What Is a System Security Plan? | Everything You Should Know

System Security Plan (SSP) diagram showing cybersecurity controls, compliance requirements, and risk management for CMMC and NIST SP 800-171.

A system security plan often shortened to SSP  is a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements. For CMMC Level 2, those requirements come from the 110 controls in NIST SP 800-171, and the SSP isn’t a form you fill out once. It’s a living document that has to match what’s actually happening in your environment, because an assessor will check both during an audit. 

A lot of owners hear “system security plan” and picture something like a permit fill it out, file it, done. That’s not what an SSP is, and treating it that way is exactly how shops end up with a document that says one thing while their network does another. 

Related Topic: What Is a POA&M? Complete Guide for Defense Contractors

Why the SSP Is the Document Everything Else Points Back To?

Every other piece of CMMC documentation your policies, your Plan of Action and Milestones, your SPRS score exists to support what’s written in the SSP. It’s the master record of your information security posture: your information system’s boundaries, what data lives where, who owns which piece of the environment, and which of the 110 NIST SP 800-171 security requirements you’ve actually implemented versus which ones are still open. It’s not the same thing as a security policy  a policy states the rule; the SSP documents whether your systems actually follow it. 

An assessor doesn’t grade the SSP on how polished it looks. They grade it on whether it matches reality. If your SSP says remote access requires multi-factor authentication and an assessor finds one system where it doesn’t during an audit, that’s not a formatting problem. That’s a finding. That distinction matters more right now than it used to: a March 2026 GAO report found that only about 92 organizations were authorized to conduct CMMC Level 2 assessments as of December 2025, serving roughly 200,000 defense industrial base companies that may eventually need one — and GAO flagged that DoD hasn’t fully planned for that capacity gap. With assessor availability already tight, the accuracy of your own self-assessment and SSP carries more weight, not less. 

Related Topic: FCI vs. CUI: What Every Defense Subcontractor Needs to Know

What Actually Has to Be In It?

A generic SSP template will give you section headers. It won’t give you the actual content those sections need and that’s usually where the gap shows up first. 

System Boundaries and Data Flow 

Your SSP needs to show where Controlled Unclassified Information and other sensitive data actually move through your environment  not just where you think it lives. One assessment we walked through recently found the shop had never actually mapped this out. They knew CUI came in through customer drawings and lived on the file server, but nobody had drawn the picture of how it got from the customer’s email to the file server to the machines on the shop floor that needed it. Without that diagram, an assessor has no way to verify your boundary is actually closed — and neither do you. 

Encryption — And Where It Actually Breaks Things 

NIST SP 800-171 requires FIPS-validated cryptography for protecting CUI in transit, and your SSP has to document exactly where that’s implemented. Here’s the part most shops don’t find out until they’re mid-assessment: enforcing FIPS-validated cryptography on a VPN can break other things running in your environment. We’ve seen it stop QuickBooks from launching. We’ve seen it cause problems with certain remote monitoring tools. A well-built SSP documents exceptions, explains their justification, and identifies compensating controls instead of leaving compliance gaps unaddressed.

Training That’s Actually Tied to CUI — Not Just Generic Phishing Awareness 

A yearly “don’t click suspicious links” training satisfies almost nothing under NIST SP 800-171. The requirement is role-based: people who handle CUI need training specific to that responsibility, on a documented annual cycle, and your SSP needs to show who got what training and when. General security awareness training is good practice. It is not the same requirement, and assessors know the difference. 

Proof That Separation of Duties Is Real, Not Just Written Down 

If your SSP says HR and IT responsibilities are separated — that the person who can create a new user account isn’t the same person approving that request  you need something that proves it happened. An email trail. A ticket. Something dated and attributable. Writing the policy is the easy half. The evidence trail is what turns a policy statement into something an assessor can actually verify. 

The Template Problem 

A lot of shops start with a downloaded SSP template, and that’s not wrong  everyone starts somewhere. The problem is stopping there. A template gives you the shape of the document. It doesn’t know your system boundaries, your specific tools, your actual data flow, or which of the 110 requirements you’ve genuinely closed versus which ones are aspirational. A customized SSP reflects your actual environment, while generic templates quickly expose compliance gaps during security assessments.

Related Topic: Why Passing CMMC Starts With Finding the Gaps First?

What Happens to the Gaps You Haven’t Closed Yet?

No shop’s SSP shows every one of the 110 requirements fully met on day one. That’s normal, not a red flag — what matters is how you document what’s still open. The requirements you haven’t closed get tracked in a companion document, the Plan of Action and Milestones (POA&M), which lays out what’s missing, what it will take to close it, and a realistic target date. 

We helped organizations improve SPRS scores from negative 145 by documenting existing security controls and completing essential policy requirements. Having an antivirus tool but no written policy governing it costs you points you could otherwise have. The SSP documents your current security posture, while the POA&M outlines actions, timelines, and responsibilities for closing remaining security gaps.

Related Topic: CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

Who Owns This Document 

Every SSP needs a clear system owner someone accountable for keeping it accurate as your environment changes. This isn’t a document you write once during a compliance push and file away. New tools get added. Remote access policies change. Someone adds a new server. Every one of those changes needs to be reflected in the SSP, or the document you’d hand an assessor stops matching the systems it’s supposed to describe. 

What This Actually Means for Your Timeline 

Building a real SSP — one grounded in your actual system boundaries, your actual tools, and evidence you can produce takes longer than filling out a template. It’s also the clearest sign of whether your cybersecurity program is actually operating or just written down. You can confidently provide documented security evidence that satisfies customer questionnaires and prime contractor reviews without raising compliance concerns.

If you’re not sure whether what you have would survive that second question, that’s the right place to start the conversation. A CMMC-certified team can walk through your actual environment against what your SSP says, find where the two don’t match yet, and help you build a plan for closing that gap without disrupting the shop floor to do it. 

Related Topic: What Is a Passing CMMC Score and How Is It Calculated?

Frequently Asked Questions 

What does a system security plan include?

A system security plan documents system boundaries, security controls, CUI data flows, roles, responsibilities, and compliance gaps with mitigation measures.

Who is required to comply with NIST SP 800-171?

All DoD contractors and subcontractors handling Controlled Unclassified Information must implement NIST SP 800-171 security requirements.

What’s the difference between NIST SP 800-53 and NIST SP 800-171?

NIST SP 800-53 secures federal systems, while NIST SP 800-171 protects Controlled Unclassified Information in nonfederal systems.

Is a system security plan considered CUI?

Organizations often restrict SSP access because it contains sensitive security information, although it is not automatically classified as CUI.

What is the system security plan requirement for DoD contracts?

DoD contracts require an SSP to document NIST SP 800-171 compliance and support DFARS and SPRS assessment requirements.

Our Blog

ITAR vs EAR: Which Rules Apply to You?

ITAR vs EAR: Which Rules Apply to You?

 ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate…

How Manufacturers Can Strengthen Operational Technology Security

How Manufacturers Can Strengthen Operational Technology Security

Operational technology (OT) security means protecting the systems that actually run your production floor…

AS9100 Certification Guide for Manufacturers

AS9100 Certification Guide for Manufacturers

AS9100 builds on ISO 9001, adding aerospace, space, and defense requirements for risk management…