Three terms come up in nearly every CMMC conversation, and they get used loosely enough that people mix them up constantly. The System Security Plan, the POA&M, and the SPRS score are not the same thing, and they do not do the same job. Once you see how they connect, a lot of the confusion around CMMC documentation clears up.
Quick Answer
The SSP describes how your organization implements the NIST SP 800-171 security requirements. The POA&M lists what is not fully implemented yet and the plan to fix it, within limits set by CMMC. The SPRS score is the number that results from measuring your implementation against all 110 requirements, entered into a government system for applicable self-assessments and affirmations. The SSP explains, the POA&M tracks what is unfinished, and SPRS scores the result.
What the System Security Plan Documents
An SSP is not a policy statement. It is a working description of how each of the 110 NIST SP 800-171 requirements is met in your specific environment, which systems are in scope, and who is responsible for each control. An assessor reading it should be able to picture how your organization operates, not just see a list of requirements marked complete.
The most common problem with an SSP is not that it was written wrong the first time. It is that it stops getting updated. A migration to a new cloud environment, a change in who manages a system, a new vendor handling part of the workflow, any of these can make an SSP describe an environment that no longer exists. An outdated SSP is one of the more frequent findings in a readiness review, and it is usually not because the original document was bad, just old.
What a POA&M Is, and What It Is Not
A Plan of Action and Milestones documents a requirement that is not yet fully met, along with the plan and timeline to close it. It is a normal part of CMMC, not a red flag on its own. What trips people up is assuming every open item can go on a POA&M. It cannot.
Conditional Level 2 status has specific rules attached. The organization needs to hit an 80 percent score threshold, a defined set of higher-priority requirements has to be fully met rather than deferred, and any items placed on a POA&M need to close within 180 days of the assessment. A readiness review should catch which gaps qualify for a POA&M and which ones need to be closed before the assessment happens, not after.
SSP
Describes how each security requirement is implemented across your environment, and who owns it.
POA&M
Documents requirements that are not yet fully met, with a plan and deadline to close them.
SPRS Score
The weighted score reflecting how many of the 110 requirements are implemented, entered into SPRS.
How the SPRS Score Ties These Together
SPRS stands for Supplier Performance Risk System, the database where applicable NIST SP 800-171 self-assessment scores and affirmations are entered. The score is not a simple count of requirements met. It uses a weighted methodology where different requirements carry different point values out of a maximum of 110, so two organizations with the same number of unmet requirements can end up with different scores depending on which ones they are.
The SSP and POA&M are what the score is based on. If the SSP no longer reflects the environment, or a POA&M item was quietly closed without updating the record, the SPRS score stops being accurate too. Contracting officers can review this score, so keeping it current is not just an internal documentation task, it affects how the organization looks to the people awarding contracts.
Is SPRS a Cloud System
This comes up often enough to clear up directly. SPRS is not a cloud environment your organization sets up or hosts. It is a government system you log into to enter and view scores and assessment information. It has nothing to do with where your Controlled Unclassified Information lives, that is a separate decision involving platforms like GCC High. SPRS holds your score. It does not hold your data.
Where These Documents Commonly Go Wrong
- Treating the SSP as a one-time deliverable instead of a living document that needs updates as the environment changes.
- Assuming any unmet requirement automatically qualifies for a POA&M, without checking which ones do.
- Letting the SPRS score go stale after remediation work, so it no longer reflects current implementation.
- Confusing SPRS, the scoring system, with the cloud environment that stores CUI.
- Relying entirely on software output without anyone reviewing whether the documented controls match what is really happening.
Keeping the SSP, POA&M, and SPRS score aligned is ongoing work, not a task you finish once and file away. Sentinel Blue’s post on best practices for CMMC assessment preparation covers how to pressure test these documents before an assessment, and the post on managed CMMC compliance covers what it takes to keep them current after certification.
CMMC Readiness AssessmentA readiness review is where most SSP, POA&M, and SPRS problems get caught before they become assessment findings.
Frequently Asked Questions
What is a System Security Plan in CMMC?
What is a POA&M and how does it work in CMMC?
What is SPRS and why does the score matter?
Is SPRS a cloud platform contractors need to set up?
How often should an SSP and POA&M be updated?
Can software alone keep an SSP, POA&M, and SPRS score accurate?
Not sure if your SSP, POA&M, and SPRS score still match your environment?
Sentinel Blue helps contractors review and update this documentation before it becomes a finding during an assessment.