For any contractor meeting NIST 800-171, two documents carry the program: the System Security Plan and the Plan of Action and Milestones. Assessors read them first. Get them right and you have a defensible posture. Get them wrong and no amount of good security underneath will show.
Here is what each one is for and how to write them so they hold up.
The System Security Plan
The SSP describes your system and how it meets each of the 110 NIST 800-171 controls. It defines the boundary of the system that handles Controlled Unclassified Information, the environment around it, and the specific way each control is satisfied. It is the single source of truth an assessor uses to understand your environment.
A good SSP is specific. For each control, it says what you actually do, not what the control requires. Naming your tools, your configurations, and your responsible roles is the difference between a plan that reflects reality and one that recites the standard.
The Plan of Action and Milestones
No one meets all 110 controls on day one. The POA&M is the honest record of what you do not yet meet and how you will close each gap. For every open control, it lists the deficiency, the planned remediation, an owner, and a target date.
A POA&M is not an admission of failure. It is evidence of a managed program. Assessors expect gaps. What they judge is whether you know about them and have a credible plan. An empty POA&M paired with a low real posture is a red flag, not a strength.
How They Work Together
The SSP says what you do. The POA&M says what you have not done yet and when you will. Together they should reconcile perfectly with your SPRS score. If your SSP claims a control is met but your score deducts for it, or your POA&M lists a gap the SSP calls closed, the inconsistency is exactly what an assessor catches.
Where They Fall Apart
- Templated SSPs that describe the standard instead of your actual system.
- Controls marked met with no evidence or detail behind them.
- A POA&M with vague remediations and no owners or dates.
- Milestones that passed months ago with no update.
- SSP, POA&M, and SPRS score that do not agree with each other.
Every one of these is avoidable. They come from treating the documents as paperwork rather than as the description of a real program.
Keep Them Living
An SSP and POA&M are not one-time deliverables. As you close gaps, update the POA&M and revise the SSP and your score. As your environment changes, the SSP has to follow. Documents that were accurate a year ago and untouched since are their own kind of finding.
Frequently Asked Questions
Is a POA&M a bad sign?
No. Open items are expected. A POA&M shows you know your gaps and have a plan. What matters is that the remediations are credible and the milestones are current.
How detailed does the SSP need to be?
Detailed enough that an assessor can see exactly how each of the 110 controls is met in your environment, with specific tools, configurations, and responsible roles. Generic restatements of the control are not enough.
Do the SSP, POA&M, and SPRS score need to match?
Yes. They should reconcile exactly. Inconsistencies between them are one of the first things an assessor looks for.
If your SSP and POA&M have drifted from reality, that gap is your real exposure. A NIST 800-171 assessment rebuilds them around your actual environment. Talk with a senior advisor at JBW Group.