SSP and POA&M requirements for CMMC

The short answer

The SSP is not paperwork — it is the document NIST 800-171 requirement 3.12.4 obliges you to maintain, and under the DoD Assessment Methodology it is the precondition for having a score at all. The POA&M is a rule-governed deferral instrument, not a to-do list: banned outright at Level 1, permitted at Level 2 and 3 only inside a conditional status that requires at least 80% of the maximum score, barred entirely for the requirements §170.21 enumerates, and closed within 180 days — after which the conditional status expires and contractual remedies apply. Since the July 2026 assessment pause, no assessor stands between your SSP and your attestation: the document is the record.

The SSP's legal home: the Security Assessment family

Four requirements in NIST 800-171's 3.12 family carry the assessment-and-documentation load. Under the DoD scoring methodology, 3.12.4 is special: it carries no point weight because without a system security plan, a score cannot be posted at all.

3.12.1Periodically assess the security controls in organizational systems to determine if the controls are effective in their application

This control requires organizations to periodically assess the security controls in organizational systems to determine if the controls are effective in their application. It is part of the Security Assessment family and is one of the 110 NIST SP 800-171 Rev. 2 requirements DFARS 252.204-7012 obliges contractors handling CUI to implement — the requirement set CMMC Level 2 assesses. Implementing it protects CUI and supports the score you self-report to SPRS.

3.12.2Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems

This control requires organizations to develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. It is part of the Security Assessment family and is one of the 110 NIST SP 800-171 Rev. 2 requirements DFARS 252.204-7012 obliges contractors handling CUI to implement — the requirement set CMMC Level 2 assesses. Implementing it protects CUI and supports the score you self-report to SPRS.

3.12.3Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls

This control requires organizations to monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. It is part of the Security Assessment family and is one of the 110 NIST SP 800-171 Rev. 2 requirements DFARS 252.204-7012 obliges contractors handling CUI to implement — the requirement set CMMC Level 2 assesses. Implementing it protects CUI and supports the score you self-report to SPRS.

3.12.4Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systemsthe SPRS gate — 3.12.4

This control requires organizations to develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. It is part of the Security Assessment family and is one of the 110 NIST SP 800-171 Rev. 2 requirements DFARS 252.204-7012 obliges contractors handling CUI to implement — the requirement set CMMC Level 2 assesses. Implementing it protects CUI and supports the score you self-report to SPRS.

The four POA&M rules, quoted from 32 CFR 170

Level 1: no POA&M, period

To satisfy CMMC Level 1 requirements, a POA&M is not allowed.

§170.21

The 17 Level 1 practices must all be met at assessment time. There is no conditional path.

Level 2 and 3: allowed, above a floor

If the minimum score is achieved on the assessment (equal to 80% of the maximum score)…

§170.16, §170.18 (conditional status eligibility)

A POA&M only exists inside a conditional status — and conditional status requires scoring at least 80% of the maximum. Below that, there is nothing to defer into; the assessment simply does not pass.

Not everything can be deferred

Section 170.21 identifies the Level 2 security requirements that cannot have a POA&M and must be fully met at the time of the assessment.

§170.21(a)(2)

The rule enumerates specific requirements that must be MET on assessment day regardless of score. Read the list in the rule text before you plan a deferral — do not assume a requirement is deferrable because it is hard.

The 180-day clock, and what expiry means

All POA&Ms must be closed within 180 days of the Conditional CMMC Status Date. … if a POA&M closeout assessment does not find that all requirements have been met by the end of 180 days, then the CMMC Status of Conditional Level 2 (Self) or Conditional Level 2 (C3PAO) will expire. At this point, standard contractual remedies will apply.

§170.21, §170.16

Expiry is not a paperwork event — it removes the status your contract eligibility rests on.

Quotes from Cybersecurity Maturity Model Certification (CMMC) Program — Final Rule (32 CFR part 170) (Federal Register / govinfo.gov (89 FR, Oct 15, 2024), retrieved 2026-08-09).

The working sequence

  1. 1

    Score yourself honestly first

    The 80% floor means a POA&M strategy starts with knowing your number. The calculator walks all 110 requirements with the DoD point weights.

    SPRS Score Calculator
  2. 2

    Write the SSP before anything else

    It is the scoring gate (3.12.4) and the document every later step references. Boundary, CUI flows, per-requirement implementation status.

    CUI Flow Mapper (the boundary section writes itself)
  3. 3

    Plan deferrals inside the rule, not around it

    Only above the floor, only for requirements §170.21 does not exclude, only with a 180-day close plan you can actually execute.

    DFARS 252.204-7020 — what assessments must show
  4. 4

    Treat the affirmation as the record

    Post-pause, your annual affirmation and SPRS posting stand unaudited. What you attest is what you own.

    DFARS 252.204-7019 — the posting requirement

Frequently asked

What is an SSP under NIST 800-171 and CMMC?

The System Security Plan is the document NIST 800-171 requirement 3.12.4 obliges you to develop, document and update: it describes your system boundary, how CUI moves through it, and how each of the 110 requirements is implemented (or where it is not). Under the DoD Assessment Methodology, a current SSP is the precondition for a score at all — no SSP means nothing to assess against.

Is a POA&M allowed for CMMC Level 1?

No. The CMMC final rule states plainly that "To satisfy CMMC Level 1 requirements, a POA&M is not allowed" (32 CFR 170.21). All Level 1 practices must be met at assessment time.

What score do I need before a POA&M is even possible at Level 2?

At least 80% of the maximum assessment score. Conditional CMMC status — the only state in which a POA&M exists — requires achieving that minimum on the assessment (32 CFR 170.16). Below the floor, the assessment fails outright; a POA&M cannot rescue it.

How long do I have to close a CMMC POA&M?

180 days from the Conditional CMMC Status Date. If the closeout assessment finds requirements still unmet at 180 days, the conditional status expires and standard contractual remedies apply (32 CFR 170.21, 170.16).

Can every NIST 800-171 requirement go on a POA&M?

No. 32 CFR 170.21 enumerates Level 2 requirements that cannot be deferred and must be fully met at assessment time. Check the rule text for the specific list before planning any deferral.

Did the 2026 CMMC pause change SSP or POA&M obligations?

The July 2026 pause halted third-party certification assessments; it did not change NIST 800-171 (your SSP obligation under 3.12.4), DFARS 252.204-7019/7020 (SPRS posting and assessment requirements), or annual affirmations. With no assessor in the path, the SSP and the score you attest to carry the record.

NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1 (June 24, 2020), Annex A / §5

Working on this for real?

Reading a clause is the easy part. Deciding what to build, in what order, and what it costs is the work.

  • See how the assessment works — the AI Integration Assessment: a sequenced, costed plan, $12,500, fixed scope.
  • Apply for an evaluation — we don't take every client. Qualified applications book instantly; pilots ($6,000–$45,000, one workflow in your boundary) are reviewed for strategic fit.