Technical controls get the attention in most compliance conversations, but when an assessor sits down with a contractor, the first thing requested is usually paper. Specifically, the system security plan and the plan of action and milestones. These two documents decide whether your security program can be demonstrated, and many small contractors have never written either.
This post explains both in plain English and shows how they relate to NIST SP 800-171 and CMMC Level 2.
The framework in one paragraph
NIST SP 800-171 defines security requirements for protecting controlled unclassified information (CUI) in nonfederal systems. It contains 110 requirements organized into families such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, media protection, physical protection, risk assessment, system and communications protection, and system and information integrity. CMMC Level 2 is built on those requirements.
What a system security plan is
The system security plan (SSP) describes your environment and explains how you meet each requirement. A good SSP includes:
- A description of the system boundary, meaning the systems, people and locations that handle CUI
- A network and data flow overview
- An inventory of hardware, software and cloud services in scope
- For every requirement, a statement of how it is implemented, who is responsible and where the evidence lives
- Connections to external providers, such as cloud services or outsourced IT
How to write implementation statements
Weak statements restate the requirement. Strong statements describe what you actually do. Compare:
- Weak: "The company limits system access to authorized users."
- Stronger: "Access to the CUI file share is granted through named security groups, approved by the project manager and reviewed every quarter by the IT administrator. Accounts are disabled the day of termination."
The second statement names a mechanism, a role and a frequency, and an assessor can ask for proof of each.
What a plan of action and milestones is
The POA&M lists the requirements you have not fully met. For each gap it records:
- What the gap is
- The risk it creates
- Resources needed
- The responsible person
- A realistic completion date
- Milestones along the way
It is a working project plan, not a confession. However, the CMMC program places limits on what may remain open at the time of an assessment, so a POA&M does not allow you to leave everything for later. Check the current program rules and your contract for what is permitted.
How the two documents work together
The SSP describes where you are today. The POA&M describes how you will close the distance. When you finish a milestone, you update the SSP and close the POA&M item. Assessors expect the documents to agree with each other and with what they see in your systems.
Evidence matters
Every claim in your SSP should connect to something you can show. Examples include screenshots of configuration settings, exported user lists, training attendance records, policy documents with approval dates, log samples and incident response exercise notes. Create an evidence folder organized by requirement family and keep it current.
Common mistakes
- Copying a template without changing it to match your environment
- Defining the scope so broadly that every laptop and server must comply
- Writing policies nobody follows
- Letting the SSP go stale after a system change
- Forgetting external service providers that touch CUI
- Treating the POA&M as a one-time exercise
Who should own these documents
IT staff or your managed provider can draft the technical sections, but a business leader should own the final plan and sign it. Compliance depends on decisions about people, budgets and priorities that technology staff cannot make alone.
A simple starting plan
- Define your CUI boundary.
- Inventory the systems inside it.
- Score yourself against the 110 requirements.
- Draft implementation statements for the ones you meet.
- Record the rest in the POA&M with owners and dates.
- Collect evidence as you go and review everything every quarter.
How Ironfield Cyber helps
Ironfield Cyber helps defense contractors and suppliers draft the SSP and POA&M, close technical gaps and prepare evidence for assessment. If these documents do not exist yet, a short working session is often enough to get the first draft started.