Search for a CMMC SSP template and you'll find two extremes: blank federal shells with 200 empty fields, and vendors selling "pre-filled" documents that describe a company that isn't yours. Both miss what the System Security Plan actually is — the document that anchors your entire compliance story, the one SPRS asks you to name when you post your score, and the first thing an assessor or prime reads. Here's its anatomy, section by section, with examples of what good looks like.

Section 1 — System Identification

The administrative header: system name (give it one — "ACME-CUI-ENCLAVE" beats "our network"), your CAGE code, the responsible owner and point of contact, physical locations, and the date and version. Trivial to write, and the version matters more than it looks: SPRS records your SSP name and version, so this block is what ties your posted score to a specific document.

Section 2 — System Description and Boundary

Where CUI lives and what's in scope: the environment (cloud tenant, on-prem servers, endpoints), the people who touch CUI, and — critically — the boundary line. Everything inside the boundary answers to all 110 controls; everything outside needs a sentence explaining why it's outside. This section is where good scoping pays for itself: a deliberate CUI enclave here can shrink every section that follows.

Include or reference a simple network diagram. Assessors ask for one almost immediately, and a hand-drawn-but-accurate diagram beats a beautiful stale one.

Section 3 — The Per-Control Implementation Statements

The meat: one statement for each of the 110 requirements describing how your organization implements it. This is where templates fail people, because no template can know that you use Microsoft 365 Business Premium, Duo for MFA, and a locked closet in Fairfax. The test for every statement: could a stranger verify it? That means naming the tool, the scope, the setting, and the evidence.

Here's the difference, using AC.L2-3.1.1 (limit system access to authorized users):

Weak: "Access to systems is limited to authorized users."

Defensible: "All CUI resides in the ACME-CUI-ENCLAVE (M365 GCC tenant). Access requires an individually named account in Azure AD, approved by the owner via the onboarding checklist (POL-AC-01). Shared accounts are prohibited by policy and disabled by audit. The current authorized-user list is reviewed quarterly; the last review was July 2026."

The weak version restates the requirement — an assessor reads it as "not documented." The defensible version names the system, the mechanism, the policy, the cadence, and the evidence trail. You need 110 of these, which is why this section is roughly 70% of the whole CMMC workload.

Section 4 — Gaps, N/As, and the Honesty Rule

Controls you haven't implemented yet belong in the SSP too — stated plainly and cross-referenced to your POA&M, not disguised with aspirational language. "FIPS-validated encryption is not yet implemented for data at rest on laptops; see POA&M item 12, target October 2026" is a compliant sentence. "We employ industry-standard encryption" is a False Claims Act deposition waiting to happen. The same goes for N/A claims: every "not applicable" needs a written justification tied to your scope.

Why honesty wins mechanically, not just morally: the DoD Assessment Methodology defines your SPRS score as an assessment of the SSP. An SSP that overclaims produces a score you can't defend; an SSP that states gaps produces a lower score with a paper trail — and a POA&M showing motion. Contracting officers see the second pattern as a supplier managing risk, and the first as a liability.

Where to Get a Template — Three Honest Options

The SSP that writes itself from your answers

Do the free 110-control assessment first. When you're ready, $149/month turns those same answers into your SSP, POA&M, and all 14 policies — named tools, real cadences, honest gaps. See a sample SSP before you pay anything.

Start with the free assessment →
Free to assess · No credit card · Documents $149/mo

The Sections People Forget