Draft your System Security Plan — the part that actually takes time
Answer plain-English questions about how you meet the Access Control and Identification & Authentication requirements of NIST SP 800-171, and this tool assembles assessor-ready SSP narrative language for each one — plus draft POA&M entries for the gaps. It's a starting draft you edit and own, not a substitute for your own assessment.
Covers families 3.1 (Access Control, 22 requirements) and 3.5 (Identification & Authentication, 11 requirements). Narrative is written to the NIST SP 800-171A assessment objectives. Self-assessment aid only — see disclaimer.
Step 1
Tell us about your environment
These fill into every narrative so the output reads like your real system. Leave blanks and we'll use a neutral placeholder you can find-and-replace later.
Step 2
How do you meet each requirement?
Pick the honest answer for each. A requirement only counts as implemented if it's fully in place and documented.
Step 3
Your draft SSP sections
0 implemented · 0 on the POA&M · 0 N/A. Review every line before it goes in your real SSP.
Get the editable version
Enter your email and we'll send you this draft plus a heads-up when the full multi-family generator and other CMMC tools drop. Your draft is also right above — copy or print it anytime.
🔒 No spam — just useful CMMC tools.
✓
You're on the list
Your SSP draft is on its way, and I'll let you know the moment the next tool is ready. No spam, ever.