Many AEC firms pursuing federal work have a System Security Plan. It was written once, often with outside help, and saved as a long document. It describes the network, the controls, and the people responsible.
Then the firm adds a new office, switches file storage, replaces a firewall, and hires a new office manager. The SSP still describes last year.
For CMMC, that gap matters. An SSP that does not match reality is a liability, not an asset.
What the SSP is supposed to be
The SSP explains how your firm protects Controlled Unclassified Information. It covers where that information lives, who can access it, and how each required practice is met. An assessor uses it to understand your environment and then checks whether reality matches.
The key word is reality. The SSP is a living description of your systems, not a one-time deliverable.
Why SSPs drift
Nobody owns it. The person who wrote it moved on, or it was a consultant. Updating it is nobody's job.
Changes happen outside compliance. A PM requests a new cloud tool for a client. IT sets up a new site. Neither thinks "update the SSP."
It is hard to edit. A long document with dense control language is intimidating. People avoid touching it.
Evidence lives elsewhere. The SSP says MFA is enforced. The proof is in an admin console. Linking the two is manual.
What drift costs
- Assessment risk. Mismatches between the plan and the environment are exactly what assessors look for.
- Scramble time. Firms spend weeks before an assessment rewriting the SSP from scratch.
- Pursuit risk. Federal and defense clients increasingly ask about CMMC status during pursuits. A shaky answer costs credibility.
A better workflow
Tie changes to updates
Any change to systems, locations, or responsibilities that touch CUI should trigger an SSP review. Add one question to your IT change process: "Does this affect the SSP?"
Review on a schedule
Quarterly is reasonable for most mid-size firms. Walk through each section and confirm it still matches.
Keep evidence next to the claim
For each practice, record where the proof lives and when it was last checked. When the SSP says something is true, you should be able to show it in minutes.
Write in plain language
The SSP should be understandable by the people who run your systems. Control language has its place, but each section should also say plainly what you actually do.
Where AI helps, and where it does not
It helps with:
- Comparing the current environment against what the SSP describes and flagging differences
- Drafting plain-language updates for a human to review
- Reminding owners when reviews or evidence checks are due
It does not replace:
- Accountable people signing off on the plan
- Decisions about how to meet a control
- The assessment itself
What matters: accuracy. Never let an AI-drafted SSP section stand without review. The SSP is a statement your firm stands behind.
How we approach it
IQ-CMMC helps PM/CM/AEC firms keep CMMC current as ongoing work rather than an annual project, including policies, training, and evidence that stay up to date.
A useful next step
Open your SSP and pick one section, such as where CUI is stored. Ask the person who runs that system whether it is still accurate. If the answer takes more than a minute, your SSP has drifted. Talk to us about getting it back in step.
Ready to simplify IT and CMMC?
Join hundreds of AEC teams already saving hours every week.