What are an SSP and a POA&M for CMMC?
A System Security Plan (SSP) describes your CUI system's boundary, environment, connections and how each NIST SP 800-171 Rev 2 requirement is implemented. A Plan of Action and Milestones (POA&M) lists requirements not yet met, with tasks, resources and completion dates. Under CMMC Level 2 the SSP itself can never be placed on a POA&M, and POA&M items must close within 180 days.
The System Security Plan
NIST SP 800-171 Rev 2 requirement 3.12.4 says to develop, document and periodically update system security plans that describe system boundaries, environments of operation, how security requirements are implemented, and relationships with or connections to other systems.
The SSP is the master record an assessor tests against. Under the CMMC scoring rule, enduring exceptions that are described in the SSP along with their mitigations are assessed as MET. Government-led Medium and High assessments under DFARS 252.240-7997 also start from your SSP.
The Plan of Action and Milestones
Requirement 3.12.2 says to develop and implement plans of action to correct deficiencies and reduce or eliminate vulnerabilities. The CMMC rule defines a POA&M as a document that identifies tasks, the resources required, milestones and scheduled completion dates.
Two kinds exist in practice. Operational plans of action track temporary deficiencies in day-to-day security; the scoring rule treats those as MET when they show reviews and progress. An assessment POA&M lists requirements scored NOT MET and is what lets you reach a Conditional Level 2 status.
CMMC limits on POA&Ms
- Your score must be at least 80 percent of the 110 requirements, 88 points.
- Only 1-point requirements may be carried, except FIPS validation for CUI encryption when encryption is already in place.
- Never allowed: the SSP (3.12.4), external connections (3.1.20), public information (3.1.22), escorting visitors, physical access logs and managing physical access (3.10.3 to 3.10.5).
- A closeout self-assessment must be posted to SPRS within 180 days, or the Conditional status expires.
- Level 1 never allows a POA&M.
What a usable SSP contains
- A boundary diagram and asset inventory showing where CUI is processed, stored and transmitted.
- Data flows to cloud services, external service providers and other systems.
- For each of the 110 requirements: the implementation narrative, the responsible party and where the evidence is.
- Customer responsibility matrices from your cloud and managed service providers.
- Final, approved documents. The CMMC rule rejects drafts and working papers as evidence.
Keeping both current
A senior official must affirm compliance after each assessment and annually, and assessment artifacts must be kept for six years. Treat the SSP and POA&M as living documents updated whenever a system changes. While Phase 2 is suspended, your self-assessment rests almost entirely on these two documents.
Common follow-up questions
Can I meet CMMC Level 2 without an SSP?
No. The SSP requirement, 3.12.4, is on the CMMC list of requirements that can never be placed on a POA&M, so an assessment without a current SSP cannot reach even Conditional Level 2 status.
How long should an SSP be?
No length is set. NIST requires it to describe system boundaries, environments, how each requirement is implemented and connections to other systems. Clarity and accurate evidence pointers matter more than page count, because an assessor will test what it says.
What happens if POA&M items are not closed in 180 days?
Your Conditional Level 2 status expires. Standard contractual remedies can apply, and the affected system is ineligible for new awards requiring Level 2 until you achieve a new CMMC status.
LAN Service Group's certified ISSO leads SSP and POA&M development for defense suppliers, from boundary definition and evidence mapping through remediation and closeout.
Talk to LAN Service Group (888) 281-7243