For risk register vs POA&M for CUI RFPs, use the risk register to record, evaluate, prioritize, and disposition risks to CUI-related operations, assets, and people; use a Plan of Action and Milestones (POA&M) to manage specific remediation work for risks or control gaps that require corrective action. Under NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice RA.L2-3.11.1, the risk register is the stronger evidence that periodic risk assessment occurred, while a POA&M proves that approved treatment activities have owners, dates, and measurable completion criteria. A POA&M does not replace a documented risk assessment, and not every accepted risk needs a POA&M.
What is a risk register, and what is a POA&M?
What does a risk register document?
A risk register is the management record of identified risks, their causes, affected assets or functions, likelihood, impact, assigned owner, treatment decision, and review status. It is the output or working record of a risk assessment process. For RA.L2-3.11.1, it should show that the organization assessed risks resulting from systems that process, store, or transmit Controlled Unclassified Information (CUI), using defined criteria and at a defined frequency.
For example, Northline Engineering Group, a 185-person engineering and design services firm, receives CUI-bearing site specifications from federal-prime customers through Microsoft 365 GCC High. Engineers download approved documents to an on-premises Autodesk Vault environment, create design packages, and return deliverables through the customer-approved collaboration channel. During its annual risk assessment, Northline records the following risk in its ServiceNow Integrated Risk Management register:
- Risk: A compromise or extended outage of the remote-access gateway could expose CUI design files or prevent engineers from accessing Vault during a contract delivery period.
- Threat sources: Credential theft, VPN appliance vulnerability, Internet service interruption, or administrator error.
- Affected interests: Contract delivery function, CUI confidentiality, customer trust, and the firm’s reputation as a reliable federal subcontractor.
- Inherent rating: Likelihood 3 of 5 and impact 5 of 5, for a high inherent risk score of 15.
- Treatment decision: Mitigate through phishing-resistant multifactor authentication, quarterly gateway configuration review, and tested alternate remote-access procedures.
- Residual rating: Likelihood 2 of 5 and impact 4 of 5, accepted by the Chief Information Security Officer after treatment is complete.
That entry demonstrates risk thinking: it connects a system, CUI workflow, threat sources, likelihood, operational impact, and a management decision. A vulnerability scan identifying an outdated VPN component can inform this analysis, but the scan itself is not the RA.L2-3.11.1 risk assessment.
What does a POA&M document?
A POA&M is a tracked remediation commitment. It describes a deficiency or risk-treatment action, the planned milestones, accountable owner, resources, due date, status, and evidence needed to close the item. A POA&M is particularly useful when the selected risk response is mitigation and the corrective work cannot be completed immediately.
Using Northline’s remote-access example, the firm may open a POA&M in Jira Service Management after the risk assessment finds that administrators still use Microsoft Authenticator push notifications rather than phishing-resistant authentication for privileged VPN administration. The POA&M is not simply “reduce VPN risk.” It should identify the discrete corrective work:
- POA&M ID: POAM-2026-014.
- Weakness: Privileged administrators of the Palo Alto GlobalProtect VPN do not yet use FIDO2 security keys.
- Milestone 1: Enroll eight privileged administrators in Microsoft Entra ID authentication methods policy requiring FIDO2 keys by August 15, 2026.
- Milestone 2: Change the Conditional Access policy for the
VPN-Privileged-Adminsgroup to require phishing-resistant MFA by August 29, 2026. - Milestone 3: Validate authentication logs in Microsoft Sentinel and retain test results by September 5, 2026.
- Closure evidence: Exported Conditional Access policy, Entra sign-in logs, test record, and security manager approval.
The risk register retains the broader management decision and residual risk. The POA&M tracks the work necessary to make the mitigation real.
How does risk register vs POA&M for CUI RFPs affect proposal evidence?
| Comparison point | Risk register | POA&M |
|---|---|---|
| Primary purpose | Documents risk identification, analysis, evaluation, and treatment decisions. | Tracks corrective actions and milestones for unresolved weaknesses or mitigation tasks. |
| Primary RA.L2-3.11.1 value | Shows that risks to operations, assets, individuals, reputation, and CUI systems were assessed. | Shows that selected remediation actions are governed and followed through. |
| Typical trigger | Annual assessment, defined periodic review, major system change, new CUI workflow, significant incident, or material supplier change. | A risk response requires work not yet complete, or an assessment identifies a control deficiency. |
| Required content | System or process, threat, vulnerability or condition, likelihood, impact, score, owner, response, residual risk, review date. | Weakness, corrective action, milestones, accountable owner, target dates, status, dependencies, closure evidence. |
| Example tool record | ServiceNow IRM risk RISK-00482: Vault remote-access compromise, inherent score 15, residual score 8. |
Jira Service Management POAM-2026-014: require FIDO2 for VPN privileged administrators by September 5, 2026. |
| Can it be closed by management acceptance? | Yes. A documented acceptance, transfer, avoidance, or mitigation decision may close the assessment cycle while retaining the risk for review. | Only when the planned action is complete, cancelled with documented authority, or superseded by an approved disposition. |
| Common proposal error | Calling a list of scan findings a “risk register” without likelihood, impact, and business consequences. | Presenting a POA&M as proof that controls are implemented when it actually shows work remains open. |
Where do teams confuse these records under RA.L2-3.11.1?
The most frequent confusion is treating a POA&M as the risk assessment itself. A proposal team may find a detailed POA&M with due dates and assume it satisfies RA.L2-3.11.1. It does not, unless the organization can also show the defined assessment frequency, documented assessment criteria, scope of CUI-related systems, assessed impacts, likelihood analysis, and management risk decisions. A POA&M explains what the organization intends to fix; the risk assessment explains why the issue matters and what risk remains.
The opposite mistake is equally common: maintaining a well-written register but never tracking mitigation work to completion. If an assessment identifies a high risk involving CUI processing and management chooses mitigation, assessors expect evidence that the chosen response is being executed. A POA&M, change ticket, project plan, or equivalent governed record can provide that evidence. For proposal purposes, a POA&M is often the clearest artifact because it associates milestones and closure evidence with a responsible official.
Assessors reviewing CMMC Level 2 evidence for RA.L2-3.11.1 generally look for more than a spreadsheet labeled “risk register.” They will want to see that the organization has defined how often it performs risk assessments, such as annually and after significant changes to CUI systems or workflows. They also expect a completed assessment showing risk to organizational operations, assets, and individuals—not merely technical findings. The assessment should address plausible sources of risk, including human error, malicious insider or external action, system failure, technology failure, supply-chain disruption, and external events.
Consider a second Northline example. The firm plans to introduce a new managed print service for large-format CUI design drawings. A vulnerability assessment may verify printer firmware and network exposure, but the RA.L2-3.11.1 assessment must also consider whether print-release workflows could send CUI to the wrong device, whether the service provider’s technicians could access stored jobs, and whether a print outage would delay a time-sensitive deliverable. The risk register records the full operational assessment. If the assessment finds that secure release printing is not enabled, the POA&M can track enabling badge release, disabling local job retention, testing the configuration, and obtaining evidence from the managed service provider.
How should a proposal writer describe the distinction?
Write to the RFP requirement without overstating maturity. If the organization has completed its risk assessment and maintains a register, say so directly. If remediation is still underway, identify it as an open POA&M and describe the approved target date and interim safeguards. Do not convert a future milestone into a present-tense compliance claim.
Our organization performs a documented enterprise and CUI-system risk assessment annually and upon significant changes to CUI processing environments. Assessment results are recorded in the risk register using defined likelihood and impact criteria. Risks requiring corrective action are assigned to controlled POA&Ms with accountable owners, milestones, target dates, and closure evidence; accepted residual risks are approved by designated management officials and reviewed during the next assessment cycle.
This language gives an evaluator the evidence chain they need: frequency, scope, assessment output, treatment governance, and management accountability. Attach or reference sanitized examples only when the RFP permits it, and ensure dates, system names, and open-item status match the proposal’s current submission date.
What is the bottom line for a compliant response?
The verdict is simple: use the risk register to satisfy the core assessment and decision-making evidence for RA.L2-3.11.1, and use a POA&M whenever a chosen mitigation has outstanding, trackable work. In the risk register versus POA&M distinction, neither artifact substitutes for the other: the register explains the risk to mission, operations, assets, reputation, and individuals, while the POA&M proves the organization is managing the corrective path without disguising an open gap as completed compliance.
Before submitting the RFP response, map each RA.L2-3.11.1 claim to the current risk assessment, relevant register entries, and any open or recently closed POA&M evidence.