What the SSP is
Your System Security Plan (SSP) is the central document of your CMMC program. It describes your system, your boundary, and how your organization meets each requirement.
There are two ways to build it in Secureframe. The recommended path is completing the Defense Navigator, which fills out your SSP as you go. You can also work directly in the SSP builder and complete everything manually.
If you are using Navigator (recommended)
As you complete the Navigator modules, your SSP fills in behind the scenes:
Organization Details: Your company information and system description populate the SSP's program details.
CMMC Scoping: Your scoping answers mark assessment objectives in or out of scope, and anything Not Applicable gets a documented justification. See CMMC Scoping.
CUI Enclave Setup: Once your scoping and enclave setup are complete, implementation statements are generated for your assessment objectives based on your scoping answers and connected technology. See CUI Enclave Setup.
Policies: Published policies are automatically linked to their corresponding CMMC requirements. See CMMC Policies in Defense Navigator.
Complete Navigator first, then open your SSP to review what has been built, adjust anything that does not match how you operate, and fill in what is left.
If you have completed Navigator and do not see generated content, reach out to your CSM.
If you are working manually
Everything in the SSP can also be completed directly in the builder. You author implementation statements yourself, mark each assessment objective's status, and complete each section by hand. The builder structures the work for you, with each control broken into its objectives and control discussion available for guidance, and you can import implementation statuses from Secureframe Comply.
Access the SSP builder
From the left-hand navigation, under Defense, select System Security Plans.
Create a new SSP
Click + Add to create your SSP.
Give your SSP a name and select your framework.
The framework selection determines which requirements are automatically added to your SSP. After creating it, you land on an overview page showing each section's name, description, and status, so you always know your progress and what is left.
Populate the required sections
Navigate through each section and complete the required fields:
Program Details: An overview of your organization's security program, including its purpose, scope, and objectives.
Key Contacts: The individuals responsible for the security and maintenance of the system.
Control Implementation: Each CMMC control broken down into its assessment objectives, with implementation statements.
External Service Providers: All external connections to the system, including vendors and cloud services.
Services, Ports, and Protocols: The services, ports, and protocols in use in your environment.
Policies and Procedures: The security policies and procedures that govern system operations.
Attachments: A repository for supporting documentation related to the SSP.
How generated statements behave
When implementation statements are drafted for you:
If an assessment objective has no statement yet, the drafted statement is written straight in.
If you have already written content for an objective, nothing is overwritten. You will see a Proposed changes banner with a card for each affected objective showing what is proposed and where it came from. Accept to add the drafted content alongside your text, or ignore to keep things as they are.
If an objective is out of scope from your CMMC Scoping answers, the proposed statement is the documented justification. Accepting it replaces the existing text, since the objective no longer applies.
Proposals can be accepted or ignored individually or in bulk.
If your scoping answers or connected technology change, Secureframe proposes updated statements for the affected objectives, so your SSP keeps reflecting your actual environment.
Track implementation status
The Control Implementation page lists all 110 CMMC Level 2 controls by control family, with filtering, sorting, and search. Click any control to open a panel with its assessment objectives.
For each assessment objective, mark Implemented, Not Implemented, or Not Applicable, and review its implementation statement. You can also add attachments or POA&M items to each assessment objective from the same panel.
Statuses roll up: once all of a control's objectives are Implemented or Not Applicable, the control is marked Implemented and you receive the SPRS points for that control.
Create POA&Ms for any gaps
As you work through the Control Implementation page, you will likely find items that are not fully implemented. For those, create a Plan of Action and Milestones (POA&M) item to document the gap and track remediation. Learn more: Creating and Managing POA&Ms
Export your SSP
Download attachment files bundles evidence attached to individual controls, not only files in the top-level Attachments section.
Navigate to the Exports tab from the main SSP page.
Click Generate export, add a brief description, and click Generate. The export may take up to a minute.
When it is ready, open the menu next to the export and select Download. Check the corresponding boxes to include your attachments and policy files.
Exports are generated as Word documents, ready to share with your assessor or prime.
Frequently Asked Questions (FAQ)
How do I access the SSP module?
The SSP is available on select plans. If you do not currently see it, contact [email protected] or reach out to your Account Manager.
Will the generated statements overwrite what I have written?
When you accept a proposal, your existing statement text is generally preserved while generated language is updated to reflect changes in your environment. For example, after a technology is disconnected and the statement is re-evaluated, a proposal may update or remove related generated language. For Not Applicable objectives, accepting replaces the statement with the documented justification because the objective no longer applies.
Will importing data from Secureframe Comply overwrite my SSP content?
Importing from Secureframe Comply only overwrites the implementation response status for assessment objectives. It will not overwrite implementation statements or narrative content already entered in the SSP.
When should I import data from Secureframe Comply into the SSP?
Complete your implementation work in Secureframe Comply first, then import into the SSP. If needed, you can import only vendors and policies to avoid updating implementation statuses.
Does the SSP "Download attachment files" export include control-level evidence?
Yes. The export now bundles evidence attached to individual controls, not only files in the top-level Attachments section.
