POA&M — Assessor View
Read-only. The same unified POA&M record the operator works from: operational plans of action (internal tracking, CA.L2-3.12.2) and assessment POA&Ms riding a Conditional Level 2 CMMC Status (32 CFR § 170.21).
Conditional Level 2 readiness
Would survive todayWould this POA&M set survive a C3PAO Conditional Level 2 determination today?
- Pass: Residual score 101 / 110 — meets the ≥88 floor32 CFR § 170.21(a)(2)(i)
- Pass: No ineligible controls on the assessment POA&M32 CFR § 170.21(a)(2)(ii)–(iii)
- Pass: All assessment items inside the 180-day closeout window32 CFR § 170.21(b) — closeout within 180 days of the Conditional CMMC Status Date
- 3.1.5Least Privilegeoperational
Least privilege is asserted, not enforced: three engineers hold local admin on the CAD workstations for driver installs.
1/3 milestonestarget 2026-11-17owner Demo assessor (read-only) - 3.1.7Privileged Functionsassessment169d of 180 left
No technical control stops a standard user from running privileged functions on the shop-floor kiosk.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.1.9Privacy & Security Noticesassessment169d of 180 left
Interactive logon notice is missing on two servers migrated in July.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.2.1Role-Based Risk Awarenessoperational
Security awareness training was delivered in 2025 but 4 of 38 staff hired since have not completed it.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.2.2Role-Based Trainingoperational
Role-based training for the two ISSO-designates has not been completed.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.2.3Insider Threat Awarenessassessment169d of 180 left
Insider-threat awareness has not been delivered to the engineering staff.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.3.4Audit Failure Alertingassessment169d of 180 left
No alert fires when audit logging fails on the file server.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.3.5Audit Correlationoperational
Audit review is ad hoc; no correlated review across the ERP, file server and identity provider.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.4.2Security Configuration Enforcementoperational
Configuration baseline exists for servers but not for the CAD workstations.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.4.8Application Execution Policyoperational
Application allow-listing runs in audit-only mode on 11 workstations.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.4.9User-Installed Softwareassessment169d of 180 left
User-installed software is not restricted on the CAD workstations.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.6.3Incident Response Testingassessment169d of 180 left
The incident response plan has not been exercised in the last 12 months.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.8.4Media Markingsassessment169d of 180 left
Printed drawings leave the engineering office without CUI markings or distribution statements.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.8.7Removeable Mediaoperational
USB mass storage is permitted on the CAD workstations.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.13.11CUI Encryptionoperational
Backups are encrypted with a module that is not CMVP-validated.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.13.12Collaborative Device Controlassessment169d of 180 left
Collaborative computing devices (conference-room camera) have no indicator-of-use control documented.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.1.12Control Remote Accessoperational
Remote maintenance sessions from the ERP vendor are not monitored or recorded.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.5.11Obscure Feedbackassessment169d of 180 left
The ERP login form echoes the last username and reveals which of username or password was wrong.
1/3 milestonestarget 2027-01-16owner Demo assessor (read-only) - 3.11.1Risk Assessmentsoperational
The last documented risk assessment is dated 2024 and predates the ERP migration.
1/3 milestonestarget 2026-11-17owner Demo assessor (read-only) - 3.12.1Security Control Assessmentoperational
No periodic self-assessment of control effectiveness has been recorded.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.13.1Boundary Protection [CUI Data]operational
The file server has a public IP for the vendor VPN endpoint; boundary protection relies on host firewall alone.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.14.6Monitor Communications For Attacksoperational
Inbound and outbound traffic is not monitored for indicators of attack; only firewall logs are kept.
1/3 milestonestarget 2026-10-18owner Demo assessor (read-only) - 3.13.16Data At Restoperational Closed
Weekly hardening run failed BITLOCKER-ALL-VOLUMES on NWD-FS01: the page file had been moved to an unencrypted data volume during the July storage expansion. CUI paged to disk was at rest outside the encrypted volume.
4/4 milestonestarget 2026-09-01owner Demo assessor (read-only)