In September, DoD finalized the CMMC Program, along with the accompanying contract clauses, with an effective date of Nov. 10, 2025. As we discussed in previous GT Alerts, defense contractors will be expected to conduct self-assessments or third party assessments in accordance with requirements in NIST SP 800-171 and NIST SP 800-172. A key element of those assessments will be the SSP, which is a required document under NIST SP 800-171 rev. 2, control 3.12.4, and is one of the first review items in a Level 2 pre-assessment. Critically, recent reports from third-party assessors estimate that 25% of the companies seeking certification have experienced false starts due to a failed pre-assessment, meaning they were unable to validate the contractors’ readiness to advance to the actual assessment.
Preparing for a CMMC Audit: The System Security Plan