Build my kit
HIPAA guide

CMMC Level 2 System Security Plan: what it must contain

The System Security Plan is the first document an assessor reads, and control 3.12.4 makes it mandatory. It is also where most small contractors lose time, because a downloaded template describes a company that is not theirs.

Free preview before you pay. Editable Word files. 14 day refund.

Why control 3.12.4 exists

NIST SP 800-171 Rev. 2 requires you to "develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems." That sentence is the table of contents for the document.

An assessor uses the plan to decide what to look at. If the plan says multifactor authentication is enforced everywhere, they will ask to see it enforced everywhere. A plan that overclaims creates findings that would not otherwise exist.

What a plan has to cover

Get the boundary small

Scope is the single biggest lever on the cost of an assessment, and it is decided in the plan. A contractor who lets CUI spread across the whole company network has to assess the whole company network. A contractor who keeps CUI inside a defined enclave assesses the enclave.

If you are still early, decide the boundary before you buy tooling. Moving CUI into a smaller enclave later means redoing work.

Where generic templates break down

A plan is not compliance

Writing that you require encryption does not encrypt anything. The plan, the POA&M, and reality have to agree, and the POA&M is the honest bridge between what you require and what is running today. An assessor would far rather see ten open POA&M items with owners and dates than a plan claiming a perfect posture.

Questions

Is an SSP required for a Level 2 self-assessment?

Yes. Control 3.12.4 requires a system security plan regardless of whether the assessment is a self-assessment or performed by a C3PAO.

How long should it be?

Long enough to cover the boundary and all 110 controls, and no longer. For a small contractor that is usually 20 to 40 pages. Padding it does not help.

How often does it need updating?

At least annually, and whenever the system changes materially. Keep superseded versions, because assessors ask what the posture was at a given date.

Can our IT provider write it for us?

They can help with the technical narratives, but the plan belongs to your company and your senior official signs it. Record which controls the provider operates on your behalf.

More guides

Templates, not legal advice. Eaglizer IT is not a C3PAO, a Registered Provider Organization, or a law firm, and does not certify compliance with CMMC or NIST SP 800-171. Documentation is a prerequisite for an assessment, not a substitute for one.