{"product_id":"nist-800-171-system-security-plan-ssp-template","title":"NIST 800-171 System Security Plan (SSP) Template","description":"\u003cp\u003e\u003cstrong\u003eA complete System Security Plan template for NIST SP 800-171 and CMMC Level 2, with an example statement for every requirement.\u003c\/strong\u003e An SSP is required by requirement 3.12.4; without one, your self-assessment cannot be scored.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eSystem Security Plan Template\u003c\/strong\u003e (Word, 81 pages): system identification, scope and boundary using the CMMC asset categories, environment, network and data flow diagrams, external providers and shared responsibility, roles, and all 110 requirements with verbatim NIST text, their 320 assessment objectives, status boxes and a fictional example implementation statement for each. Appendices include a change log.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSSP Implementation Tracker\u003c\/strong\u003e (Excel): a 110-row tracker for drafting, review and approval of each statement, with owners, target dates and a dashboard by family.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps, what good looks like and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eCMMC Level 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eComplete sections 1 to 3 (identification, scope and boundary, roles) and draw the diagrams (1 to 3 days).\u003c\/li\u003e\n\u003cli\u003eAssign an owner and target date to each requirement in the tracker (1 hour).\u003c\/li\u003e\n\u003cli\u003eDraft section 4 family by family, starting with Access Control, Identification and Authentication, and System and Communications Protection. Replace every blue example with your own statement (3 to 6 weeks part time).\u003c\/li\u003e\n\u003cli\u003eReview each statement against its objectives and evidence, and record gaps on your POA\u0026amp;M.\u003c\/li\u003e\n\u003cli\u003eApprove the SSP, use it for your self-assessment and SPRS entry, and review it annually.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eSmall and mid-sized defense suppliers that handle CUI (Controlled Unclassified Information) and need an SSP for a NIST SP 800-171 or CMMC Level 2 self-assessment, and the MSPs who write SSPs for them.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742654658,"sku":"ICC-CMMC-SSP","price":99.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/nist-800-171-system-security-plan-ssp-template.png?v=1790686313","url":"https:\/\/isocloudconsulting.com\/products\/nist-800-171-system-security-plan-ssp-template","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}