The Document You Did Not Know You Were Writing

If you own the CMMC program inside a defense contractor, you have probably been told that the System Security Plan is the foundation of your assessment. That is true, but it undersells the point. The SSP is not the foundation of the assessment. The SSP is the assessment, and the contractor wrote it. The CMMC Assessment Process is built around examining what the SSP claimed, interviewing the people the SSP said do the work, and testing the mechanisms the SSP said are in place. Every one of those activities starts from the contractor's own document.

The paper frames it plainly: the SSP functions like a restaurant menu, and everything on the menu will be ordered. The assessment team orders what the contractor listed and expects the environment to produce it. The data says contractors misjudge this constantly. A 2025 survey of active assessors found that roughly half had delayed or declined engagements because gaps surfaced during pre-award review, and approximately eighty percent identified assumed readiness without proper validation as the primary cause. The contractor believed the document described their environment. The assessor discovered that it described an aspiration.

Three Failure Modes

The first failure mode is the implementation statement that verifies as fiction. It arrives in three varieties: policy language masquerading as implementation language, vendor boilerplate that describes what a product can do rather than what the deployment actually does, and the quiet future tense that records the environment the contractor intends to have. All three read fine on paper and collapse under examine and test, and the third carries exposure beyond the assessment, because the SSP supports a score submitted to the Supplier Performance Risk System, and that score is a representation to the government.

The second failure mode is documentation that contradicts itself. The SSP, the network and data flow diagrams, the asset inventory, and the SPRS score must tell one story. Assessors read internal consistency as the leading indicator of organizational maturity, and they decide whether to sample or to dig before they ever arrive. The third failure mode is the SSP nobody has read, the accurate and professionally written document that is unknown to the people who will be interviewed against it. Interview validation checks the document against the people named in it, and a document that was right about a hypothetical company fails against the real one.

Everything on the menu will be ordered. The assessment team builds its evidence requests, interview plan, and test plan from the SSP before arriving. Every implementation statement is a claim the contractor has invited the team to verify.

The verdict is rendered on the evidence. The assessment methodology gives the team three methods: examine, interview, and test. An articulate narrative moves no determination statement if the artifact and the test do not support the claim.

Consistency is read as maturity. An assessment team that trusts the documentation samples. A team that does not trust the documentation digs, and the difference is decided before the team arrives.

Writing Statements That Survive Verification

The constructive discipline is writing every implementation statement against the standard the assessor actually uses, which is not NIST SP 800-171 but NIST SP 800-171A, the companion assessment procedures document where each requirement breaks down into the determination statements the assessor must mark as satisfied or other than satisfied. A statement built to survive verification has five properties: it is written in the present tense, it names the specific systems and mechanisms involved, it names the role or person responsible, it states where the evidence lives, and it answers every determination statement for the requirement rather than the requirement heading alone.

The same discipline applies to the boundary itself. The scoping decision must be settled before the SSP is written, not discovered during the assessment. Manufacturing environments feel this hardest, because the networked machine tools, the shared drives where government drawings become G-code, and the wireless networks the shop floor rides on are the assets that scoping exercises rush past and assessors walk straight toward.

The Shorter Honest SSP Wins

The paper closes with the strategic conclusion that runs against the instinct of nearly every contractor preparing for assessment. The instinct is to claim every control as fully implemented. The framework rewards the opposite. CMMC permits conditional certification when the assessment scores at least 88 of 110 points and every open requirement is POA&M-eligible, with 180 days to close them. A contractor presenting controls that verify cleanly alongside a credible POA&M for the eligible remainder will have a faster, smoother assessment and a defensible certification. A contractor presenting inflated claims that collapse under examination will face a long, adversarial assessment and, in an enforcement environment where the Department of Justice has settled multiple False Claims Act cases over cybersecurity misrepresentation, a documentary trail that works against them.

Conditional certification is a legitimate target. At least 88 of 110 points with every open requirement POA&M-eligible, and 180 days to close them. Honest claims with an eligible POA&M outperform impressive claims that fail verification.

The documentary trail outlasts the assessment. The SSP, the SPRS score, and the assessment record together form a record of what the company represented to the Department of Defense and when. A document that honestly describes a partial posture with a remediation plan is a compliance program. A document that describes a finished posture that does not exist is evidence.

Download the Full White Paper

The full paper includes the three failure modes in detail with the recognizable varieties of each, the role of examine, interview, and test in how the verdict is rendered, the four-document consistency check across the SSP, diagrams, asset inventory, and SPRS score, the interview validation problem with outsourced SSPs, the five properties of an implementation statement written against the NIST SP 800-171A determination statements, the scoping discipline for manufacturing environments, and the strategic case for conditional certification with an eligible POA&M.

Download PDF →
Related

The CMMC Decision, Second Edition

Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.

Read More →