The SSP is the central document for a CMMC assessment. NIST SP 800-171 Rev 2 § 3.12.4 establishes the SSP as a security requirement in its own right (CA.L2-3.12.4), and the CMMC Assessment Scope, Level 2 (v2.13) adds scope-documentation requirements that map directly into the SSP.
There is no required SSP format
The rule does not prescribe a specific layout, software, or template. What matters is that the SSP covers the required content thoroughly and is usable by an assessor. A docx file is the most practical format because it supports tables, change tracking, and the kind of reviewer mark-up assessors use.
Required content per NIST SP 800-171 Rev 2 § 3.12.4
The SSP shall describe:
- The system boundary. What is included in the in-scope environment.
- The environment of operation. Physical and logical context.
- How security requirements are implemented. One entry per practice, describing implementation or referencing where it is described.
- The relationships with or connections to other systems, including external service provider services.
Write implementation statements at the assessment-objective level
Assessors evaluate against the assessment objectives in NIST SP 800-171A. Each of the 110 practices breaks down into multiple discrete objectives that the assessor must determine MET or NOT MET. Writing the SSP implementation statements at the objective level (rather than just the practice level) means:
- The assessor can map your implementation directly to the objectives they have to evaluate.
- You catch gaps in your own implementation before the assessor does. An objective without a corresponding implementation statement is a missing control.
- You make the assessment faster, which reduces both the cost and the chance of misinterpretation.
Required content per the CMMC Scoping Guide
From the L2 Scoping Guide, the OSA must additionally document:
- The asset inventory. Every CUI Asset, Security Protection Asset, CRMA, and Specialized Asset documented. The asset inventory may be a separate workbook, but the SSP must reference it.
- The treatment of each asset category in the SSP. What controls apply, what is inherited from ESPs, what is risk-managed.
- The network diagram of the CMMC Assessment Scope, provided to the assessor during pre-assessment scoping discussions.
- The ESP relationships, service descriptions, and Customer Responsibility Matrix (CRM) for every ESP that touches the assessment scope.
Practice-level documentation, written objective-by-objective
For each of the 110 NIST SP 800-171 Rev 2 practices, the SSP must describe:
- How the practice is implemented, with a separate implementation statement for each assessment objective in NIST SP 800-171A.
- The responsible role or team.
- The supporting policy and procedure references.
- Where applicable, the inheritance from an ESP (referencing the CRM).
- For practices not yet fully implemented, the gap and the POA&M item identifier.
Common SSP failures at assessment
- Generic implementation statements. "We have a policy" is not an implementation statement. The assessor needs to know how the practice operates: product names, settings, frequencies, responsible roles.
- Implementation statements at the practice level only. If the assessor has to map your single statement to multiple objectives themselves, they will, and the gaps will surface as findings. Write one implementation statement per assessment objective.
- Missing ESP CRM references. An ESP listed without a CRM, or a CRM that does not allocate every practice the ESP claims to provide, is a finding.
- Stale network diagrams. Diagrams drawn 18 months ago for a different scope are a credibility problem before the technical assessment even starts.
- Asset inventory that does not match the network diagram. Assessors cross-reference these in the first hour.
- No identification of CRMAs. Many SSPs omit the CRMA section entirely, either because the contractor does not have any or because they have not identified them. The Scoping Guide requires the CRMA category to be addressed.
Sources
- NIST SP 800-171 Rev 2, § 3.12.4 (CA.L2-3.12.4), System Security Plan. link
- NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. Assessment objectives. link
- CMMC Assessment Scope, Level 2 (v2.13). OSA documentation requirements. link
- 32 CFR Part 170, § 170.16; § 170.17; § 170.19. link
Get the SSP template I use on engagements.
The CMMC Compliance Engine includes the System_Security_Plan.docx template, structured around the assessment objectives in NIST SP 800-171A.
Get the CMMC Compliance Engine