or FCI Environment

Plan of Action and Milestones is the requirement behind the document that tracks how your unmet security requirements will be fixed. It is part of the Security Assessment and Monitoring (03.12) family, and it is where findings from assessments and monitoring become tracked remediation commitments. Plan of Action and Milestones (03.12.02) has two (2) parts: develop a plan of action and milestones (POAM) that documents planned remediation actions and reduces or eliminates known vulnerabilities, and update the existing POAM based on findings from assessments, audits or reviews, and continuous monitoring. Per the NIST discussion, POAMs describe how unsatisfied security requirements will be met, they can be combined with or separate from the system security plan, and federal agencies may use the system security plan and POAM as inputs to decisions about whether to process Controlled Unclassified Information (CUI) on a nonfederal system.

A common difficulty with this requirement is treating the POAM as a static list built once for an assessment. R3 makes the update obligation explicit and ties it to three sources: assessments, audits or reviews, and continuous monitoring. A POAM that is created for a certification and never updated as new findings arrive does not satisfy the requirement, since remediation planning is meant to be a living process.

Where things stand for companies facing the transition from NIST 800-171 R2 to R3:

  • The National Institute of Standards and Technology (NIST) withdrew R2 on May 14, 2024, the same day R3 was published. The withdrawal notice states that R2 "has been withdrawn (archived), and is provided solely for historical purposes," so it will never receive another correction or clarification from NIST.
  • R2 remains the contractual standard for the Department of Defense (DoD) and the Defense Industrial Base (DIB). Cybersecurity Maturity Model Certification (CMMC) assessments reference it directly: per Title 32 of the Code of Federal Regulations (CFR), section 170.14(c)(3), "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
  • The rulemaking points the other direction. The proposed Controlled Unclassified Information (CUI) rule for the Federal Acquisition Regulation (FAR), published June 23, 2026 as part of the Revolutionary FAR Overhaul, would apply CUI safeguarding requirements government wide rather than only to DoD contracts, and it sets the baseline at R3. That rule is not final, and DoD has separately signaled an interim rule to move CMMC to R3.

What Does NIST 800-171 R3 03.12.02 Actually Require?

The following is reproduced verbatim from NIST 800-171 R3, requirement 03.12.02 Plan of Action and Milestones. Only the formatting has been adjusted for readability. This requirement has two (2) lettered parts, each with numbered sub-parts:

  • a. Develop a plan of action and milestones for the system:
    1. To document the planned remediation actions to correct weaknesses or deficiencies noted during security assessments and
    2. To reduce or eliminate known system vulnerabilities.
  • b. Update the existing plan of action and milestones based on the findings from:
    1. Security assessments,
    2. Audits or reviews, and
    3. Continuous monitoring activities.

The source control is CA-05 from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, organizations use POAMs to describe how unsatisfied security requirements will be met and how planned mitigations will be implemented, and system security plans and POAMs can be separate or combined documents in any format. You can read the requirement directly at NIST 800-171 R3, 03.12.02 (p. 56).

What Are the Organization-Defined Parameters (ODPs) Associated with NIST 800-171 R3 03.12.02?

None (0). Requirement 03.12.02 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.

Your System Security Plan (SSP) narrative for 03.12.02 therefore records how the requirement is implemented rather than a parameter you chose.

What Are the Assessment Objectives (AOs) For NIST 800-171 R3 03.12.02?

NIST 800-171A R3 breaks 03.12.02 into five (5) determination statements, and it has no Organization-Defined Parameters (ODPs). These AOs are:

  • A.03.12.02.a.01: a plan of action and milestones for the system is developed to document the planned remediation actions for correcting weaknesses or deficiencies noted during security assessments.
  • A.03.12.02.a.02: a plan of action and milestones for the system is developed to reduce or eliminate known system vulnerabilities.
  • A.03.12.02.b.01: the existing plan of action and milestones is updated based on the findings from security assessments.
  • A.03.12.02.b.02: the existing plan of action and milestones is updated based on the findings from audits or reviews.
  • A.03.12.02.b.03: the existing plan of action and milestones is updated based on the findings from continuous monitoring activities.

Part a covers developing the POAM and part b covers updating it from three sources. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.12.02 (p. 72).

Assessment Methods and Objects for NIST 800-171 R3 03.12.02

Examine: security assessment and monitoring policy and procedures; procedures for plans of action and milestones; security assessment plan; security assessment report; security assessment evidence; plan of action and milestones; system security plan.

Interview: personnel with plans of action and milestones development and implementation responsibilities; personnel with information security responsibilities.

Test: mechanisms for developing, implementing, and maintaining plans of action and milestones.

How Does NIST 800-171 R3 03.12.02 Map From NIST 800-171 R2?

03.12.02 maps from NIST 800-171 R2 requirement 3.12.2 (develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems):

  • A.03.12.02.a.01 and A.03.12.02.a.02 map indirectly to elements of R2 3.12.2[a], 3.12.2[b], and 3.12.2[c] (developing the plan of action to correct deficiencies and reduce vulnerabilities).
  • A.03.12.02.b.02 and A.03.12.02.b.03 are net new for R3.
  • A.03.12.02.b.01 has no clear mapping to any R2 assessment objective.

