Identification
Auto-assigned. Must stay unique and consistent across submissions.
Description, source and detection date are copied from the finding.
A short description of the weakness. For scan findings, use the plugin/vulnerability title.
Full description of the weakness and any other relevant detail from the assessment.
SC-8 SC-13
Detection Source
Plugin or vulnerability ID, where applicable.
Must match the corresponding unique asset IDs in the Integrated Inventory Workbook.
Risk & Schedule
Leave blank unless a risk adjustment was approved.
Auto-calculated from the risk rating — moderate findings get 90 days.
Remediation windowsHigh and critical: 30 days from discovery · Moderate: 90 days · Low: 180 days. Changing the risk rating recalculates the scheduled completion date.
Ownership & Remediation
Especially important where remediation extends beyond the standard window.
Vendor Dependency & Deviations
CISA BOD 22-01
Additional Information
Attach supporting documents
Scan output, screenshots, change records · up to 100 MB each
Fields marked * are mandatory in the FedRAMP POA&M template.
Completeness
72%
Mandatory fields13 of 18
Situational fields4 of 10
Remaining mandatory:
Remediation plan Resources required
Milestones

Break the remediation plan into dated milestones. You can also add them after the item is created.

Update gateway cipher policy Due 2026-09-12 · M. Patel
Rescan and capture evidence Due 2026-10-24 · T. Nguyen
Template Guidance

Every risk identified in the SAR Risk Exposure Table needs a matching POA&M item. During continuous monitoring only past-due scan risks must be tracked, but all 3PAO assessment risks belong in the authorization package submission.

Open the field reference