What Is a System Security Plan (SSP)? Requirements and How to Write One
A system security plan (SSP) is a system-level document that defines a system’s boundary, the information it processes, its operating environment, and how each applicable security requirement is implemented. It is required by NIST SP 800-171 (requirement 3.12.4 / 03.15.02), NIST SP 800-53 control PL-2, CMMC, and FedRAMP, and it is the primary artifact assessors read.
- An SSP describes one system, not the whole company: boundary, components, information types, environment of operation, and how every applicable requirement is actually implemented.
- NIST finalized SP 800-18 Rev. 2 on June 30, 2026, replacing the 2006 guidance and expanding “security plan” into security, privacy, and C-SCRM “system plans” with 21 core elements.
- You cannot submit an SPRS score without an SSP — SPRS stores the SSP name, version, and date, and DoD’s assessment methodology treats a missing SSP as an assessment that could not be completed.
- Under CMMC, CA.L2-3.12.4 can never be placed on a POA&M (32 CFR 170.21), so an incomplete SSP is an immediate failure, not a deferred item.
- DoD suspended CMMC Phase 2 on July 13, 2026, but DFARS 252.204-7012, self-assessments, annual affirmations, and the SSP obligation all remain in force.
What Is a System Security Plan?
An SSP is the authoritative description of one system: what it does, where its boundary sits, what data it handles, and how each applicable security requirement is implemented. It is a system-level document, not a corporate policy. A policy says what the organization intends; an SSP says what is running, on which hosts, configured how, and by whom.
The obligation appears in every federal framework under a slightly different label. NIST SP 800-171 Rev. 2 requirement 3.12.4 directs organizations to develop, document, and periodically update plans describing “system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.” Rev. 3 moves it to 03.15.02 under the Planning family, breaks it into eight explicit elements, and adds an instruction to protect the plan from unauthorized disclosure. In NIST SP 800-53 Rev. 5 the equivalent is control PL-2, which lists 15 plan contents and requires approval by the authorizing official before implementation.
The underlying guidance was rewritten this year. NIST SP 800-18 Rev. 2, finalized June 30, 2026, supersedes Rev. 1, which had stood since February 2006. It widens the concept from a single security plan to three interlocking “system plans” — security, privacy, and supply chain risk management — and pushes organizations toward machine-readable formats such as OSCAL, so plan data can be collected automatically rather than retyped into a Word file.
What Sections Must an SSP Contain?
There is no single mandated template. DoD’s guidance to contractors states there is no prescribed format or specified level of detail, and NIST SP 800-171 allows the plan to be a collection of documents referencing existing policies rather than one monolithic file. What is fixed is the information set. SP 800-18r2 defines 21 core system plan elements; NIST SP 800-171 and SP 800-53 PL-2 require overlapping subsets of the same content.
| SSP section | What it must document | Where it is required |
|---|---|---|
| System identity and overview | Name, unique ID, operational status, and the mission or business processes supported | PL-2a.3; SP 800-18r2 |
| Roles and responsible personnel | Named individuals — system owner, ISSO, administrators — not job titles alone | 800-171 03.15.02a; PL-2a.4 |
| Information types | Data created, stored, transmitted, and disposed of, including CUI categories present | 800-171 03.15.02a; PL-2a.5 |
| Authorization boundary | What is inside and outside scope, and why — the section assessors test hardest | 800-171 3.12.4; SP 800-18r2 |
| System component inventory | Hosts, cloud services, endpoints, and for CMMC each asset category | 800-171 03.15.02a; CMMC scoping |
| Environment of operation | Network and data flow diagrams showing where CUI actually moves | 800-171 3.12.4; SP 800-18r2 |
| Categorization and requirement set | Security categorization or CUI determination, and the applicable baseline | PL-2a.6, a.11; SP 800-18r2 |
| Control implementation and status | Per requirement: how it is met, by what, and whether implemented, planned, or N/A | 800-171 03.15.02a; PL-2a.12 |
| Interconnections and exchanges | Dependencies on and connections to other systems, including external providers | 800-171 3.12.4; PL-2a.9 |
| Threats of concern | Specific threats to this system, not a generic threat catalog | 800-171 03.15.02a; PL-2a.7 |
| Remediation actions | Open gaps and the linked plan of action and milestones | SP 800-18r2 Table 1 |
| Approval and change records | Approver signatures and dates, plus a log of reviews and changes | PL-2a.15, b–d; SP 800-18r2 |
If a requirement does not apply, say so and say why. An unexplained gap reads to an assessor as an unimplemented control, which costs points.
Who Needs an SSP, and Under Which Rules?
Defense contractors handling CUI. DFARS 252.204-7012 requires implementation of NIST SP 800-171, SSP included. DFARS 252.204-7019 then requires an assessment “not more than 3 years old unless a lesser time is specified in the solicitation,” with the summary level score posted in SPRS before award.
CMMC-covered organizations. At Level 2 the SSP is practice CA.L2-3.12.4. Under 32 CFR 170.16, Level 2 self-assessments run every three years against NIST SP 800-171A, with affirmation in SPRS at assessment and annually thereafter. Our CMMC Level 2 requirements checklist walks the full practice set.
Note the July 2026 change, and what it did not change. On July 13, 2026, DoD suspended the CMMC Phase 2 rollout, pausing new C3PAO certification requirements in solicitations pending a program review. Per WilmerHale’s July 20, 2026 client alert, the Department stated that “all Phase I self-assessment requirements remain firmly in place” and that the action “does not eliminate the requirement for companies to protect federal data.” DFARS 252.204-7012, 800-171 Rev. 2 implementation, SPRS scores, annual affirmations, and current SSPs all still apply — see our CMMC Phase 2 compliance guide.
Cloud providers and agencies under FedRAMP. The legacy FedRAMP SSP template and its 17 lettered appendices are now marked legacy content as the program moves to its Consolidated Rules for 2026 and FedRAMP 20x Key Security Indicators. The plan did not disappear: FedRAMP’s 2026 initial agency authorization guidance still tells agencies to “document the implementation in the agency System Security Plan.” Machine-readable evidence supplements the plan; it does not replace it.
Non-DoD federal contractors. The governmentwide FAR CUI rule (FAR Case 2017-016) was still proposed as of its June 23, 2026 Federal Register publication, so SSP obligations outside DoD arrive mainly through individual contract clauses. Our guide to NIST compliance shows how the frameworks stack.
How Does the SSP Affect Your SPRS Score?
Directly and structurally. The NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 starts every assessment at 110 points and subtracts 5, 3, or 1 point for each requirement not implemented, weighted by the risk the gap creates. Negative scores are entirely possible.
The SSP is not just one of those line items — it is the precondition. DoD’s methodology states that a contractor must have a system security plan for each covered contractor information system, and that its absence produces a finding that the assessment could not be completed due to incomplete information and noncompliance with DFARS 252.204-7012.
The plumbing reflects that. Alongside the score, SPRS stores the “System Security Plan (SSP) name, SSP version, SSP date, and confidence level” for every assessment. You are attesting to a specific version of a specific document, and a government assessor can ask for that version later.
Nor can you defer it. Under 32 CFR 170.21, CA.L2-3.12.4 System Security Plan is one of only six Level 2 requirements that may never be placed on a POA&M. An incomplete SSP is an immediate failure rather than a 180-day remediation item.
The industry baseline is still weak. In the CyberSheath and Merrill Research study published October 1, 2025, the median SPRS score had risen from 20 in 2022 to 60 in 2025 against a maximum of 110, while 17% of contractors still reported negative scores, only 42% had submitted a score at all, and just 1% called themselves fully prepared for assessment.
How Do Assessors Actually Use the SSP?
As the map. An assessor reads the SSP first, uses it to fix the boundary, then spends the engagement testing whether the environment matches the document. Every discrepancy is a finding, which is why an aspirational SSP is worse than a modest, accurate one.
For CMMC Level 2 the SSP also carries the scoping decision. Per DoD’s Level 2 scoping guidance, CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets must all appear in the asset inventory, be documented in the SSP, and be shown in a network diagram; only out-of-scope assets are exempt. For Specialized Assets — government furnished equipment, IoT, OT, and test equipment — CMMC guidance has assessors review the SSP documentation showing risk-based management and go no further. The document is the assessment.
Assessment procedures come from NIST SP 800-171A, which decomposes each requirement into determination statements satisfied through examining artifacts, interviewing people, and testing mechanisms. A plan that names the tool, the configuration, the owner, and the evidence location shortens an assessment by days.
Both catalogs also treat the plan as a controlled artifact: 800-171 Rev. 3 requires you to protect the SSP from unauthorized disclosure, 800-53 PL-2 from unauthorized access and alteration. Our comparison of NIST 800-53 and 800-171 shows where the catalogs diverge.
What Are the Most Common SSP Mistakes?
Restating the requirement instead of describing the implementation. “The organization limits system access to authorized users” is control text, not an answer. The answer names the identity provider, the group structure, the approval workflow, and the review cadence.
A boundary that does not survive contact with reality. If CUI reaches a laptop, file share, helpdesk ticket, or subcontractor mailbox the diagram does not show, the boundary is wrong and every downstream scoping decision inherits the error.
Letting it go stale. SP 800-18r2 frames system plans as living documents reviewed at life cycle milestones and significant contracting activity; CMMC guidance points to updates typically at least annually. Cloud tenants and endpoint fleets change monthly, so an annual refresh often describes a system that no longer exists.
No named owners or approvers. SP 800-18r2 expects the full names, roles, titles, signatures, and dates of everyone who approved the plan. An unsigned SSP has no accountable author.
Treating it as a Word document rather than a data set. That is the practical takeaway from 800-18r2’s push toward OSCAL. When inventory, control status, owners, and remediation actions live in a system of record and the SSP is generated from them, the plan is accurate on the day someone asks — the only day that matters.
Writing it last. The SSP forces you to discover what you actually have. Start it at the beginning of a readiness effort: the gaps it exposes become your POA&M, and the two should be maintained as a matched pair.
Frequently asked questions
What is a system security plan (SSP)?
Is an SSP required for CMMC Level 2?
How long should a system security plan be?
How often should you update an SSP?
Can you submit an SPRS score without an SSP?
What is the difference between an SSP and a POA&M?
- NIST SP 800-18 Rev. 2, Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems (June 30, 2026)
- NIST SP 800-18r2 (full text PDF)
- NIST SP 800-171 Rev. 2, Protecting CUI in Nonfederal Systems (requirement 3.12.4)
- NIST SP 800-171 Rev. 3 (requirement 03.15.02, System Security Plan)
- NIST SP 800-53 Rev. 5, control PL-2 System Security and Privacy Plans
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 24, 2020)
- SPRS — NIST SP 800-171 assessment data stored
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements
- 32 CFR 170.21 — Plan of Action and Milestones requirements (eCFR)
- 32 CFR 170.16 — CMMC Level 2 self-assessment and affirmation requirements (eCFR)
- DIB SCC CyberAssist — CA.L2-3.12.4 System Security Plan
- FedRAMP Consolidated Rules for 2026 — Initial Agency Authorization
- WilmerHale — Pentagon Suspends CMMC Phase 2 Requirements (July 20, 2026)
- CyberSheath/Merrill Research CMMC readiness study (October 1, 2025)
Keep Your System Security Plan Current With Compyl
Compyl’s agentic GRC platform keeps your SSP tied to live system data — asset inventory, control implementation status, owners, and evidence — so the document an assessor reads matches the environment they walk through. Map once to NIST SP 800-171, CMMC, and 800-53, and let the plan update itself.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.