Understanding CMMC: Temporary Deficiencies, Enduring Exceptions and Operational Plans of Action

BLOG

The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework continues its phased rollout under 32 CFR Part 170. It is important for organizations to keep working toward compliance.

TL;DR – CMMC 2.0 recognizes that organizations may have security gaps during their compliance journey, but it does not allow those gaps to be ignored. 

  • Not all compliance gaps are the same. 
    • Temporary Deficiencies are fixable issues that require remediation, 
    • Enduring Exceptions address unavoidable technical limitations and require compensating controls.
  • POA&Ms provide accountability. They establish ownership, milestones and timelines to ensure identified gaps are actively managed and resolved.
  • Successful CMMC compliance depends on transparency and continuous improvement. Organizations must demonstrate that security gaps are documented, understood and being actively addressed, not ignored.

As part of CMMC compliance efforts, organizations must understand the mechanisms available to identify, manage and address cybersecurity gaps. Three critical concepts every organization should understand are Temporary Deficiencies, Enduring Exceptions and Operational Plans of Action (POA&Ms).

What is a Temporary Deficiency?

In cybersecurity, a temporary deficiency is a condition where remediation of a discovered security gap is feasible, meaning a known fix is available or is already in process. The key word here is temporary: the organization acknowledges the gap exists, understands how to resolve it and is actively working toward closure.

Temporary deficiencies commonly appear during the initial implementation or security requirement review. For example, during a system-wide rollout of multi-factor authentication (MFA), a limited subset of users resist or attempt to justify being exempt. This subset represents a temporary deficiency, not a permanent exemption.

Key characteristics of a temporary deficiency:

  •  The deficiency is fixable with known technology or processes
  • A remediation path has been identified and documented
  • No standard duration is prescribed; however, the deficiency must not persist beyond 180 days
  • The organization must formally document the deficiency in an Operational Plan of Action

Temporary deficiencies are not a free pass. They can cause the organization not to become certified. These deficiencies signal to assessors that the organization is aware of the gap and has committed resources to closing it within a defined timeframe.

What is an Enduring Exception?

An enduring exception is fundamentally different from a temporary deficiency. It is a documented acknowledgment that a specific asset cannot natively implement a required National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 security control due to hardware or firmware limitations. Critically, an enduring exception does not waive the requirement. Instead, it simply recognizes that the standard implementation path is not possible for that particular asset.

Enduring exceptions are most commonly encountered in environments with operational technology (OT), industrial control systems (ICS) or specialized equipment that cannot be upgraded or replaced without impacting mission-critical operations.

Key characteristics of an enduring exception:

  •  The asset has a documented hardware or firmware limitation
  • The security requirement still applies and is not waived; the organization must provide a business justification and details describing how compensating controls protect the affected asset
  • The organization must implement a compensating control to provide equivalent or comparable protection
  • The organization must document the exception and its compensating control in the System Security Plan (SSP)
  • The organization must periodically review the exception to determine whether the limitation still exists

The CMMC framework provides two primary mechanisms for managing these situations: the Specialized Asset category and the Enduring Exception with a required Compensating Control. These are not loopholes. They are load-bearing elements of the framework designed for organizations running real-world operational environments.

What is an Operational Plan of Action?

The Operational Plan of Action and Milestones (POA&M) is the formal corrective action plan that ties everything together. It documents known deficiencies, sets milestones for remediation and provides a clear timeline for closure. The Department of War (DoW) includes POA&Ms in CMMC 2.0, recognizing that no system is perfect and that some government contractors may need additional time to remediate identified gaps.

What a POA&M must include:

  • A description of the deficiency or weakness
  • The specific NIST SP 800-171 requirement or objective that is not fully met
  • Planned remedial actions to correct the deficiency
  • Responsible parties and resource allocation
  • Milestones with target completion dates
  • Current status and progress updates

Important rules for POA&Ms under CMMC Level 2:

  • An organization may earn Conditional Level 2 Certification if it meets certain criteria and uses POA&Ms for a limited number of low-impact deficiencies
  • The organization must remediate each POA&M item within 180 days of the conditional certification
  • Failure to close POA&M items within the 180-day window risks loss of certification
  • POA&Ms cannot be used for high or critical security requirements (DoD values of three or five); those must be fully met at the time of assessment
  • Organizations must update POA&Ms based on findings from security control assessments, security impact analyses and continuous monitoring activities

How These Three Concepts Work Together

Think of these mechanisms as a tiered approach to managing compliance gaps:

Concept
Nature of the Gap
Duration
Required Action

Temporary Deficiency

Fixable gap with known solution

Time-limited (no standard duration)

Document in POA&M; remediate

Enduring Exception

Hardware/firmware limitation prevents native implementation

Ongoing (reviewed periodically)

Document in SSP; implement compensating control

Operational POA&M

Formal remediation tracking document

180 days max for conditional certification

Track milestones; close gaps; report progress

A temporary deficiency feeds into a POA&M. An enduring exception lives in the SSP with its compensating control. Both require documentation, accountability and ongoing review.

The Bottom Line

CMMC 2.0 is designed to be rigorous but realistic. The framework acknowledges that perfect compliance on day one is not always achievable,but it demands accountability, documentation and a clear path forward. Temporary deficiencies, enduring exceptions and operational plans of action are the tools the DoD provides to manage that reality.

The organizations that succeed in their CMMC assessments are those that understand these mechanisms, use them appropriately and demonstrate to assessors that security gaps are being actively managed, not ignored.

Senior Security Consultant, Compliance
GuidePoint Security

Jason Spencer is a Cybersecurity Consultant with more than a decade of experience in security assessments, compliance and risk management. Since beginning his cybersecurity career in 2010, he has specialized in network security, wireless security, vulnerability management and regulatory compliance assessments across commercial, banking and federal environments. Jason has extensive experience conducting NIST 800-171 and CMMC assessments, having led and participated in more than 100 assessments since 2017. He is a Certified CMMC Professional (CCP) and also supports organizations with NIST 800-53, HITRUST, DFARS, HIPAA and PCI compliance initiatives. Additionally, Jason has served as a Qualified Security Assessor (QSA) since 2019 and is trained on PCI DSS 3.2.1 and 4.0.1. His technical expertise includes perimeter, network, wireless and firewall security assessments, database auditing, workstation reviews, social engineering and security operations support within both Network Operations Center (NOC) and Security Operations Center (SOC) environments. Jason holds a Bachelor of Arts degree in Geology with teacher certification and maintains several industry certifications, including CISSP. He has also presented at Converge in Anaheim, California.