
The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework continues its phased rollout under 32 CFR Part 170. It is important for organizations to keep working toward compliance.
TL;DR – CMMC 2.0 recognizes that organizations may have security gaps during their compliance journey, but it does not allow those gaps to be ignored.
As part of CMMC compliance efforts, organizations must understand the mechanisms available to identify, manage and address cybersecurity gaps. Three critical concepts every organization should understand are Temporary Deficiencies, Enduring Exceptions and Operational Plans of Action (POA&Ms).
In cybersecurity, a temporary deficiency is a condition where remediation of a discovered security gap is feasible, meaning a known fix is available or is already in process. The key word here is temporary: the organization acknowledges the gap exists, understands how to resolve it and is actively working toward closure.
Temporary deficiencies commonly appear during the initial implementation or security requirement review. For example, during a system-wide rollout of multi-factor authentication (MFA), a limited subset of users resist or attempt to justify being exempt. This subset represents a temporary deficiency, not a permanent exemption.
Temporary deficiencies are not a free pass. They can cause the organization not to become certified. These deficiencies signal to assessors that the organization is aware of the gap and has committed resources to closing it within a defined timeframe.
An enduring exception is fundamentally different from a temporary deficiency. It is a documented acknowledgment that a specific asset cannot natively implement a required National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 security control due to hardware or firmware limitations. Critically, an enduring exception does not waive the requirement. Instead, it simply recognizes that the standard implementation path is not possible for that particular asset.
Enduring exceptions are most commonly encountered in environments with operational technology (OT), industrial control systems (ICS) or specialized equipment that cannot be upgraded or replaced without impacting mission-critical operations.
The CMMC framework provides two primary mechanisms for managing these situations: the Specialized Asset category and the Enduring Exception with a required Compensating Control. These are not loopholes. They are load-bearing elements of the framework designed for organizations running real-world operational environments.
The Operational Plan of Action and Milestones (POA&M) is the formal corrective action plan that ties everything together. It documents known deficiencies, sets milestones for remediation and provides a clear timeline for closure. The Department of War (DoW) includes POA&Ms in CMMC 2.0, recognizing that no system is perfect and that some government contractors may need additional time to remediate identified gaps.
Think of these mechanisms as a tiered approach to managing compliance gaps:
|
Concept
|
Nature of the Gap
|
Duration
|
Required Action
|
|---|---|---|---|
|
Temporary Deficiency |
Fixable gap with known solution |
Time-limited (no standard duration) |
Document in POA&M; remediate |
|
Enduring Exception |
Hardware/firmware limitation prevents native implementation |
Ongoing (reviewed periodically) |
Document in SSP; implement compensating control |
|
Operational POA&M |
Formal remediation tracking document |
180 days max for conditional certification |
Track milestones; close gaps; report progress
|
A temporary deficiency feeds into a POA&M. An enduring exception lives in the SSP with its compensating control. Both require documentation, accountability and ongoing review.
CMMC 2.0 is designed to be rigorous but realistic. The framework acknowledges that perfect compliance on day one is not always achievable,but it demands accountability, documentation and a clear path forward. Temporary deficiencies, enduring exceptions and operational plans of action are the tools the DoD provides to manage that reality.
The organizations that succeed in their CMMC assessments are those that understand these mechanisms, use them appropriately and demonstrate to assessors that security gaps are being actively managed, not ignored.
Senior Security Consultant, Compliance
GuidePoint Security