Mapped against the five (5) AOs, two (2) are indirect (moderate effort), two (2) are net new, and one (1) has no clear mapping, with the last two (2) categories both counting as significant effort. Developing the POAM carries forward, but the explicit obligation to update it based on audits or reviews and continuous monitoring is new, and updating from assessment findings does not trace cleanly to a R2 objective. Three of the five (5) objectives are significant effort, all concentrated on keeping the POAM current.

How Does NIST 800-171 R3 03.12.02 Map to NIST 800-53 R5 and the SCF?

Source Control in NIST 800-53 R5:

  • CA-05

Secure Controls Framework (SCF) Crosswalk

Organizations running a single control set across multiple frameworks can satisfy 03.12.02 through the following SCF controls:

  • CPL-06 Non-Conformity Oversight
  • IAO-12 Capabilities Deficiency Tracking
  • RSK-14 Risk Register
  • RSK-17 Risk Remediation
  • VPM-06 Vulnerability Remediation Process
  • VPM-08 Software & Firmware Patching

The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.

Common Pitfalls with NIST 800-171 R3 03.12.02

The following are issues teams may encounter rather than certainties. They are about keeping the POAM current, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:

  • The POAM is a living document. A.03.12.02.b.01 through b.03 require updates from assessments, audits or reviews, and continuous monitoring. A static POAM built once for certification does not satisfy these objectives.
  • Three update sources. Audits or reviews (b.02) and continuous monitoring (b.03) are net new as explicit triggers. Updating only after formal assessments leaves objectives open.
  • Develop it for the right reasons. A.03.12.02.a.01 and a.02 require the POAM to document remediation for assessment findings and to reduce or eliminate known vulnerabilities, so tie POAM entries to real findings.
  • Coordinate with risk response. Risk Response (03.11.04) decides which findings need planned remediation, and those become POAM entries, so keep the two connected.

What Is Reasonable Evidence For NIST 800-171 R3 03.12.02?

Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.12.02 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.12.02 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.

  • E-CPL-05 Internal Audit (IA) Findings. A centrally-managed and prioritized repository internal audit (ia) findings.
  • E-CPL-09 Non-Compliance Oversight Reporting. Governance oversight reporting of non-compliance to the organization's executive leadership.
  • E-MNT-03 Patch Management. Maintenance activities for technology assets, applications and/or services (taas) (e.g., patch management).
  • E-RSK-03 Plan of Actions & Milestones (POA&M) / Risk Register. A poa&m, or risk register, that tracks control deficiencies from identification through remediation.
  • E-VPM-01 Vulnerability & Patch Management Program (VPMP). A vulnerability & patch management program (vpmp). this is program-level documentation in the form of a runbook, playbook or a similar format provides guidance on organizational practices that support existing policies and standards.
  • E-VPM-07 Flaw Remediation Change Control. Installation/change control records for security-relevant software and firmware updates.
  • E-VPM-09 Flaw Remediation Actions. List of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws).

Alongside these, keep the System Security Plan (SSP) narrative for 03.12.02.

Timeline Considerations for NIST 800-171 R3 03.12.02

With two (2) AOs mapping indirectly, two net new, and one with no clear mapping, 03.12.02 is a moderate lift centered on the update process. A realistic sequence:

  1. Develop the POAM to document remediation actions and reduce or eliminate known vulnerabilities (A.03.12.02.a.01 and a.02).
  2. Establish the update process so the POAM is refreshed from security assessments (A.03.12.02.b.01).
  3. Add update triggers for audits or reviews and continuous monitoring (A.03.12.02.b.02 and b.03), the net-new sources.
  4. Connect the POAM to Risk Response (03.11.04) and Continuous Monitoring (03.12.03).
  5. Collect evidence for all five (5) AOs, including the POAM and its update history from each source.

Frequently Asked Questions About NIST 800-171 R3 03.12.02

How many assessment objectives does NIST 800-171 R3 03.12.02 have? NIST 800-171A R3 breaks 03.12.02 into five (5) assessment objectives. An assessor works through each one separately, so each needs its own evidence.

Which NIST 800-53 R5 control does NIST 800-171 R3 03.12.02 come from? CA-05.

How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.12.02 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.

Where does NIST 800-171 R3 03.12.02 sit in the NIST 800-171 R3 Kill Chain? Phase 5b, Document The CUI and/or FCI Environment. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.

Bottom Line on NIST 800-171 R3 03.12.02

03.12.02 Plan of Action and Milestones develops a POAM to track remediation and reduce vulnerabilities, and updates it from assessments, audits or reviews, and continuous monitoring. It maps from R2 3.12.2 with POAM development transitioning indirectly, while the audit and continuous-monitoring update triggers are net new. The recurring problem is a static, certification-only POAM. Build the POAM from real findings, and keep it current from all three sources.

Authoritative sources:

Authoritative sources:

This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.