Chapter 1
Who Should Review Our SSP Before the Assessment?
You finished the SSP (System Security Plan). It describes every safeguard that protects your CUI (Controlled Unclassified Information). One wrong statement can turn into a failed practice on assessment day.
Assessors treat the SSP as evidence, not decoration. The DoD (Department of Defense) assessment method lists the system security plan as a standard examination object. (NIST SP 800-171A) DFARS (Defense Federal Acquisition Regulation Supplement) clause 252.204-7020 requires High assessments to validate that requirements are implemented as described in the SSP. (DFARS 252.204-7020)
Why does the SSP get so much attention?
NIST (National Institute of Standards and Technology) publishes requirement 3.12.4 in SP 800-171 Rev. 2. It requires organizations to develop, document, and update SSPs. (NIST SP 800-171 Rev. 2) It must describe system boundaries, environments of operation, how requirements are implemented, and system connections.
NIST does not dictate a format. It only requires the plan to convey the 3.12.4 information. (CSRC Protecting CUI FAQs)
CMMC (Cybersecurity Maturity Model Certification) Level 2 covers the 110 requirements of NIST SP 800-171 Rev. 2. (CMMC final rule) Many contracts require a C3PAO (CMMC Third-Party Assessment Organization) certification assessment. (32 CFR Part 170) Even a self-assessment starts with the SSP. DFARS 252.204-7020 defines a Basic Assessment as the contractor's own review of their SSP. (DFARS 252.204-7020) So the SSP is the document every assessment reads first.
Who should review the SSP, and in what order?
Review in this order: system owner, ISSO (Information System Security Officer), control owners, independent reviewer. Each reviewer looks for different problems. Fix owner-level issues first. A boundary change can invalidate control-level review.
What does the system owner check?
The system owner answers one question: does this plan describe the real system?
- System name, owner, and purpose match reality.
- The boundary includes every component that stores, processes, or transmits CUI.
- Data flow descriptions match how data actually moves.
- Components marked out of scope really are out of scope.
- The sign-off page names a senior official and a date.
The owner also confirms the CUI categories in scope. Check the contract. The contract says which CUI categories you handle. The SSP must cover those categories and no others.
Only the owner can confirm business facts. Only the owner can accept the risk of the boundary.
What does the ISSO check?
The ISSO checks whether each claim will survive an assessor.
- Every practice has an implementation statement.
- Status words are honest: implemented, planned, or not applicable.
- Nothing says implemented unless evidence exists.
- Inherited controls name the provider and the responsibility split.
- Non-applicable practices include the documented reason. (NIST SP 800-171A)
- Every planned item points to a POA&M (Plan of Action and Milestones) entry with a date.
- Dates, names, and system details are current.
Compare each POA&M entry against its SSP statement. The dates must match. The owners must match. A POA&M entry without an SSP reference is invisible to the assessor.
An assessor examines the SSP for every control. The ISSO should read it the same way first.
What do the control owners check?
Control owners are the people who operate each control. Examples: the network admin, the help desk lead, the training coordinator. Each one reads only their assigned sections. They answer one question: is this how it really works?
- The MFA (multifactor authentication) statement says admins require MFA. The admin confirms it is enforced, not optional.
- The backup statement says weekly encrypted backups. The backup owner confirms the schedule and the encryption.
- The training statement names the annual course. The training lead confirms new hires take it within 30 days.
Control owners also supply the evidence. Screenshots, logs, tickets, and reports go with the statement. Ask for the evidence at the same time. Do not accept "we will find it later." An implementation claim without evidence is a weak claim.
Why add an independent reviewer?
Everyone who wrote the plan has read it too many times. They stop seeing what is actually written. They see what they meant to write.
An independent reviewer has no history with the document. A good reviewer is an internal colleague from another team. A better one is a consultant who has sat through real assessments.
The reviewer asks the questions an assessor will ask. Where is the evidence for this claim? Who approved this exception? What happens if this person leaves?
Give the reviewer the SSP without the evidence first. Ask them to mark every claim they cannot verify from the text alone. Then give them the evidence and ask what is still missing.
Schedule this review at least two weeks before the assessment. You need time to fix what the reviewer finds.
How should the review be run?
Use the same three methods assessors use. NIST SP 800-171A defines them: Examine, Interview, Test. (NIST SP 800-171A)
- Examine. Read the SSP line by line against the actual system.
- Interview. Ask each owner to explain their section without reading from the page.
- Test. Spot-check three to five controls in the live system.
Run the review control by control. For each practice, open the SSP statement, then open the evidence. Mark each practice as verified, needs fix, or missing evidence.
Hold one review meeting per control family. Short meetings find more problems. Start the review four to six weeks before the assessment. Leave the last two weeks for fixes and a second read.
What is on the pre-assessment checklist?
- Every practice has a status: implemented, planned, or not applicable.
- Planned practices each link to a dated POA&M entry.
- The boundary diagram matches the asset inventory.
- Inherited controls name the external service provider.
- Every claim has evidence attached or filed where the SSP points.
- Interviewees know their sections without reading them.
- The system owner has signed the final version.
- The SSP version is dated after the last change.
A conditional assessment allows up to 180 days to close POA&M items. (CMMC final rule) Do not count on that grace period. Close items before the assessor arrives.
Next step
Your SSP is the first thing an assessor reads. Make it the best-reviewed document you own.
See how PolicyCortex generates SSP text from collected evidence.
Sources
- NIST SP 800-171 Rev. 2, requirement 3.12.4
- NIST SP 800-171A, assessment methods and objects
- CSRC Protecting CUI FAQs, SSP templates
- 32 CFR Part 170, CMMC program rule
- CMMC final rule, Federal Register
- DFARS 252.204-7020, DoD assessment requirements