Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

POA&M (Plan of Action and Milestones)

A Plan of Action and Milestones, usually shortened to POA&M, is a tracked record of security requirements that are not yet met, each with a named owner, a planned remediation and a target completion date. It sits alongside the System Security Plan and is a required deliverable in the CPCSC and CMMC programmes.

In practice

The POA&M is a live document rather than a submission artefact. Items close, new ones open when the environment changes, and an assessor comparing this year's to last year's will notice if the same entries have simply had their dates pushed.

The most common weakness is vagueness. "Improve logging" with an owner of "IT" and a date of "Q4" tells nobody anything. "Enable CloudTrail in the two remaining regions, owner J. Smith, 30 November" can be verified.

// how traztech helps

traztech delivers CPCSC readiness including the SSP and POA&M for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A POA&M is how you carry an unmet requirement without failing. It records what is not in place, who owns it, what the fix is and when it lands, and it is a mandatory artefact in CPCSC and CMMC rather than an optional planning document.

Assessors read the POA&M alongside the System Security Plan. The SSP says how each requirement is met; the POA&M covers the ones that are not yet. Dates that have already passed are the fastest way to lose credibility with an assessor.

POA&M (Plan of Action and Milestones): common questions

Is a POA&M an admission of failure?

No. Every real programme has open items. What matters is that each has a named owner, a specific remediation and a date that has not already gone by.

Do SOC 2 and ISO 27001 require a POA&M?

Not by that name. ISO 27001 uses a risk treatment plan and SOC 2 relies on management responses to findings, but the substance is the same: a tracked list of gaps with owners and dates.

How long can something sit on a POA&M?

In CPCSC and CMMC contexts, closure timeframes are set by the programme and some requirements cannot be POA&Med at all. Elsewhere the honest test is whether the date is real and whether it moves each time somebody looks.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.