CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

System Security Plan, policy and POA&M

The documents an assessor actually reads.

Writing the documents an assessor reads: the System Security Plan, the policy set, and a POA&M naming every open control.

Writing a System Security Plan, the policy set behind it, and a Plan of Action and Milestones for CMMC Level 2, written against your actual environment, not a template.

What it is

A System Security Plan, the SSP, is the document that says, control by control, how your business meets each of the 110 NIST SP 800-171 requirements, where CUI lives, and who is responsible. The policies are the written rules the plan points to. The POA&M, the Plan of Action and Milestones, lists every control not yet met, what closing it takes, and who owns it.

Why it matters

You cannot post a score to SPRS without a System Security Plan in place, and it is the first document an assessor reads. A gap assessment tells you where you stand. This is the work that writes it down, so it can be scored, affirmed and assessed.

Is this the right service?

SCOPED, NOT PRICED

Who it is for

A contractor that knows its gaps, often from a gap assessment, and needs the documents written: no SSP yet, an SSP that no longer matches the environment, or policies copied from a template.

How it starts

With your current state. If you have a recent gap assessment, we write from its findings. If you do not, we start with one, because a plan written before the gaps are known describes an environment nobody has checked.

How it differs

The $5,000 gap assessment does not write an SSP or policies, and does not review policies: it scores you and gives you a broad POA&M. This service writes the documents. CMMC In A Container includes the same documents and keeps them current as part of a managed program.

What you receive

A System Security Plan written against your environment as it actually is.The policy set behind it, each policy mapped to the controls it satisfies.A POA&M naming every open control, what closing it requires, and who owns it.Documents you keep and your own team can maintain.

What this is not

Documentation, not remediation: we write the plan and the policies, we do not implement the controls they describe or collect your evidence under this engagement. We are not an Authorized C3PAO.

Book a 30-minute call.

BOOK A CALL

Scoped per client, so the first step is a conversation. Pick a time.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Talk to us about it.

This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.

Book a 30-minute call

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant