---
title: "What Is SSP? CMMC Definition"
description: "An SSP is the document describing how an organization implements each required security control across its in-scope environment."
url: https://policycortex.com/cmmc/glossary/ssp
sealed: 2026-07-02
register: cmmc/glossary/ssp
records: 3
digest: sha3:0e4262ee7f5180e6e7a852a86bf3484e0c764ed12e301d1b4842ff1317ba2232
---

# What is SSP?

Register / Glossary

An SSP is the document describing how an organization implements each required security control across its in-scope environment.

Sealed 2026-07-02

SSP stands for System Security Plan.

The System Security Plan (SSP) documents your system boundary, the CUI data flows within it, and how each of the 110 NIST 800-171 controls is implemented. It is the central artifact a C3PAO reviews.

Assessors consistently report that documentation gaps — an SSP that does not match the live environment — drive more failed assessments than missing technical controls. SSPs commonly run to hundreds of pages.

Keeping the SSP true to a continuously changing cloud environment is the core challenge; automated evidence generation exists to close the gap between what the SSP claims and what the environment actually does.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [POA&M: Plan of Action and Milestones](https://policycortex.com/cmmc/glossary/poam): A POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates. |
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [C3PAO: CMMC Third-Party Assessment Organization](https://policycortex.com/cmmc/glossary/c3pao): A C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments. |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: Unchanged since sealing
- **Record**: https://policycortex.com/cmmc/glossary/ssp

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 71d69f454167 | d8ccc3b5206f |
| REC 0001 | DEFINITION | def573b10d34 | 71d69f454167 |
| REC 0002 | RELATED RECORDS | 0e4262ee7f51 | def573b10d34 |

Head sha3:0e4262ee7f5180e6e7a852a86bf3484e0c764ed12e301d1b4842ff1317ba2232. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
