What Is a System Security Plan (SSP)? The Document Your CMMC Assessment Can't Start Without
Plain-English guide to the System Security Plan for small federal contractors: what NIST SP 800-171 requirement 3.12.4 actually demands, what goes in an SSP, who needs one, the mistakes that sink small shops, and how the SSP connects to your SPRS score and POA&M.
The one-sentence version
A System Security Plan (SSP) is the document that describes which systems in your company touch federal data, and how each of the 110 NIST SP 800-171 requirements is implemented on those systems — and under the DoD's own assessment methodology, no SSP means your assessment cannot be conducted at all. Not a low score. No score.
That makes the SSP the single most load-bearing document in a small contractor's compliance stack, and the one most small shops don't have.
Why this matters now
If you handle Controlled Unclassified Information (CUI) under a DoD contract, DFARS 252.204-7019 and 7020 require a current NIST SP 800-171 self-assessment score in SPRS — and that assessment is conducted against your SSP. The methodology scores what your SSP says you do, verified against reality. Even with CMMC Phase 2 suspended, the self-assessment obligation never paused, which means the SSP obligation never paused either.
Primes have caught on. Supplier questionnaires increasingly ask, straight out: "Do you have a current System Security Plan?" — because that's how a prime tests whether your SPRS number is real or typed in on a Friday afternoon.
What an SSP actually is (and isn't)
NIST SP 800-171 requirement 3.12.4 says it plainly: develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
In practice, an SSP is four things stapled together:
- A boundary. Which computers, servers, cloud services, and people are inside the environment that touches federal data — and, just as important, which are outside it.
- An environment description. What that in-scope environment looks like: your office network, Microsoft 365 or GCC High tenant, the CAD workstation with the drawings on it, who administers what.
- 110 implementation statements. For each 800-171 requirement: how you meet it, in your environment, with your tools. Not "the organization shall configure session locks" — that's a policy. An SSP statement reads more like: "Workstations lock after 10 minutes via Intune policy X; verified quarterly."
- Connections. What the environment talks to — the prime's portal, your MSP's remote-management tool, a cloud backup service.
What an SSP isn't: a policy binder. Policies say what your company intends and requires; the SSP says what one specific system environment actually does. Assessors want both, and they check that the two agree.
Do you need one?
| Your situation | SSP required? |
|---|---|
| FCI only — CMMC Level 1 / FAR 52.204-21 | Not formally required — but a short one makes your annual self-assessment far easier to defend |
| CUI in scope — CMMC Level 2 / DFARS 7012 | Yes. Requirement 3.12.4, and the precondition for any SPRS score |
| Bidding on work that would bring CUI | Effectively yes — primes ask for it during teaming, before award |
The trap for small contractors is the second row arriving unannounced: a prime flows down DFARS 252.204-7012, a drawing package lands in your inbox, and you're a CUI handler with no SSP describing the environment it landed in.
The mistakes that sink small shops
Scoping the whole company. If your SSP says the boundary is "everything," then every laptop, the front-desk PC, and the owner's phone are all in scope for all 110 requirements. Small contractors that pass keep the CUI environment small — a handful of machines, one enclave, one cloud tenant — and document that boundary tightly.
Describing aspirations as implementations. The SSP is what your SPRS score is built on, and the score you affirm is a legal representation to the government. "We will deploy MFA in Q3" written as "MFA is deployed" is how a compliance gap becomes a False Claims Act problem. Write what's true today; put the rest in your POA&M.
Buying a template and changing the company name. Assessors and primes have seen every 200-page boilerplate SSP on the market. One implementation statement that mentions a firewall brand you don't own does more damage than a short, accurate document ever could.
Letting it rot. 3.12.4 says periodically update. An SSP describing the server you decommissioned two years ago tells an assessor exactly one thing: nobody looks at this document.
How big does it need to be?
Right-sized for a 10-person machine shop with a tight boundary: often 30–60 pages, most of it the 110 implementation statements at a paragraph or less each. Page count is not the goal — an assessor would take 35 accurate pages over 200 aspirational ones every time.
SSP, POA&M, SPRS: how the three fit
- The SSP says how each requirement is implemented — or honestly says "not yet."
- Every "not yet" becomes a line in the POA&M (Plan of Action & Milestones): who fixes it, how, by when.
- The SPRS score is the arithmetic across all 110: implemented per the SSP earns the points, POA&M items subtract theirs (most requirements are worth 1, 3, or 5 points on the −203 to 110 scale).
One document describes, one plans, one scores. Assessors read them together and check that they tell the same story.
Where CyberPolicify fits
The reason SSPs don't get written is that requirement #47 of 110 is where humans give up. CyberPolicify inverts the order of work: you run the guided Level 2 self-assessment — all 110 requirements in plain English, with a live estimated SPRS score on the official DoD scale — and the platform builds the SSP from your actual assessment answers, alongside the POA&M and SPRS submission package, on the Professional plan. The assessment itself is on every plan, so you can know your number and see your gaps before spending anything on documentation.
Bottom line
The SSP is not paperwork for its own sake — it's the precondition for your SPRS score, the first document a prime or assessor requests, and the place where honest scoping saves small contractors real money. Keep the boundary small, write what's true, update it when the environment changes, and let the POA&M carry what isn't finished yet.
Generate documentation mapped to frameworks
Generate policies, procedures, and gaps you can act on—without consultant-heavy overhead.