Compyl
GRC Your Way

What Is a System Security Plan (SSP)? Requirements and How to Write One

Compyl Research

What Is a System Security Plan (SSP)? Requirements and How to Write One

By Compyl ResearchLast updated: August 11, 20267 min read

A system security plan (SSP) is a system-level document that defines a system’s boundary, the information it processes, its operating environment, and how each applicable security requirement is implemented. It is required by NIST SP 800-171 (requirement 3.12.4 / 03.15.02), NIST SP 800-53 control PL-2, CMMC, and FedRAMP, and it is the primary artifact assessors read.

Key takeaways
  • An SSP describes one system, not the whole company: boundary, components, information types, environment of operation, and how every applicable requirement is actually implemented.
  • NIST finalized SP 800-18 Rev. 2 on June 30, 2026, replacing the 2006 guidance and expanding “security plan” into security, privacy, and C-SCRM “system plans” with 21 core elements.
  • You cannot submit an SPRS score without an SSP — SPRS stores the SSP name, version, and date, and DoD’s assessment methodology treats a missing SSP as an assessment that could not be completed.
  • Under CMMC, CA.L2-3.12.4 can never be placed on a POA&M (32 CFR 170.21), so an incomplete SSP is an immediate failure, not a deferred item.
  • DoD suspended CMMC Phase 2 on July 13, 2026, but DFARS 252.204-7012, self-assessments, annual affirmations, and the SSP obligation all remain in force.

What Is a System Security Plan?

An SSP is the authoritative description of one system: what it does, where its boundary sits, what data it handles, and how each applicable security requirement is implemented. It is a system-level document, not a corporate policy. A policy says what the organization intends; an SSP says what is running, on which hosts, configured how, and by whom.

The obligation appears in every federal framework under a slightly different label. NIST SP 800-171 Rev. 2 requirement 3.12.4 directs organizations to develop, document, and periodically update plans describing “system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.” Rev. 3 moves it to 03.15.02 under the Planning family, breaks it into eight explicit elements, and adds an instruction to protect the plan from unauthorized disclosure. In NIST SP 800-53 Rev. 5 the equivalent is control PL-2, which lists 15 plan contents and requires approval by the authorizing official before implementation.

The underlying guidance was rewritten this year. NIST SP 800-18 Rev. 2, finalized June 30, 2026, supersedes Rev. 1, which had stood since February 2006. It widens the concept from a single security plan to three interlocking “system plans” — security, privacy, and supply chain risk management — and pushes organizations toward machine-readable formats such as OSCAL, so plan data can be collected automatically rather than retyped into a Word file.

What Sections Must an SSP Contain?

There is no single mandated template. DoD’s guidance to contractors states there is no prescribed format or specified level of detail, and NIST SP 800-171 allows the plan to be a collection of documents referencing existing policies rather than one monolithic file. What is fixed is the information set. SP 800-18r2 defines 21 core system plan elements; NIST SP 800-171 and SP 800-53 PL-2 require overlapping subsets of the same content.

SSP section What it must document Where it is required
System identity and overview Name, unique ID, operational status, and the mission or business processes supported PL-2a.3; SP 800-18r2
Roles and responsible personnel Named individuals — system owner, ISSO, administrators — not job titles alone 800-171 03.15.02a; PL-2a.4
Information types Data created, stored, transmitted, and disposed of, including CUI categories present 800-171 03.15.02a; PL-2a.5
Authorization boundary What is inside and outside scope, and why — the section assessors test hardest 800-171 3.12.4; SP 800-18r2
System component inventory Hosts, cloud services, endpoints, and for CMMC each asset category 800-171 03.15.02a; CMMC scoping
Environment of operation Network and data flow diagrams showing where CUI actually moves 800-171 3.12.4; SP 800-18r2
Categorization and requirement set Security categorization or CUI determination, and the applicable baseline PL-2a.6, a.11; SP 800-18r2
Control implementation and status Per requirement: how it is met, by what, and whether implemented, planned, or N/A 800-171 03.15.02a; PL-2a.12
Interconnections and exchanges Dependencies on and connections to other systems, including external providers 800-171 3.12.4; PL-2a.9
Threats of concern Specific threats to this system, not a generic threat catalog 800-171 03.15.02a; PL-2a.7
Remediation actions Open gaps and the linked plan of action and milestones SP 800-18r2 Table 1
Approval and change records Approver signatures and dates, plus a log of reviews and changes PL-2a.15, b–d; SP 800-18r2

If a requirement does not apply, say so and say why. An unexplained gap reads to an assessor as an unimplemented control, which costs points.

Who Needs an SSP, and Under Which Rules?

Defense contractors handling CUI. DFARS 252.204-7012 requires implementation of NIST SP 800-171, SSP included. DFARS 252.204-7019 then requires an assessment “not more than 3 years old unless a lesser time is specified in the solicitation,” with the summary level score posted in SPRS before award.

CMMC-covered organizations. At Level 2 the SSP is practice CA.L2-3.12.4. Under 32 CFR 170.16, Level 2 self-assessments run every three years against NIST SP 800-171A, with affirmation in SPRS at assessment and annually thereafter. Our CMMC Level 2 requirements checklist walks the full practice set.

Note the July 2026 change, and what it did not change. On July 13, 2026, DoD suspended the CMMC Phase 2 rollout, pausing new C3PAO certification requirements in solicitations pending a program review. Per WilmerHale’s July 20, 2026 client alert, the Department stated that “all Phase I self-assessment requirements remain firmly in place” and that the action “does not eliminate the requirement for companies to protect federal data.” DFARS 252.204-7012, 800-171 Rev. 2 implementation, SPRS scores, annual affirmations, and current SSPs all still apply — see our CMMC Phase 2 compliance guide.

Cloud providers and agencies under FedRAMP. The legacy FedRAMP SSP template and its 17 lettered appendices are now marked legacy content as the program moves to its Consolidated Rules for 2026 and FedRAMP 20x Key Security Indicators. The plan did not disappear: FedRAMP’s 2026 initial agency authorization guidance still tells agencies to “document the implementation in the agency System Security Plan.” Machine-readable evidence supplements the plan; it does not replace it.

Non-DoD federal contractors. The governmentwide FAR CUI rule (FAR Case 2017-016) was still proposed as of its June 23, 2026 Federal Register publication, so SSP obligations outside DoD arrive mainly through individual contract clauses. Our guide to NIST compliance shows how the frameworks stack.

How Does the SSP Affect Your SPRS Score?

Directly and structurally. The NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 starts every assessment at 110 points and subtracts 5, 3, or 1 point for each requirement not implemented, weighted by the risk the gap creates. Negative scores are entirely possible.

The SSP is not just one of those line items — it is the precondition. DoD’s methodology states that a contractor must have a system security plan for each covered contractor information system, and that its absence produces a finding that the assessment could not be completed due to incomplete information and noncompliance with DFARS 252.204-7012.

The plumbing reflects that. Alongside the score, SPRS stores the “System Security Plan (SSP) name, SSP version, SSP date, and confidence level” for every assessment. You are attesting to a specific version of a specific document, and a government assessor can ask for that version later.

Nor can you defer it. Under 32 CFR 170.21, CA.L2-3.12.4 System Security Plan is one of only six Level 2 requirements that may never be placed on a POA&M. An incomplete SSP is an immediate failure rather than a 180-day remediation item.

The industry baseline is still weak. In the CyberSheath and Merrill Research study published October 1, 2025, the median SPRS score had risen from 20 in 2022 to 60 in 2025 against a maximum of 110, while 17% of contractors still reported negative scores, only 42% had submitted a score at all, and just 1% called themselves fully prepared for assessment.

How Do Assessors Actually Use the SSP?

As the map. An assessor reads the SSP first, uses it to fix the boundary, then spends the engagement testing whether the environment matches the document. Every discrepancy is a finding, which is why an aspirational SSP is worse than a modest, accurate one.

For CMMC Level 2 the SSP also carries the scoping decision. Per DoD’s Level 2 scoping guidance, CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets must all appear in the asset inventory, be documented in the SSP, and be shown in a network diagram; only out-of-scope assets are exempt. For Specialized Assets — government furnished equipment, IoT, OT, and test equipment — CMMC guidance has assessors review the SSP documentation showing risk-based management and go no further. The document is the assessment.

Assessment procedures come from NIST SP 800-171A, which decomposes each requirement into determination statements satisfied through examining artifacts, interviewing people, and testing mechanisms. A plan that names the tool, the configuration, the owner, and the evidence location shortens an assessment by days.

Both catalogs also treat the plan as a controlled artifact: 800-171 Rev. 3 requires you to protect the SSP from unauthorized disclosure, 800-53 PL-2 from unauthorized access and alteration. Our comparison of NIST 800-53 and 800-171 shows where the catalogs diverge.

What Are the Most Common SSP Mistakes?

Restating the requirement instead of describing the implementation. “The organization limits system access to authorized users” is control text, not an answer. The answer names the identity provider, the group structure, the approval workflow, and the review cadence.

A boundary that does not survive contact with reality. If CUI reaches a laptop, file share, helpdesk ticket, or subcontractor mailbox the diagram does not show, the boundary is wrong and every downstream scoping decision inherits the error.

Letting it go stale. SP 800-18r2 frames system plans as living documents reviewed at life cycle milestones and significant contracting activity; CMMC guidance points to updates typically at least annually. Cloud tenants and endpoint fleets change monthly, so an annual refresh often describes a system that no longer exists.

No named owners or approvers. SP 800-18r2 expects the full names, roles, titles, signatures, and dates of everyone who approved the plan. An unsigned SSP has no accountable author.

Treating it as a Word document rather than a data set. That is the practical takeaway from 800-18r2’s push toward OSCAL. When inventory, control status, owners, and remediation actions live in a system of record and the SSP is generated from them, the plan is accurate on the day someone asks — the only day that matters.

Writing it last. The SSP forces you to discover what you actually have. Start it at the beginning of a readiness effort: the gaps it exposes become your POA&M, and the two should be maintained as a matched pair.

Frequently asked questions

What is a system security plan (SSP)?
An SSP is a system-level document that defines a system’s authorization boundary, its components and information types, its operating environment and interconnections, the individuals responsible for it, and how each applicable security requirement is implemented. It is required by NIST SP 800-171, NIST SP 800-53 control PL-2, CMMC, and FedRAMP.
Is an SSP required for CMMC Level 2?
Yes. The SSP is practice CA.L2-3.12.4, and under 32 CFR 170.21 it is one of six Level 2 requirements that can never be placed on a POA&M. An incomplete or missing SSP is an immediate failure rather than a gap you can defer for 180 days.
How long should a system security plan be?
There is no prescribed length or format. DoD states there is no specified level of detail, and NIST SP 800-171 allows the plan to be a set of documents that reference existing policies. Completeness of the required information matters far more than page count; accuracy matters most.
How often should you update an SSP?
NIST SP 800-171 Rev. 3 requires review and update at an organization-defined frequency, and CMMC guidance points to updates typically at least annually. NIST SP 800-18r2 treats system plans as living documents that should also be updated at life cycle milestones and after significant system changes.
Can you submit an SPRS score without an SSP?
No. DoD’s NIST SP 800-171 Assessment Methodology states that a missing system security plan results in a finding that the assessment could not be completed and that the contractor is noncompliant with DFARS 252.204-7012. SPRS itself records the SSP name, version, and date with every score.
What is the difference between an SSP and a POA&M?
The SSP describes the system and how implemented requirements are met; the POA&M tracks the requirements that are not yet met, with owners, milestones, and completion dates. They are maintained together: gaps identified while writing the SSP populate the POA&M, and closed POA&M items update the SSP.

Keep Your System Security Plan Current With Compyl

Compyl’s agentic GRC platform keeps your SSP tied to live system data — asset inventory, control implementation status, owners, and evidence — so the document an assessor reads matches the environment they walk through. Map once to NIST SP 800-171, CMMC, and 800-53, and let the plan update itself.

Request a demo →

About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies