Skip to content
ControlVerdict
CA.L2-3.12.2CMMC Level 2Level 2

Operational Plan of Action

Practice statement

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.12.2.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(3)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    deficiencies and vulnerabilities to be addressed by the plan of action are identified;

    1 example covers this

  2. [b]

    a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities; and

    1 example covers this

  3. [c]

    the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    CA.L2-3.12.2Operational Plan of Action
    Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
    • [a]

      deficiencies and vulnerabilities to be addressed by the plan of action are identified;
    • [b]

      a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities; and
    • [c]

      the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

    Every POA&M item carries an owner, a funding line, and a closure test

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all Operational Plan of Action objectives: identifying the deficiencies and vulnerabilities to address, developing the plan, and implementing it.

    Identifying deficiencies. Four intake channels feed one register: control assessment findings, vulnerability scan results that cannot be patched inside the SLA, incident after-action items, and external audit or customer findings. Each item records the source, the practice or objective affected, and the risk if left open. Duplicates are merged so a single root cause does not appear as five items.

    Developing the plan. An item is not accepted into the register without: a named accountable owner (a person, not a department), the corrective action described concretely enough to test, a resource estimate, a scheduled completion date, and any interim compensating control. Items needing capital carry a budget line reference; that is why the CFO attends the review, and it is why dates in this register tend to hold.

    Implementing. Corrective actions execute through normal change management with the ticket linked to the register item, so the work leaves the same audit trail as any other change. Milestones are updated monthly; a slipped date requires a written reason and a new date approved by the ISSO, and slipping twice escalates to the executive sponsor.

    Closure. An item closes only after a closure test performed by someone other than the implementer, with the test result attached. Closure without evidence is not permitted by the workflow.

    Maintenance. Monthly review of all open items; quarterly trend report on aging and on how many items were found internally versus externally. Long-lived items are re-risk-rated rather than left to drift.

    Accepted gap. One legacy manufacturing execution system cannot be brought to the endpoint baseline until it is replaced, which is a multi-year capital project. It remains an open register item with network isolation and enhanced logging as the documented compensating control, re-approved by leadership annually.

    What the evidence looks like

    • POA&M register export showing source, owner, milestone, and status for open items
    • Two closed items with the independent closure test attached
    • Change ticket linked to a corrective action
    • Monthly review minutes including the funding decisions
    • Compensating control approval for the long-lived legacy item

    Environment

    Aerospace subcontractor, ~500 staff. Deficiencies arrive from self-assessment, vulnerability scanning, incidents, and customer audits; the ISSO reviews the register monthly with the CFO because most fixes need money.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.