SSP and POA&M review and assessor readiness
Will an assessor accept your SSP and POA&M as written?
We review a System Security Plan and Plan of Action and Milestones that already exist or are still being written. We check every requirement's implementation statement against the NIST SP 800-171A assessment objectives, mark what an assessor will challenge, and get both documents assessor ready.
The gap assessment itself is delivered by Capital Cyber. If you have not been measured against NIST SP 800-171 yet, start there. Capital Cyber gap assessment.
Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.
Book a 30 minute callWhat does the engagement include?
- A review of each requirement's implementation statement against the NIST SP 800-171A assessment objectives
- A check that the System Security Plan boundary, scope and asset inventory match how the company actually works
- A review of the POA&M for eligible items, owners, milestones and dates under 32 CFR 170.21
- Findings on the statements an assessor is likely to challenge, with rewrite guidance
- Review of the policies and procedures the System Security Plan cites
- A check that the score posted in SPRS is supported by the documented implementation
Who is this for?
Contractors that already have a System Security Plan and POA&M, or are writing them, and want both checked before an assessor or DoD reads them.
What do you get?
How does the engagement run?
- A 30 minute call about your contracts, your deadline and where your sensitive data lives.
- A written scope that names the deliverables, the schedule and who does what.
- A kickoff with your leadership and your IT provider, then regular progress briefings until the deliverables are accepted.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What else do buyers ask?
Do you perform the gap assessment?
No. The gap assessment is delivered by Capital Cyber at capitalcybercompliance.com. This engagement reviews the System Security Plan and POA&M that come out of it, or that you already have, and gets them ready for an assessor. Capital Cyber gap assessment.
What is the difference between an SSP and a POA&M?
The System Security Plan describes your system boundary and how each requirement is implemented. The Plan of Action and Milestones lists the requirements that are not yet fully met, with the actions, owners and dates to close them. An assessor reads both.
Can we go into a CMMC assessment with open POA&M items?
Only in a limited way. Under 32 CFR 170.21 you may hold a POA&M at a Level 2 assessment only if your score is at least 88 of 110 and the open items are all 1 point requirements, with a few exceptions; the result is conditional status and the items must be closed within 180 days.
What is the DoD Assessment Methodology score?
It is the scoring method DoD uses for NIST SP 800-171 self assessments. Each requirement carries a weight, unmet requirements subtract from a maximum of 110, and the result is entered in the Supplier Performance Risk System, SPRS, as DFARS 252.204-7019 requires.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.