NIST SP 800-171
SSP versus POA&M: which does an assessor read first?
The System Security Plan comes first, every time. An assessor reads the SSP to learn what you claim, how your environment is built and where the boundary sits, and then spends the rest of the assessment testing those claims. The Plan of Action and Milestones comes after, as the record of what is not yet done. The two documents answer different questions, and contractors who blur them tend to struggle in assessments. This article explains what each one is, how they relate, and how to write both so they survive contact with an assessor.
What is a System Security Plan?
A System Security Plan is the document that describes your system boundary, your environment and how each of the 110 NIST SP 800-171 requirements is implemented. Requirement 3.12.4 calls for it directly, which means the SSP is itself something an assessor checks.
A useful SSP is specific. For each requirement it names the technology, the setting, the people responsible and the procedure, in enough detail that someone outside the company could go and verify it. "We use multifactor authentication" is a claim. "Multifactor authentication is enforced by a conditional access policy for all users of the enclave tenant, with exceptions reviewed quarterly by the IT lead" is an implementation statement an assessor can test.
What is a POA&M?
A Plan of Action and Milestones is the list of requirements that are not yet fully met, with what will be done about each, who owns it and when it will be finished. Requirement 3.12.2 asks for plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities, and the POA&M is how most contractors meet it.
Each entry should identify the requirement, describe the gap plainly, state the planned fix, name an owner and give a realistic date. Interim measures that reduce the risk while the fix is in progress belong there too. A POA&M with no dates, or with dates that have all passed, tells an assessor the program is not being managed.
Which document does an assessor read first?
The assessor reads the SSP first, because it defines what is being assessed. The boundary, the asset inventory, the network diagram and the implementation statements in the SSP become the assessor's map. Interviews, document reviews and tests are then planned against it.
Under the DoD Assessment Methodology a missing SSP is not just a lower score. Without one, the assessment cannot be completed at all. That is why a contractor with strong technology and a thin SSP often scores worse than expected. The assessor can only credit what the SSP explains and the evidence proves.
How do the SSP and POA&M relate to each other?
They should describe the same environment from two angles and never contradict each other. The SSP says how each requirement is met. Where a requirement is not fully met, the SSP should say so and point to the POA&M entry that will close it.
Contradictions are the most common problem we find. An SSP that says a requirement is implemented, next to a POA&M that lists the same requirement as open, forces the assessor to pick which document to believe. Usually the answer is neither, and every other statement in both documents gets read with more suspicion afterward.
What makes an implementation statement hold up?
An implementation statement holds up when it can be traced to evidence an assessor can see. Name the system, the setting and the owner, describe the procedure in the order it actually happens, and cite where the evidence lives, such as a policy section, a configuration export, a log query or a ticket history.
Write to the assessment objectives in NIST SP 800-171A, not just to the requirement text. Many requirements have several objectives, and each one is judged. A statement that answers the headline of a requirement but misses one of its objectives leaves the requirement unmet, however good the rest of it is.
How many items can stay open on the POA&M?
Fewer than most contractors hope. For a CMMC Level 2 assessment to reach conditional status, 32 CFR part 170 requires a minimum score of 88 out of 110, limits which requirements may be left open, and requires every open item to be closed within 180 days. The highest weighted requirements generally cannot be deferred.
For the SPRS score under DFARS 252.204-7019, open POA&M items still count as not met. The POA&M records the plan, but it does not earn the points. Planning to finish the work is what improves the score.
How often should the documents be updated?
Both should be updated whenever the environment changes, and reviewed on a schedule even when it seems not to have. A new cloud service, a new office, a new managed provider or a change to how CUI arrives all change the SSP. Closing a gap, slipping a date or finding a new gap all change the POA&M.
A sensible minimum is a documented review before each annual affirmation, with version history kept for both. When the affirmation is signed, the person signing should be able to see that the SSP is current and that the POA&M dates are real.
Where do most contractors go wrong?
Most go wrong by treating the SSP as a template to fill in rather than a description of their own environment. Generic language copied from a vendor, references to tools the company does not use, and a boundary diagram that does not match the network are all easy for an assessor to find.
The second common mistake is leaving evidence collection to the end. Evidence gathered as each requirement is implemented is easier to find, more convincing and less stressful than a scramble in the weeks before an assessment. Write the SSP as you build, keep the POA&M honest, and the assessment becomes a review of work already documented.