CMMC and NIST 800-171
The System Security Plan: What It Is and What Happens Without One
If you are a defense contractor or a small business handling Controlled Unclassified Information (CUI), you are required to maintain a System Security Plan (SSP) under DFARS 252.204-7012 and NIST SP 800-171 Rev 2. CA.L2-3.12.4 specifically mandates that you develop, document and periodically update your SSP. Without one, you risk more than just a failed audit, you expose your company to False Claims Act liability and may jeopardize your government contracts.
What is a System Security Plan and why is it required?
A System Security Plan is a comprehensive document that describes how your organization implements security requirements for systems storing, processing, or transmitting CUI. According to CA.L2-3.12.4, every contractor subject to NIST SP 800-171 Rev 2 must have an SSP that details the environment, boundaries, and controls in place to protect sensitive defense information.
The SSP is more than a formality. It is the starting point for your compliance program. It covers your network architecture, lists the assets in scope, and explains how each of the 110 controls from NIST SP 800-171 Rev 2 is addressed. The CMMC Scoping Guide requires that you identify asset categories, such as CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out of Scope Assets, and document these in your SSP.
Without an SSP, you cannot credibly claim to meet the requirements for handling CUI or pass a self-assessment. The Department of War continues to enforce these requirements through self-assessments and government-led assessments, even as the third party CMMC certification requirement is suspended pending strategic review.
What does CA.L2-3.12.4 actually require?
CA.L2-3.12.4, part of the Security Assessment family, requires that you develop, document, and periodically update your System Security Plan. This means your SSP must:
- Describe the system boundary, operational environment, and how security requirements are implemented.
- Identify all assets in and out of scope, including CUI flow diagrams, network boundary diagrams, physical site diagrams, and authorized user lists.
- Be updated as your environment or controls change, more than once a year.
The SSP is only one part of your documentation. It must be supported by policies that define your intent, procedures that explain how you operate, and evidence that proves your controls are actually working. Documentation alone is not proof of compliance, real, timestamped, system-generated artifacts are required.
What happens if you do not have a System Security Plan?
The risks of skipping or neglecting your SSP are not hypothetical. The government has taken action against companies that failed to maintain proper documentation. In the MORSECORP case, the contractor failed multiple NIST SP 800-171 controls on Army and Air Force contracts. Crucially, MORSECORP had no System Security Plan on file, and also used non-FedRAMP email services. The result was government intervention and False Claims Act exposure, more than for the company, but for any involved affiliates and owners.
When there is no third party assessor between your self-assessment and the government, the senior official’s signature on your annual affirmation is the only assurance the government has. This signature carries significant risk. If your documentation, including your SSP, does not match reality, you face potential False Claims Act liability if your claims of compliance are found to be false.
How does the SSP fit into CMMC and NIST 800-171 compliance?
Although the CMMC Level 2 third party certification requirement is currently suspended, you are still required to comply with all 110 NIST SP 800-171 controls and conduct annual self-assessments. Your SSP is central to this process. It is reviewed during assessments and is one of the core documents you must provide to auditors, whether they are from the government or a C3PAO in the future.
The CMMC Scoping Guide makes it clear: your SSP must cover all relevant asset categories and show how CUI flows through your environment. Without a current and complete SSP, you cannot achieve a perfect SPRS score of 110, which is required for full compliance.
What evidence do you need beyond a System Security Plan?
An SSP shows your intent and how you plan to meet requirements, but intent is not enough. You must also maintain:
- Policies, which define your organizational intent.
- Procedures, describing how controls are implemented.
- Evidence, such as system logs, access records, or configuration screenshots, to prove execution.
Assessment objectives, as described in NIST SP 800-171A, require that every one of the 320 objectives under the 110 controls is fully met. Assessors will look for evidence that your controls are more than described in your SSP but are actually in effect.
What are the common mistakes and how can you avoid them?
Many companies believe that a completed SSP is a one-time exercise. In reality, your SSP must be a living document, updated as your systems, processes, or personnel change. Another common mistake is treating the SSP as a substitute for evidence. Remember, assessors and the government require proof of execution, more than documentation of intent.
Fewer than half of Level 2 companies have completed both SSP and POA&M documentation, according to CMMC program figures. The average SPRS score across the Defense Industrial Base is about 60, against a required 110 for full compliance. Without a current SSP, you are unlikely to meet the minimum requirements.
Common questions
What is the difference between an SSP and a POA&M? The SSP documents your current security posture and how you meet requirements. The POA&M (Plan of Actions and Milestones) lists any gaps or deficiencies and your plan to remediate them.
Is a third party assessment required right now? No. The Department of War suspended the CMMC Level 2 third party certification requirement. However, self-assessments, SPRS posting, and annual senior official affirmation are still fully required and enforced.
What happens if my SSP is out of date? An outdated SSP cannot accurately reflect your current environment or controls. This can lead to compliance failures during an assessment and potential False Claims Act exposure if your self-attestation is not accurate.
How to Find System Security Plan Support
If you need to update or create a System Security Plan for CMMC or NIST 800-171 compliance, you do not have to do it alone. The Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant, delivered as services, covering all 110 NIST 800-171 controls for qualifying defense contractors. This grant includes a comprehensive assessment of your current posture and detailed recommendations. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.
For official guidance on NIST SP 800-171 requirements, visit the NIST Computer Security Resource Center.