Your CMMC Level 2 assessment stands or falls on one document: your System Security Plan. The SSP is not a checkbox exercise. It is the single artifact that proves to a C3PAO assessor that your organization actually implements the 110 security controls in NIST SP 800-171. Get it right and you have a clear path to certification.
This guide breaks down what goes into a CMMC SSP, section by section, so you can build one that reflects your actual security posture rather than a fantasy version of it.
What is a System Security Plan, and why does CMMC require one?
A System Security Plan is a formal document that describes how your organization protects Controlled Unclassified Information (CUI). Under CMMC Level 2, your SSP maps directly to the 110 security requirements in NIST SP 800-171. It is not a policy manual and not a network diagram. It is the operational blueprint that shows exactly how each control is implemented in your specific environment.
The SSP is the backbone of your assessment. When a C3PAO assessor begins, the SSP is the first document they review, and it frames the entire assessment scope. Every control narrative, every piece of evidence requested, and every interview traces back to what your SSP says you do.
Assessors evaluate three things:
- Accuracy: does the SSP describe what you actually do, not what you wish you did?
- Completeness: does every required control have a narrative that addresses the requirement?
- Specificity: are the descriptions specific to your environment, or could they apply to any company on earth?
A vague SSP signals that you do not understand your own security environment. That is not the signal you want to send.
The 7 core sections every CMMC SSP must include
NIST SP 800-171 does not prescribe a rigid SSP format, but every complete plan needs these seven sections. Missing any of them creates gaps that assessors will flag.
1. System identification and boundaries
Define what is in scope. Identify your CUI environment by name, describe the types of CUI you handle, map every data flow where CUI moves, and include boundary diagrams that show where your CUI environment begins and ends. The biggest mistake here is scoping too broadly. Define a clear CUI enclave, segment it from your general business network, and document the boundaries precisely.
2. System environment and architecture
Document every component that touches CUI: hardware inventory, software inventory, network topology, and cloud infrastructure. An incomplete inventory is a red flag that undermines confidence in every other section.
3. Security control implementation
This is the heart of your SSP. For each of the 110 NIST 800-171 controls, write a narrative explaining how you implement that control in your specific environment. Per-control narratives are more thorough and easier for assessors to review. Grouped narratives organized by control family are faster to write but create gaps unless you are disciplined about coverage. Every narrative should answer four questions: what do we do, how do we do it, what tools or processes support it, and who is responsible for it?
Not sure how many of the 110 controls you actually meet today? A free 2-minute gap check gives you a directional self-assessment (not an official SPRS score) before you write a single narrative.
Run the free gap check →4. Roles and responsibilities
Define who owns what: the system owner, the information system security officer, control owners for each family, and the executive with final authority. If your SSP says everyone is responsible for security, nobody is.
5. Interconnections and information sharing
Document every external system that connects to your CUI environment: cloud service providers and whether you inherit controls from them, third-party managed security services, partners you share CUI with, and external integrations. For each, describe the data exchanged, the protections in place, and any agreements that govern the connection.
6. Incident response and contingency planning
Cross-reference your Incident Response Plan and Business Continuity Plan rather than duplicating them. Describe how those processes integrate with your security posture, including escalation procedures for CUI incidents and recovery objectives for CUI systems. Confirm your specific cyber-incident reporting obligations under your DFARS contract clauses against current DoD guidance.
7. Continuous monitoring strategy
CMMC is not a point-in-time certification you pass and forget. Describe how you maintain compliance between assessments: how often you review control implementations, what monitoring tools you use, how you track and remediate new vulnerabilities, your process for updating the SSP when the environment changes, and your schedule for internal assessments.
Common SSP mistakes that tank assessments
- Copy-paste from templates without customization. Assessors recognize generic SSPs immediately. Templates are starting points, not finished products.
- Missing or vague control narratives. Writing that you "implement access controls" is not a narrative. Describing how you configure role-based access with conditional access policies for CUI resources is. Specificity is the difference between a pass and a finding.
- Not reflecting actual implementation. If your SSP says you enforce MFA everywhere but your VPN still uses single-factor authentication, assessors will find the gap. Your SSP must describe reality, including POA&Ms for controls not yet fully implemented.
- Ignoring inherited controls. If you use a FedRAMP-authorized cloud provider, some controls are inherited. Your SSP must clearly identify which controls are inherited, which are shared responsibility, and which are fully yours.
How AaaS platforms help you manage the SSP
Writing and maintaining an SSP manually is a significant operational burden. For small and mid-size contractors without a dedicated compliance department, keeping the SSP current as the environment evolves is where the process breaks down. That is the problem AI-as-a-Service (AaaS) platforms are built to solve, by giving your team operational leverage rather than adding headcount.
- AI-assisted control mapping and narrative drafting. Instead of staring at a blank template for weeks, the platform analyzes your environment and generates draft narratives based on your actual infrastructure. A human reviews, refines, and approves every narrative. The AI handles the heavy lifting; the authorizing official makes the decisions.
- Updates as your environment changes. When you add a server, change a firewall rule, or onboard a cloud service, the platform flags SSP sections that need revision so your documentation never drifts from reality.
- Assessment-ready documentation. Instead of a frantic scramble before your C3PAO assessment, your SSP stays current and reflects your environment as of today.
This is not about replacing your compliance team. It is about giving the people responsible for compliance the tools to manage the process efficiently, with the human always in the loop on every security decision.
If your SSP is not started, not current, or built on a generic template, the fastest first step is to see where you actually stand. Start with the free gap check, then map your real posture with the $799 CMMC Readiness Snapshot.
Source: NIST SP 800-171; DoD CMMC Program Regulatory Impact Analysis (DOD-2023-OS-0063-0003). This article is general guidance, not legal or compliance advice. Confirm regulatory citations against current NIST and DoD publications.