Your System Security Plan (SSP) is the first thing a CMMC assessor reads. It describes your environment and lays out how you meet each of the 110 NIST SP 800-171 controls. When it’s solid, the assessment goes smoothly. When it’s not, you’ve basically handed the assessor a checklist of gaps to go dig into.
Here’s what your SSP has to cover and why it’s the one part of CMMC you can’t push down the road.
The SSP isn’t paperwork for the auditor’s benefit. It’s the document they grade you against. A C3PAO won’t inspect your network cold; they read your plan first, then check whether your systems actually match what it claims. If a control isn’t written down, they treat it as not done.
And it covers a lot of ground: your system boundary, every system that touches CUI, your network architecture, how each control is met, and who owns what. NIST 800-171 breaks the 110 controls into 320 assessment objectives, and the SSP is where you show you meet them.
You Can’t Defer the SSP
Plenty of contractors plan to fix gaps later with a POA&M. That doesn’t work for the SSP.
Under the CMMC rule (32 CFR 170.21), the SSP requirement CA.L2-3.12.4 is one of a small set of controls that can never go on a POA&M. A few others are off-limits too, along with any control worth 3 or 5 points, such as multi-factor authentication. And to reach Conditional Level 2 at all, you need a score of at least 88 out of 110, with the SSP fully done and matching your real environment before the assessor shows up.
You can find an SSP template online. It won’t pass on its own.
Assessors have read hundreds of them, and placeholder language gives it away. “Access control is enforced through role-based policies” tells them nothing they can verify. A template with half the blanks filled is a red flag. Your SSP has to name the actual systems, configurations, tools, and people. Generic plans get flagged because they describe a generic company instead of yours.
Keep It Current
The SSP isn’t one-and-done. Your certification runs three years, with an annual affirmation that you’re still compliant and that affirmation is a formal statement to the government, backed by your SSP.
So when something changes and the plan doesn’t keep up with a new system, a reconfiguration, someone leaving you ends up with a gap between what you claimed and what’s actually true. That’s where False Claims Act exposure starts. Build SSP updates into your normal change process instead of scrambling before each review.
The hard part is that an SSP is only as accurate as the environment behind it. Somebody has to scope your CUI boundary, understand your architecture, and know how each control is really implemented. And when a control your plan needs to claim isn’t in place yet, somebody has to build it before you can honestly write it down. That’s engineering, not writing.
That’s how we work at Rudram. Our Registered Practitioner scopes your boundary and writes an SSP mapped to your real systems. And because we’re a systems engineering firm with 18+ years in the Defense Industrial Base with NASA, Raytheon, and the U.S. Air Force Academy among our clients when a control needs to be built before your plan can claim it, our engineers handle that too. One team writes the plan and stands up the environment it describes.
No. Under 32 CFR 170.21, the SSP control (CA.L2-3.12.4) can’t be deferred. It has to be complete and accurate at the time of your assessment.
A template can help with structure, but it won’t pass on its own. Assessors read the SSP against your actual environment, and placeholder text is a red flag.
At least 88 out of 110 (80%) for Conditional Level 2, with all required controls including the SSP met. POA&Ms only cover certain 1-point gaps, and you have 180 days to close them.
Schedule Your Free CMMC Readiness Assessment with Rudram’s Registered Practitioner
Rudram Engineering, Inc. | Rockledge, FL | Serving the Defense Industrial Base for 18+ years | Trusted by NASA, the U.S. Air Force Academy, and Raytheon