Guide

What is an SSP?

A System Security Plan describes your system and how each control is implemented. Here is what belongs in it and how to keep it current.

Intended audience
Program owners and contractors
Difficulty
Intermediate
Estimated time
10 minutes
Access
Free
NIST SP 800-171
CMMC
FedRAMP
Government contracting

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • State the purpose of a System Security Plan and who reads it first.
  • Identify the four elements of a strong control implementation narrative.
  • Explain why an unchanged SSP is often a warning sign.
  • Describe when an SSP should be updated and what approval should accompany the update.
  • Draft a narrative statement that names a tool, a role, a frequency, and evidence.

Purpose

The SSP is the document an assessor reads first. It answers: what is the system, where are its edges, who uses it, what data does it hold, and how is each requirement met.

What makes a good narrative

  • Names the tool doing the work.
  • Names the person or role performing the action.
  • States the frequency.
  • Points to the evidence that proves it.

Keeping it alive

An SSP that has not changed in two years is usually wrong. Update it when a tool, boundary, or owner changes, and record an approval each time.

Key takeaways

  • The SSP describes the system boundary, its users and data, and how each requirement is implemented, and it is typically the first document an assessor reads.
  • A strong narrative names the specific tool, the responsible role, the frequency of the activity, and where the supporting evidence lives.
  • An SSP that has not been updated in years usually no longer reflects reality.
  • The SSP should be updated whenever a tool, boundary, or system owner changes.
  • Each update should be accompanied by a recorded approval to keep the document defensible.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 3
Knowledge check

80% required to pass. Answers are graded on our servers.

1. What document does an assessor typically read first?

2. Which of these is NOT one of the four elements of a good narrative?

3. What does an SSP unchanged for two years usually indicate?

4. When should the SSP be updated?

5. What should accompany each SSP update?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal); DoD supply chain
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Template

SSP Outline

A section-by-section outline for a System Security Plan a small business can maintain.

Advanced
60 min
Premium
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Template

POA&M Starter

A plan of action and milestones you can actually maintain, with the fields assessors expect.

Intermediate
30 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Guide

What is a POA&M?

A Plan of Action and Milestones is how you honestly track gaps. Done well, it builds trust; done badly, it destroys it.

Beginner
8 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.