Updated September 29, 2026
The situation is common. Years ago someone posted a cybersecurity score for your company in SPRS, the Defense Department system where suppliers report how well they meet its 110 security requirements. Behind that score sits an SSP (system security plan, the document that says how you protect your customers' sensitive data) that came out of a template, and nobody can say which of your systems it describes.
That's a bigger problem than it looks. A posted score is a statement to the government, and one you can't back up is a legal exposure, not a paperwork gap. Penn State paid $1.25 million in 2024 to settle False Claims Act allegations that included posting completion dates in SPRS and then not doing the work (Justice Department). If that's you, preserve the current score and talk to a lawyer before you change it. That process →
Then spend the first two weeks finding out what's true, fix access and scope in weeks three to five, run your routines long enough to have proof in weeks six to nine, and re-score in the last four. Rewrite the SSP only once you know what it should say. Starting there is how you get a second SSP as fictional as the first.
| Weeks | Work | You move on when |
|---|---|---|
| 1–2 | Pull your defense contracts and list the security clauses in each. Then follow one real drawing through the shop: where it arrives, who opens it, where it's saved, where it's backed up. List every system, person, and outside provider it touches. | You can describe the environment, its systems, and its CAGE codes (your company's government ID numbers) on one page, and every open question has an owner |
| 3–5 | Close anything that lets the wrong person reach sensitive data today: accounts of people who left, admins who log in with only a password, sharing links anyone can open. Settle open questions about your backup vendor and what your outside IT company can reach. Rewrite the SSP around the week-two page. | Access matches the approved user list, the SSP describes the systems you traced, and every provider has a written list of its duties |
| 6–9 | Run the recurring work and let it produce records: an access review, weekly log reviews, a vulnerability scan, a test restore from backup. Collect evidence from each tool. Run a mock assessment, a practice run of the real thing. | Each routine has run at least once with a dated record, and each finding from the mock has an owner |
| 10–13 | Close the findings, re-check every requirement a fix touched, and make the SSP, your scoring worksheet, and the SPRS draft agree. Your Affirming Official, the executive who signs for the company, decides what to submit. | A score you can back with evidence, and a written list of anything still open |
For whoever reads the contracts in week one, the clauses to list are DFARS 252.204-7012, 7021, and either 7019/7020 (older contracts) or 252.240-7997 (awards since February 1, 2026, under DoD's class deviation). The data you trace is CUI, controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive. The vulnerability scan in weeks six to nine is requirement 3.11.2.
The week-two page is the hinge of the whole plan. If it isn't done by day 15, everything after it is built on a guess, so let the plan slip rather than skip it. The same goes for any decision that stalls. If the backup vendor still hasn't said where your data lives by day 20, write down what that blocks: the SSP, the proof that backups are protected (3.8.9), and the restore test. Moving the end date without naming what it blocked isn't replanning.
Weeks six to nine feel slow, and they're where most shortcuts happen. A quarterly access review needs a quarter's worth of access to review, and a log review policy needs logs that someone actually reviewed. Leave the calendar time. Records produced in a rush the week before submission look exactly like what they are.
Every milestone needs a test someone else could check. "Access controls done" can't be checked. "The approved user list matches the Entra ID and SharePoint exports, exceptions have owners, and the two departed accounts are disabled" can.
At day 90 there are three honest outcomes: a score ready to submit, a Conditional status if every open item qualifies (the rules), or a shorter, precise list of what's left. Keep your internal 90 days separate from the official 180-day Conditional clock. They start at different times and neither resets the other. For the order to work gaps in, see which gaps to fix first.
An up-to-date SSP is required before a Level 2 assessment can be completed at all (32 CFR 170.24). A consultant will write you one in a week. It will describe the company they were told about, and it will drift the day it's signed.
Garde1 turns the week-two page into your scope, writes the SSP and 14 policies from it, collects evidence from your tools during weeks six to nine, and runs the mock assessment that feeds weeks ten to thirteen.
