Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.12.02OFFICIAL TITLEPENDING NIST SME REVIEW

03.12.02Plan of Action and Milestones

03.12 Security Assessment and Monitoring · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires developing a plan of action and milestones that documents the planned remediation of weaknesses or deficiencies found during security assessments and reduces or eliminates known system vulnerabilities, and updating the plan based on findings from assessments, audits and reviews, and continuous monitoring.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The plan of action and milestones is the honest list of what is not done yet: each weakness, what will fix it, who owns the fix, and by when. Kept current, it is the engine that turns findings into finished work. Left stale, it is written evidence that the organization knows about its gaps and is not moving on them.

Mapped practices

Brilliant at the Basics practices that support this requirement

Evidence supportModerate confidence

Why: The practice's remediation tracking — findings, owners, dates, windows held or missed — is the same shape of record a plan of action and milestones draws on for its known-vulnerability entries, so the practice's normal operation keeps that portion of the plan supplied with current, truthful input.

What this does not claim: Provides evidence relevant to the requirement rather than implementing it. A plan of action and milestones is a governance document spanning weaknesses in any security requirement, produced and updated through the assessment process; a patch queue does not become one by renaming it, and deficiencies outside vulnerability management never appear in the practice's records at all.

Practice-side activities
  • Roll remediation status for significant open vulnerabilities into plan-of-action entries with milestones
  • Feed missed-window findings into the plan's update cycle
Evidence this produces
  • Plan-of-action entries traceable to the remediation tracker
  • Update records showing vulnerability items closed with evidence

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Create entries from every finding source — self-assessments, audits, continuous monitoring — with milestones and dates that survive contact with real workloads.
  • Update on a cadence and on events: close items with evidence attached, and re-date slips explicitly rather than silently.
  • Keep per-vulnerability remediation detail in the operational tracker and roll it up — a plan with four hundred CVE rows stops being a management document.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The plan itself, with weaknesses, milestones, owners, and dates
  • Update history showing items closed with evidence and slipped items re-planned

Suggested owners, derived from the mapped practices and artifacts: IT leader / MSP · IT leader or compliance lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated