Updated September 29, 2026
Keep one page of facts (the system's name, your CAGE codes, your IT providers, your devices, your locations) and make your security plan, your scoring worksheet, and your SPRS entry all copy from it.
Three documents are involved. The SSP (system security plan) describes how you protect CUI, the controlled drawings and technical data a defense customer sends you. The worksheet is where you score yourself against the 110 CMMC requirements. SPRS (the DoD's Supplier Performance Risk System) is the government website where you post the resulting score, and where your primes look it up.
If the plan describes one company and the score describes another, the score has nothing under it. An assessor stops trusting everything else the moment they notice, and a posted score you can't back up is a statement to the government that can turn into a False Claims Act problem (what an unsupported score risks). The usual cause isn't dishonesty. It's a plan written last winter.
What drift looks like
Here is version 3 of the SSP at a 20-person machine shop, next to what's true on the day they plan to submit:
| SSP v3 says | True today | What it pulls in | What an assessor checks | |
|---|---|---|---|---|
| CAD files | Stored in SharePoint only | Local copies on laptops ENG-01 to ENG-07 | Seven laptops join the scope and need disk encryption | 3.13.16, protecting stored CUI |
| IT support | MSP-A | MSP-B since March | A new split of who does what; MSP-B's admin accounts need multi-factor login and logging | 3.5.3 and 3.3.1 |
| Locations | One office | Office plus two remote workers | Remote access has to be described and proven | 3.1.12, worth 5 points |
| System name | "Corporate IT" | "Engineering E-04" | Nothing, but the name must match SPRS word for word | The SPRS scope field |
(An MSP is a managed service provider, the outside company that runs your IT.)
Changing the date on the cover fixes none of this. Each row goes back to whoever owns that fact: the engineering lead for the CAD files, the MSP contract for support. The SSP, the device list, and the network diagram change together, and every requirement the change touches gets scored again. A new MSP alone moves access control, logging, and incident response. When a vendor change means reassessment
Write sentences someone can check
The more common SSP problem is that nothing in it can be checked. Compare:
Before: The company follows the principle of least privilege and industry best practices for access control.
After: Access to the engineering SharePoint site is granted only through the ENG-Users group in Entra ID. The engineering manager approves each addition in the IT ticket queue, and the IT lead makes the change. Group membership is listed in the user inventory and reviewed every quarter by the engineering manager. Exceptions go in the exceptions log.
Entra ID is Microsoft's account system; ENG-Users is a named group in it. Every sentence in the second version points to something an assessor can open: a group, a ticket, an inventory, a review. Point to the inventory rather than pasting 40 account names into the SSP. The inventory stays current and the SSP stays readable.
The five-minute test
Pick three statements from your SSP that matter and ask the person who owns each one to show you the proof while you watch. If the SSP says access is reviewed quarterly, they open the last review. If it says backups cover the project library, they open the backup job and the last test restore. If it says outside sharing is blocked, they open the sharing setting in the SharePoint admin center and try to share a file with a Gmail address.
Anything they can't show in five minutes is a finding. Fix the system or fix the sentence, but don't rewrite the sentence to describe whatever happens to be easy to show. That's how SSPs end up describing a company nobody works at.
When all three pass, write the SSP version number into your SPRS records so the score and the document point at each other. The SPRS entry itself asks for the scope, employee count, and CAGE codes covered (SPRS entry guide); the SSP requirement, 3.12.4, asks for the boundary, how the system operates, how each requirement is met, and what it connects to (NIST SP 800-171 Rev. 2). Submitting in SPRS
Garde1 keeps that page of facts as your scope and writes the SSP and 14 policies from it. When the scope changes, say the MSP, it flags which document sections went stale, and why, that same day, and you regenerate them.
