The SPRS portal asks for very little: a score, an assessment date, a scope, and a POA&M completion date. That minimalism misleads people. The number you post is a summary of an assessment the government assumes you actually performed — and everything that makes the number defensible lives outside the portal, in documents you keep. Here's the full stack, in the order you should build it.

The Score Is Anchored to a Document, Not a Feeling

The DoD Assessment Methodology is explicit about what a NIST SP 800-171 assessment is: a review of how your System Security Plan implements the 110 controls. Under the methodology, the absence of an SSP means the assessment cannot be completed — there's nothing to assess. So a posted score with no SSP behind it isn't a thin assessment; it's a number with no assessment at all.

CMMC practitioners compress this into a rule worth taping to your monitor:

Not documented = not met.

The Documentation Stack, In Build Order

1. Scope statement

One or two pages: where CUI enters your business, which systems store or transmit it, who has access, and where the boundary sits. Every later document inherits this decision — and a deliberately small boundary (a CUI enclave) is the biggest cost-saver available to a small contractor. Our scoping guide covers the asset categories.

2. System Security Plan (SSP)

The master document: for each of the 110 controls, how your organization implements it — the tool, the setting, the process, the person responsible. Assessors read this first, primes request it most, and per the methodology your score is formally an assessment of this document. See what goes in an SSP if you're starting from zero.

3. Assessment record

The working record of the self-assessment itself: each control's status (met / not met / N/A with justification), the date, who made the call, and what was reviewed to make it. This is the artifact that turns "we posted 85" into "here is how we got 85." Keep it current — a status that changes should carry a date and a reason.

4. Plan of Action & Milestones (POA&M)

Every unmet control, its point value, a remediation owner, and a realistic date. The SPRS portal asks when the POA&M will be complete, so this document feeds your submission directly. POA&M mechanics here — including which controls can't sit on one forever.

5. Per-control evidence

For each "met" claim: the screenshot, the configuration export, the signed policy, the training record. Evidence doesn't get uploaded anywhere — it gets retained, so that any met control can be demonstrated within a day of being asked. A simple folder-per-control structure beats a clever system you won't maintain.

6. Policies

The 14 policy families an assessor expects (access control, incident response, media protection, and so on). Many controls are only "met" when the technical setting is paired with a written, approved policy — a firewall rule without a policy is half a control. What the policy set covers.

If an MSP or cloud platform does some of this for you: document who does what, control by control, in a Shared Responsibility Matrix. "Our MSP handles it" is not a control status — it's the beginning of one. You still own the outcome.

The Walkthrough, End to End

  1. Scope first. Boundary, CUI flows, asset list. Half a day of honest thinking that saves weeks downstream.
  2. Assess each control against its objectives. NIST SP 800-171A breaks every control into the specific objectives an assessor verifies. Judge yourself against those, not against the one-line requirement — it's the difference between "we have MFA" and "MFA covers all accounts, including the owner's laptop and that one shared login."
  3. Record status honestly, with the math visible. Unmet controls subtract 1, 3, or 5 points from 110. The full scoring method — resist the urge to round up. A defensible 72 beats an indefensible 95.
  4. Write the SSP and POA&M from the assessment — not as separate creative-writing projects. The SSP describes what's implemented; the POA&M holds what isn't. Together they account for all 110.
  5. Post to SPRS at sprs.apps.mil (you'll need your SAM registration and PIEE access), entering the score, date, scope, and POA&M completion date.
  6. Diarize the maintenance: the annual affirmation, evidence refreshes, and a re-assessment whenever your environment materially changes — not just when the three-year clock runs out.

The assessment is free. The paperwork is $149.

CMMC Map walks all 110 controls in plain English and scores you live — free, no card. When you're ready for the documentation, it generates the SSP, POA&M, and all 14 policies from the answers you already gave. No blank pages.

Start the free assessment →
Free to assess · Documents $149/mo

The Mistakes That Undo the Whole Exercise