CMMC Gap & POA&M Tracker
Owned by the compliance lead and updated by whoever is named as responsible on each row, this tracker produces the single register of every deficiency found against NIST SP 800-171 Rev 2, what will be done about it, who will do it, what it depends on, when it is due and what evidence will show it is closed. It is where the readiness checklist and the policy matrix send their gaps, and it is the working source for the Plan of Action and Milestones (POA&M) that your System Security Plan (SSP) refers to.
- 01
Give every deficiency an ID that will never change (G-001, G-002 …). References from meeting notes, tickets and the SSP will use it.
- 02
Name the requirement by identifier (for example IA.L2-3.5.3), not by family alone. A gap against a family is not specific enough to close.
- 03
Write the remediation activity as something a person can start on Monday: "enable MFA for the 6 remaining VPN accounts and remove the exception group", not "improve authentication".
- 04
Record dependencies honestly: budget approval, a vendor change, a production window, another row in this tracker. Most missed dates are missed dependencies.
- 05
Update Status from a fixed list: open, in progress, blocked, closed pending evidence, closed. A row is closed only when the Supporting evidence column names an artefact that exists.
- 06
Review the tracker at a set cadence, weekly while remediation is active, and keep the dated snapshots.
2 working tables, 1 checklist, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- Gap and POA&M register
- Status summary
- Count at each review
- Review questions
- At every tracker review
- Group deficiencies by root cause (missing procedure, unmanaged asset class, provider gap) and fix the cause once rather than the symptom several times.
- Reflect the open items in the POA&M your SSP refers to, and confirm against 32 CFR 170.21 which of them may remain open at assessment.
- As rows close, prove them: record the artefact for each in the CMMC Evidence Collection Tracker (CMMCg-R008).
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.