What do CMMC assessors actually look for in an SSP?
CMMC assessors scrutinise the System Security Plan (SSP) to verify it accurately describes the organisation's information system, its boundaries, and the implementation of security controls protecting Controlled Unclassified Information (CUI). The SSP must demonstrate a clear understanding of CMMC requirements, aligning with NIST SP 800-171, and serve as a foundational document for the assessment, proving the organisation's commitment to cybersecurity maturity.
A well-prepared SSP is more than a compliance checklist; it is a comprehensive narrative detailing how each CMMC practice is met within the specific organisational context. Assessors look for consistency between the SSP's descriptions, other documented policies and procedures, and observable evidence during the assessment. Common deficiencies include generic control descriptions lacking specific implementation details, failure to clearly define the CUI boundary, or an SSP that is not regularly updated to reflect system changes. The SSP should articulate the system's purpose, its components, data flows, and the roles and responsibilities of personnel involved in its operation and security.
The SSP serves as the primary roadmap for the CMMC assessment, guiding assessors in understanding the scope and complexity of the system under review. Assessors use it to identify key personnel for interviews, validate control implementations, and plan their evidence collection strategy. They will cross-reference the SSP's assertions with technical configurations, system logs, and direct observations to confirm that stated controls are operational and effective. An SSP that clearly and accurately details the implementation of each CMMC practice significantly streamlines the assessment process and reduces the likelihood of findings.
Sources
- CMMC Level 2 Assessment Guide
- NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations