Five SSP Mistakes That Fail CMMC Assessments
By Christina Sentry · 2026-07-02
Your System Security Plan is the first thing an assessor opens. These are the five mistakes we see most, and how to correct each one before it gets scored.
Your System Security Plan is the first thing an assessor opens. Before they interview a single employee or test a single control, they read your SSP. It frames everything that follows — and a weak one puts you on the back foot for the entire engagement.
After conducting and observing dozens of CMMC assessments, we see the same five mistakes surface again and again. Each one is fixable. None of them should cost you points if you know to look.
Mistake 1: Scope That Doesn't Match Reality
The SSP defines your assessment boundary. It lists every system, user, and connection that stores, processes, or transmits Controlled Unclassified Information (CUI). If what's in your SSP doesn't match what an assessor can observe on-site or in your network diagrams, the entire document loses credibility.
The most common version of this: contractors list their primary workstations but forget shared drives, cloud storage accounts (like SharePoint or Google Drive), or collaboration tools where CUI actually lives. An assessor will ask your staff where they receive and store CMMC-relevant files. If the answer points to a system outside your documented scope, expect a Practice deficiency — and potentially a scope re-evaluation that delays the whole assessment.
Fix it: Walk your documented scope against your actual data flow. Follow CUI from the moment it arrives — email, portal download, USB — through every system that touches it until it's archived or destroyed. Every stop on that journey must be in scope.
Mistake 2: Control Descriptions That Are Too Generic
CMMC Level 2 maps to NIST SP 800-171. Each of the 110 practices requires you to describe how your organization implements it, not just that you do. Generic statements like "We use firewalls" or "Access is controlled by policy" are not descriptions — they're assertions.
Assessors are trained to identify what the CMMC Assessment Guide calls "not implemented" versus "partially implemented." A one-sentence description of a complex control like AC.2.006 (control the use of portable storage devices on external systems) tells an assessor you either don't fully understand the requirement or haven't thought through your implementation.
Fix it: For each practice, answer three questions in your SSP: What specific tool or mechanism implements this control? Who is responsible for operating it? How would you demonstrate to an auditor that it works? If you can't answer all three, the control isn't fully documented — and an assessor will find that gap.
Mistake 3: POA&M Items With No Realistic Closure Dates
A Plan of Action and Milestones (POA&M) is not a list of excuses — it's a commitment. CMMC allows you to enter an assessment with open POA&M items, but assessors evaluate whether each item has a credible, time-bound remediation plan. A POA&M entry that says "Q4 2025" — written in 2024 and never updated — signals that your organization doesn't take the plan seriously.
Worse, some contractors use the POA&M as a catch-all for controls they simply haven't prioritized. If more than 20–25% of your 110 practices are on your POA&M, an assessor will question whether you've made a genuine compliance effort or are treating the assessment as a paperwork exercise.
Fix it: Before your assessment, audit every open POA&M item. Update the milestone dates to reflect your actual current timeline. For each item, confirm the person responsible is still in that role and still owns the task. Close anything you can close before the assessment starts — points you earn before day one are points you don't have to defend.
Mistake 4: Missing or Outdated Network Diagrams
Your SSP must include network architecture diagrams showing how CUI flows through your environment. These diagrams are often the first thing a technical assessor turns to — they use them to verify your scope, validate your segmentation claims, and identify systems that may have been left out.
Contractors who built their SSP three years ago frequently have diagrams that predate cloud migrations, new locations, remote work infrastructure, or acquisitions. An assessor who spots a VPN concentrator not shown on your diagram, or a cloud tenant not represented in your architecture, now has reason to question every other claim in the document.
Fix it: Treat your network diagram as a living document. Update it whenever you add a new system, migrate a service, or change how CUI flows. Before your assessment, verify it against your actual network — pull a current asset inventory and confirm every device that touches CUI appears correctly.
Mistake 5: No Evidence of Policy Acknowledgment or Training
CMMC includes several practices in the Awareness and Training (AT) family that require you to demonstrate, not just claim, that your staff has received security training. Your SSP may describe a training program, but if you have no records — completion logs, sign-off sheets, LMS exports — an assessor cannot score those practices as implemented.
The same applies to policy acknowledgment. If your Acceptable Use Policy or CUI Handling Policy requires annual employee sign-off, your SSP should say so and your records should prove it. Many small contractors have the policies but have never collected acknowledgment records, making it impossible to demonstrate compliance.
Fix it: Before your assessment, pull your training completion records and policy acknowledgment records for the past twelve months. Confirm every current employee with CUI access appears in both. If records are missing, hold a makeup session and document it. An assessor who sees a current, complete training record will score AT practices as implemented — one who sees nothing will not.
An SSP doesn't have to be perfect to support a successful assessment. It has to be honest, specific, and current. Assessors are looking for evidence of a real security program, not a document that says the right words. These five fixes take the most common reasons SSPs fail and remove them before the assessment clock starts.
If you'd like an expert review of your SSP before your C3PAO engagement begins, contact Cipher Sentinel for a gap assessment.