CMMC Ready Now
Back to Knowledge Center
Documentation7 min read

System Security Plan (SSP): What It Must Contain

The SSP is the master document of your CMMC program — describing your CUI boundary, every system in scope, and how each of the 110 controls is implemented. Assessors read it first.

The System Security Plan (SSP) is required by NIST SP 800-171 control 3.12.4 and is the foundational document of your CMMC program. An assessor's first significant action in any CMMC engagement is to review the SSP.

Required SSP contents under NIST 800-171

  • System name, identifier, and operational status
  • System categorization and description of CUI types handled
  • System owner and authorizing official
  • System boundary description (what systems, networks, and locations are in scope)
  • Network topology diagram and data flow diagrams
  • System interconnections (connections to external systems, cloud services, MSPs)
  • For each of the 110 controls: implementation status and a description of how the control is implemented
  • References to relevant policies, procedures, and supporting documentation
  • POA&M reference for any controls that are not fully implemented

Common SSP mistakes

  • Incomplete boundary: describing a too-narrow CUI boundary that omits systems that actually handle CUI
  • Template boilerplate: using a downloaded SSP template without customizing the control descriptions to reflect your actual implementation
  • Stale content: an SSP that does not reflect current system configurations, cloud migrations, or personnel changes
  • Missing interconnections: failing to document MSP relationships, external cloud services, or government network connections

The SSP as a living document

Your SSP is not a one-time document you create for the assessment. It must be maintained continuously and updated whenever your environment changes. A change management process that triggers SSP updates is itself a CMMC control (CM.L2-3.4.3).

Need help building or reviewing your SSP? Our gap assessment service includes a review of your current SSP posture and delivers a documentation roadmap as part of the output.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.