NEW FIELD GUIDES  |  Free, practical CMMC guidance from an authorized C3PAO. Browse all guides → NEW FIELD GUIDES  |  Free, practical CMMC guidance from an authorized C3PAO. Browse all guides → NEW FIELD GUIDES  |  Free, practical CMMC guidance from an authorized C3PAO. Browse all guides → NEW FIELD GUIDES  |  Free, practical CMMC guidance from an authorized C3PAO. Browse all guides →

Home / Blog / CMMC & Cybersecurity

CMMC & Cybersecurity September 29, 2026 7 min read

SSP, POA&M, and SPRS Explained for CMMC Compliance

Sentinel Blue
Sentinel Blue 7 min read
SSP, POA&M, and SPRS Explained for CMMC Compliance

Three terms come up in nearly every CMMC conversation, and they get used loosely enough that people mix them up constantly. The System Security Plan, the POA&M, and the SPRS score are not the same thing, and they do not do the same job. Once you see how they connect, a lot of the confusion around CMMC documentation clears up.

Quick Answer

The SSP describes how your organization implements the NIST SP 800-171 security requirements. The POA&M lists what is not fully implemented yet and the plan to fix it, within limits set by CMMC. The SPRS score is the number that results from measuring your implementation against all 110 requirements, entered into a government system for applicable self-assessments and affirmations. The SSP explains, the POA&M tracks what is unfinished, and SPRS scores the result.

What the System Security Plan Documents

An SSP is not a policy statement. It is a working description of how each of the 110 NIST SP 800-171 requirements is met in your specific environment, which systems are in scope, and who is responsible for each control. An assessor reading it should be able to picture how your organization operates, not just see a list of requirements marked complete.

The most common problem with an SSP is not that it was written wrong the first time. It is that it stops getting updated. A migration to a new cloud environment, a change in who manages a system, a new vendor handling part of the workflow, any of these can make an SSP describe an environment that no longer exists. An outdated SSP is one of the more frequent findings in a readiness review, and it is usually not because the original document was bad, just old.

What a POA&M Is, and What It Is Not

A Plan of Action and Milestones documents a requirement that is not yet fully met, along with the plan and timeline to close it. It is a normal part of CMMC, not a red flag on its own. What trips people up is assuming every open item can go on a POA&M. It cannot.

Conditional Level 2 status has specific rules attached. The organization needs to hit an 80 percent score threshold, a defined set of higher-priority requirements has to be fully met rather than deferred, and any items placed on a POA&M need to close within 180 days of the assessment. A readiness review should catch which gaps qualify for a POA&M and which ones need to be closed before the assessment happens, not after.

SSP

Describes how each security requirement is implemented across your environment, and who owns it.

POA&M

Documents requirements that are not yet fully met, with a plan and deadline to close them.

SPRS Score

The weighted score reflecting how many of the 110 requirements are implemented, entered into SPRS.

How the SPRS Score Ties These Together

SPRS stands for Supplier Performance Risk System, the database where applicable NIST SP 800-171 self-assessment scores and affirmations are entered. The score is not a simple count of requirements met. It uses a weighted methodology where different requirements carry different point values out of a maximum of 110, so two organizations with the same number of unmet requirements can end up with different scores depending on which ones they are.

The SSP and POA&M are what the score is based on. If the SSP no longer reflects the environment, or a POA&M item was quietly closed without updating the record, the SPRS score stops being accurate too. Contracting officers can review this score, so keeping it current is not just an internal documentation task, it affects how the organization looks to the people awarding contracts.

Is SPRS a Cloud System

This comes up often enough to clear up directly. SPRS is not a cloud environment your organization sets up or hosts. It is a government system you log into to enter and view scores and assessment information. It has nothing to do with where your Controlled Unclassified Information lives, that is a separate decision involving platforms like GCC High. SPRS holds your score. It does not hold your data.

Where These Documents Commonly Go Wrong

  • Treating the SSP as a one-time deliverable instead of a living document that needs updates as the environment changes.
  • Assuming any unmet requirement automatically qualifies for a POA&M, without checking which ones do.
  • Letting the SPRS score go stale after remediation work, so it no longer reflects current implementation.
  • Confusing SPRS, the scoring system, with the cloud environment that stores CUI.
  • Relying entirely on software output without anyone reviewing whether the documented controls match what is really happening.

Keeping the SSP, POA&M, and SPRS score aligned is ongoing work, not a task you finish once and file away. Sentinel Blue’s post on best practices for CMMC assessment preparation covers how to pressure test these documents before an assessment, and the post on managed CMMC compliance covers what it takes to keep them current after certification.

Related

CMMC Readiness AssessmentA readiness review is where most SSP, POA&M, and SPRS problems get caught before they become assessment findings.

Read the guide →

Frequently Asked Questions

What is a System Security Plan in CMMC?+
A System Security Plan, or SSP, is the document that describes how an organization has implemented the NIST SP 800-171 security requirements across its systems, people, and processes. It names what is in scope, how each requirement is met, and who owns it. An assessor reads the SSP alongside the evidence and interviews, so it needs to describe the environment as it operates now, not as it was originally designed a year or two ago.
What is a POA&M and how does it work in CMMC?+
A Plan of Action and Milestones, or POA&M, documents a security requirement that is not yet fully met and lays out the plan and timeline for closing it. Not every open requirement is eligible for a POA&M under CMMC. Conditional Level 2 status requires an 80 percent score threshold, limits which requirements can remain open, and requires the organization to close those items within 180 days of the assessment.
What is SPRS and why does the score matter?+
SPRS is the Supplier Performance Risk System, the database where applicable NIST SP 800-171 self-assessment scores and affirmations are entered. The score reflects how many of the 110 security requirements are implemented, using a weighted methodology where different requirements carry different point values, so it is not simply a count of items completed. Contracting officers can review this score, which makes an outdated or inflated one a real risk, not just a paperwork issue.
Is SPRS a cloud platform contractors need to set up?+
No. SPRS is a government system contractors log into to enter and view scores and assessment information, not a cloud environment an organization builds or hosts. It is separate from cloud platforms like GCC High that contractors use to store and process Controlled Unclassified Information. The two get confused often enough that it is worth stating plainly, SPRS holds your score, it does not host your data.
How often should an SSP and POA&M be updated?+
Whenever the environment they describe changes in a way that affects a security requirement, not on a fixed annual schedule alone. New systems, new vendors, staffing changes, and infrastructure migrations can all shift what the SSP should say. An SSP that has not been touched in a year is a common finding during readiness reviews, since the environment it describes has usually moved on without it.
Can software alone keep an SSP, POA&M, and SPRS score accurate?+
Software can help track requirements and generate documentation, but it cannot judge whether a control is genuinely operating the way the SSP describes it. That still requires someone to review evidence, talk to the people running the control, and update the score and documentation to match what is really happening. Treating a tool’s output as the final answer is one of the more common ways an SPRS score ends up out of date.

Not sure if your SSP, POA&M, and SPRS score still match your environment?

Sentinel Blue helps contractors review and update this documentation before it becomes a finding during an assessment.

Share: LinkedIn X / Twitter Email

Ready to get to work? So are we.

Our cyber adversaries aren't waiting and neither are we. Let's get the conversation started.

Contact Us Today