Hands highlighting financial documents on a desk

How to Enter a POA&M in eMASS: A Practical Walkthrough

·

·

Once you know how to write a good finding, the next question every ISSO hits is how to enter a POA&M in eMASS so it actually tracks, ages correctly, and survives an assessor’s review. eMASS is where the DoD’s POA&Ms officially live — not the spreadsheet on your desktop — and the tool has its own required fields, milestone structure, and status logic. This is the field-by-field walkthrough: what each field wants, how to set milestones and completion dates, and how to keep entries from silently going overdue.

If you haven’t nailed the underlying writing yet — what a defensible weakness description and milestone chain look like — read how to write a POA&M first. This post is about getting that content into eMASS correctly.

What a POA&M Is in eMASS (vs. a Spreadsheet POA&M)

A spreadsheet POA&M is a working draft; the eMASS POA&M is the record of authority. When you enter a POA&M item in eMASS, it links directly to the failed control and its assessment result, it drives the system’s risk posture that the AO sees, and its scheduled completion date is what the aging clock runs against. That linkage is the whole point — an eMASS POA&M item isn’t a standalone note, it’s tied to the control that generated it, so closure evidence traces cleanly back to the finding. Many teams still draft in a tracker first and transcribe into eMASS once the entry is solid, which is smart because eMASS entries are visible to reviewers the moment they exist.

Creating a POA&M Item — Every Required Field

From the system’s POA&M module, you create a new item and populate the standard fields. Here’s what each one actually wants:

eMASS fieldWhat to put there
Control / APLink the item to the specific security control and assessment procedure that failed — this is what makes closure traceable
Weakness descriptionYour translated, system-specific description — assets, control, what’s deficient — not raw scanner text
Source of weaknessAssessment finding, ACAS scan (date + plugin), or STIG rule ID that identified it
Severity / raw & adjusted riskPulled from the actual finding; adjusted risk reflects your mitigations
Resources requiredHonest labor, funding, or tooling needed — “existing resources” only if true
Scheduled completion dateDriven by the milestone chain, not chosen to look good
MilestonesDiscrete, dated, verifiable steps (detailed below)
Comments / mitigationsWhat’s reducing the risk right now — what the AO is actually accepting

Setting Milestones and Scheduled Completion Dates

In eMASS, milestones are structured records with their own descriptions and dates — not one free-text blob. Add three to five milestones per item, each a verifiable event (“Patch validated by rescan on all 14 hosts”), each with its own date. The scheduled completion date for the whole item should equal the date of the final milestone; if it doesn’t, a reviewer will notice the arithmetic doesn’t add up.

The completion date field is the one eMASS watches. Every item carries a scheduled completion date, and eMASS compares it to today’s date to decide whether the item is on track or overdue. That single field drives most of your POA&M pain, which is why the next section matters more than any other.

Linking Findings to Controls and Test Results

The strength of eMASS is the linkage, so use it. When you enter the item, associate it with the control’s assessment procedure that was marked non-compliant. When you later remediate, you update the test result and attach closure evidence — a rescan, a screenshot, a config export — in the same lineage. An item that isn’t linked to its control, or whose closure evidence doesn’t tie back to the original finding, is exactly the kind of loose end that turns a routine review into a painful one. I’ve seen unlinked, orphaned items linger for years because nobody could reconstruct what they were even for.

Managing Overdue POA&Ms and AO Risk Acceptance

An overdue POA&M in eMASS is one of the fastest credibility killers there is — it signals an unmanaged package. The move is to manage the date before it goes red: when a milestone is going to slip, update the milestone and the scheduled completion date with a documented reason first, not after the assessor flags it. A slipped-but-explained item is normal risk management; a silently overdue one reads as neglect.

For items that genuinely can’t be closed — a fix that depends on a future funding cycle, or a legacy dependency — the path is formal AO risk acceptance, documented in eMASS, not an indefinitely extended completion date. Keeping all of this current is exactly the discipline the continuous monitoring checklist builds into your weekly rhythm so nothing ages out unnoticed.

Draft your POA&Ms before they hit eMASS

Entering clean items is far easier when you’ve drafted them somewhere forgiving first. The POA&M Tracker ($37) mirrors the eMASS fields — weakness, source, milestones, scheduled completion, aging flags — so you transcribe finished entries instead of composing them live in the system of record.

Keeping Your POA&M Audit-Ready

  • Link every item to its control and finding. Orphaned items are the ones that never close.
  • Match the completion date to the last milestone. Mismatches read as sloppy tracking.
  • Update dates before they go overdue, with a documented reason — never let eMASS flag it first.
  • Attach closure evidence in the same lineage as the finding, so a reviewer can trace open → fixed → verified without asking you.
  • Use formal AO risk acceptance for items that can’t close, instead of endlessly pushing the date.

Final Thoughts

Knowing how to enter a POA&M in eMASS is mostly about respecting two things: the linkage to the control that generated the finding, and the scheduled completion date that eMASS uses to judge whether you’re managing the item. Get the content right in a draft, transcribe it into eMASS with clean links and honest dates, and keep the dates ahead of the aging clock. Do that and your POA&M module becomes the part of the package that proves your program works — not the part you dread opening.

Babux, active DoD ISSO and author of RMF Insider

From a working DoD ISSO

Trying to break into cybersecurity?

Zero to Hired is the week-by-week 6-month plan I give people who ask me how to get their first cyber job. Already in the field? The RMF Checklist is the tool I use on real ATO packages.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading