Your SSP and POA&M: What Assessors Want
Cody D. Martin//Updated August 9, 2026
A System Security Plan must describe your system in enough detail that a stranger could tell whether each control is really in place. A POA&M needs real dates, named owners and specific milestones. Both are still required after the July 2026 CMMC suspension, under DFARS 252.204-7012.
The System Security Plan is the document everything else hangs off. Your SPRS score derives from it, your POA&M references it, and an assessor reads it before they look at anything else.
Most of the ones we see are a template with a company name dropped in.
Still required, despite the suspension
Worth stating early, because a lot of contractors stopped in July 2026 when Phase 2 of CMMC was suspended.
The suspension paused Level 2 third party assessment. It did not touch DFARS 252.204-7012 or 252.204-7021, which still require a NIST SP 800-171 self assessment, a current SSP, a POA&M for anything unmet, an SPRS score and an annual affirmation signed by a company official.
If you downed tools in July, you are out of compliance now, and the affirmation carries a name.
What an SSP is supposed to do
It describes your system: the boundary, the components inside it, how CUI moves through it, who has access, and how each of the 110 practices is implemented in that specific environment.
The test an assessor applies, whether or not they say it out loud: could someone who has never seen this network tell from this document whether the control is really in place?
“Access control is enforced” fails that test. “Access to the CUI file share is controlled by membership of the CUI-Users security group in Active Directory, reviewed quarterly by the IT manager, with membership limited to the twelve people listed in Appendix C” passes it.
The four ways SSPs fail
It describes a generic company. Written from a template and never adapted. Recognizable because it mentions systems you do not have.
The boundary is vague or wrong. If the SSP does not say clearly which systems are in scope, no statement about controls means anything, because the assessor does not know what they apply to.
It describes intent rather than implementation. “Will be configured to” and “policy requires that” are not implementations. An assessor is looking for what is true today.
It has drifted. Written two years ago, accurate then. You have since moved to a new identity provider and added a cloud environment. This is the most common one, and the annual affirmation is what makes it dangerous.
What a POA&M is supposed to do
Track what is not yet implemented, honestly, with a plan to fix it.
Each entry needs the practice, what is missing, the specific remediation, a named owner, a target date, and the resources required.
Honesty pays here. A POA&M with real dates and real owners reads as a functioning security program. A document claiming full compliance falls apart the moment an assessor asks one question, and now you have a credibility problem as well as a control gap.
What assessors ask about POA&Ms
- Are the dates realistic, or is everything due next quarter?
- Are owners named people rather than departments?
- Has anything been open for two years with the date pushed repeatedly?
- Do the highest scoring practices appear, or only the cheap fixes?
That last one matters most. Under the SPRS scoring model some practices are worth five points and some are worth one. A POA&M that closes only the one point items tells an assessor you optimized the number rather than the security.
Practical advice
Write the boundary section first and get it right. Everything else depends on it, and it is the part that is expensive to correct later.
Then work practice by practice, and where you cannot honestly say a control is implemented, put it in the POA&M rather than stretching the language. The stretched sentences are the ones assessors notice.
- SSP
- POA&M
- NIST 800-171
- CMMC
- SPRS
More on compliance
