A comprehensive document that describes how an organization implements, manages, and maintains the cybersecurity controls required to protect Controlled Unclassified Information (CUI). The SSP is a central requirement under DFARS 252.204-7012 and a foundational artifact for demonstrating compliance with NIST SP 800-171 and CMMC.

An SSP typically includes:

Assessors rely heavily on the SSP during CMMC audits to verify that an organization not only has documented policies but also enforces them in practice. A well-prepared SSP not only demonstrates compliance but also provides a roadmap for ongoing cybersecurity improvement.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.