DKDavid Koran& Associates
Home The CMMC Guide Part III · Security Assessment CA.L2-3.12.2
The CMMC Guide · Security Assessment Family

CA.L2-3.12.2  Plans of Action

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

Family
Security AssessmentCA, 4 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

CA.L2-3.12.2 is the plan-of-action requirement, the control that governs how deficiencies are corrected. It requires that the organization develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in its systems, so that known gaps have a documented path to closure and are actually closed. It is a three-point requirement that cannot be deferred on a plan of action.

Assessments and scans reveal deficiencies, and a plan of action, the POA&M, is the structured way to correct them: it identifies what needs fixing, sets out how and when it will be fixed, and is then carried through. This control requires both developing those plans, so deficiencies are documented with a path to resolution, and implementing them, so the corrections actually happen. It is the mechanism by which a program moves from knowing about a gap to closing it. There is a fitting note here: this control, about plans of action, is itself one that cannot be placed on a plan of action.

The requirement · NIST SP 800-171 Rev 2, 3.12.2

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

The requirement has three parts the assessment objectives make explicit: the deficiencies and vulnerabilities to be addressed are identified, a plan of action is developed to correct them, and the plan is implemented. Identification defines what the plan covers; development produces the documented plan with corrective actions; implementation carries those actions out. Together they ensure deficiencies are not merely recorded but resolved.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.12.2 into three objectives: identify the deficiencies, develop the plan, and implement it.

[a]

Deficiencies and vulnerabilities to be addressed by the plan of action are identified. What the plan covers is known.

MeetsThe deficiencies and vulnerabilities to be addressed are identified.
FailsDeficiencies are not identified, so the plan has no defined scope.
[b]

A plan of action is developed to correct deficiencies and reduce or eliminate vulnerabilities. A documented corrective plan exists.

MeetsA plan of action is developed with corrective actions for the deficiencies.
FailsNo plan of action is developed for the identified deficiencies.
[c]

The plan of action is implemented to correct deficiencies and reduce or eliminate vulnerabilities. The corrective actions are carried out.

MeetsThe plan of action is implemented, so deficiencies are actually corrected.
FailsThe plan is written but the corrective actions are not carried out.

The three objectives are identify, develop, and implement. The common gap is at objective [c], where plans of action are written and maintained but the corrective actions are not carried through, so deficiencies persist behind a documented intention to fix them. The assessor looks for all three: identified deficiencies, a developed plan, and its implementation.

3Failure Patterns

The failures are about plans that are written but not carried out.

Plans without implementation

A plan of action that documents corrective actions but is never carried through leaves the deficiencies open. Implementation is what closes them.

Deficiencies not identified

Without identifying the deficiencies and vulnerabilities to address, the plan has no defined scope. Identification sets what the plan covers.

No structured plan

Correcting deficiencies ad hoc, without a documented plan of action, makes progress hard to track and closure hard to show. A developed plan gives the correction structure and accountability.

The common root
This control fails when the plan becomes the endpoint rather than the roadmap. Writing a plan of action is straightforward; carrying it through takes sustained effort, so deficiencies can sit behind a documented intention to fix them. Implementing the plan is what turns the intention into a closed gap.

4Ownership

This is a security and compliance-owned control with IT executing the corrections.

RoleResponsibility for this control
Security or compliance leadIdentifies deficiencies and develops the plans of action. Owns the plan of action records.
IT and system administratorImplements the corrective actions in the plan.
Program leadTracks the plan to closure and confirms corrections are carried out.
See also: This control acts on the deficiencies found by CA.L2-3.12.1 and connects to the vulnerability remediation of RA.L2-3.11.3.

5Tooling

The control is delivered by a plan-of-action process that identifies, plans, and closes deficiencies.

ObjectivesToolingWhat it provides
[a]Deficiency identificationThe scope of what the plan addresses.
[b]Plan of action documentDocumented corrective actions.
[c]Corrective action execution and trackingImplementation of the plan to closure.

The caveat is that the plan has to be implemented, not just developed and maintained. A well-documented plan of action that never drives corrective action leaves the deficiencies open. The assessor examines all three objectives, so identification, development, and implementation all have to hold.

6Evidence

The satisfied version of 3.12.2 shows plans of action developed and carried through.

EvidenceWhat it demonstrates
Identified deficienciesObjective [a]. What the plan addresses.
Plan of action documentObjective [b]. A developed corrective plan.
Corrective action recordsObjective [c]. The plan implemented to closure.

The evidence should show identified deficiencies, a developed plan of action, and records of that plan implemented. The plan together with the corrective action records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

A plan of action is a roadmap, not a destination

Writing a plan is easy; carrying it through is the work, so this three-point control asks that deficiencies be identified, planned, and actually corrected. Building a plan-of-action process that closes gaps is part of the onsite readiness work this practice does, and fittingly, this control about plans of action is itself one that cannot be deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.12.2[a] through 3.12.2[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.2 among the three-point basic security requirements. ecfr.gov
← Previous in Security Assessment
CA.L2-3.12.1 · Assess Security Controls
Next in Security Assessment →
CA.L2-3.12.3 · Monitor Security Controls
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CA.L2-3.12.2 · Edition 2026.1 · Last reviewed July 12, 2026