HomeControl Library › 3.12.4
3.12 Security AssessmentRequired · SSP

3.12.4 — Write your System Security Plan (SSP)

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

Document how you meet every requirement — the SSP is mandatory, and without it you can't be assessed.

What it actually means

Develop, document, and periodically update a System Security Plan (SSP) that describes your system boundaries, operating environment, how each security requirement is implemented, and connections to other systems. The SSP is the backbone of your whole assessment: it's worth zero points, but without it an assessment can't even be completed — and the absence of an SSP is itself non-compliance with DFARS 252.204-7012.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

This requirement carries no point value, but it is mandatory: it is not POA&M-eligible, and without an SSP no SPRS score can be reported. Treat it as the first thing you build, not the last. Our free SSP generator gives you a starting draft.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library