MDRwatchdog
Home › Cmmc Ssp Poam
MDRwatchdog Compliance

SSP and POA&M: the two documents CMMC runs on

If CMMC has a paperwork heart, it's these two documents. The System Security Plan (SSP) describes how you meet each NIST 800-171 control; the Plan of Action & Milestones (POA&M) lists the ones you don't yet and how you'll close them. Both remain required in 2026 as part of self-assessment.

Book a 15-minute review →

The SSP is the document an assessor, a prime, or a contracting officer will ask for first. It documents your environment, your system boundary, and control-by-control how each of the 110 requirements is satisfied. A vague or outdated SSP is the fastest way to fail a review - it has to match what's actually running.

The POA&M is your honesty mechanism: it acknowledges the controls you haven't met and commits to a timeline. Handled well, it's a strength - it shows an assessor a credible, managed path. Certain high-impact controls, however, generally cannot be deferred to a POA&M, so scoping matters.

The chronic problem is drift. You write an SSP, your environment changes, and within months the document describes a system that no longer exists. Because a future assessment measures reality, a stale SSP is a liability dressed up as compliance.

MDRwatchdog generates your SSP and POA&M from live monitoring and keeps them current automatically - controls the platform can prove are marked evidenced, the rest flagged into your POA&M with the gap clearly stated. What you hand over reflects your real environment. Readiness and evidence, not certification, and not legal advice.

Frequently asked questions

What is the difference between an SSP and a POA&M?

The SSP describes how you meet each control; the POA&M lists the controls you haven't met yet and your plan to close them. You need both for a complete CMMC / NIST 800-171 self-assessment.

Are SSP and POA&M still required in 2026?

Yes. They're part of the self-assessment regime, which the July 2026 CMMC Phase 2 suspension left in force.

Can I POA&M any control?

No. Certain high-impact controls generally cannot be deferred to a POA&M and must be met outright. Scoping and prioritization matter - confirm specifics against current NIST/DoD guidance.

MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).