System Security Plan, policy and POA&M
The documents an assessor actually reads.
Writing the documents an assessor reads: the System Security Plan, the policy set, and a POA&M naming every open control.
Writing a System Security Plan, the policy set behind it, and a Plan of Action and Milestones for CMMC Level 2, written against your actual environment, not a template.
What it is
A System Security Plan, the SSP, is the document that says, control by control, how your business meets each of the 110 NIST SP 800-171 requirements, where CUI lives, and who is responsible. The policies are the written rules the plan points to. The POA&M, the Plan of Action and Milestones, lists every control not yet met, what closing it takes, and who owns it.
Why it matters
You cannot post a score to SPRS without a System Security Plan in place, and it is the first document an assessor reads. A gap assessment tells you where you stand. This is the work that writes it down, so it can be scored, affirmed and assessed.
Is this the right service?
SCOPED, NOT PRICEDWho it is for
A contractor that knows its gaps, often from a gap assessment, and needs the documents written: no SSP yet, an SSP that no longer matches the environment, or policies copied from a template.
How it starts
With your current state. If you have a recent gap assessment, we write from its findings. If you do not, we start with one, because a plan written before the gaps are known describes an environment nobody has checked.
How it differs
The $5,000 gap assessment does not write an SSP or policies, and does not review policies: it scores you and gives you a broad POA&M. This service writes the documents. CMMC In A Container includes the same documents and keeps them current as part of a managed program.
The $5,000 gap assessment, CMMC In A Container™, or all three side by side.
What you receive
What this is not
Documentation, not remediation: we write the plan and the policies, we do not implement the controls they describe or collect your evidence under this engagement. We are not an Authorized C3PAO.
Book a 30-minute call.
BOOK A CALLScoped per client, so the first step is a conversation. Pick a time.
What happens in 30 minutes
- We read your contract's CMMC and DFARS clauses with you.
- We confirm which level applies and how it will be assessed.
- We tell you the first step, whether or not it involves us. No slides.
Talk to us about it.
This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.