InstinctIQ
    Back to Blog
    IT & CMMC

    Your System Security Plan Is Not a Binder

    Many AEC firms pursuing federal work have a System Security Plan. It was written once, often with outside help, and saved as a long document. It describes the network, the controls, and the people responsible.

    Then the firm adds a new office, switches file storage, replaces a firewall, and hires a new office manager. The SSP still describes last year.

    For CMMC, that gap matters. An SSP that does not match reality is a liability, not an asset.

    What the SSP is supposed to be

    The SSP explains how your firm protects Controlled Unclassified Information. It covers where that information lives, who can access it, and how each required practice is met. An assessor uses it to understand your environment and then checks whether reality matches.

    The key word is reality. The SSP is a living description of your systems, not a one-time deliverable.

    Why SSPs drift

    Nobody owns it. The person who wrote it moved on, or it was a consultant. Updating it is nobody's job.

    Changes happen outside compliance. A PM requests a new cloud tool for a client. IT sets up a new site. Neither thinks "update the SSP."

    It is hard to edit. A long document with dense control language is intimidating. People avoid touching it.

    Evidence lives elsewhere. The SSP says MFA is enforced. The proof is in an admin console. Linking the two is manual.

    What drift costs

    • Assessment risk. Mismatches between the plan and the environment are exactly what assessors look for.
    • Scramble time. Firms spend weeks before an assessment rewriting the SSP from scratch.
    • Pursuit risk. Federal and defense clients increasingly ask about CMMC status during pursuits. A shaky answer costs credibility.

    A better workflow

    Tie changes to updates

    Any change to systems, locations, or responsibilities that touch CUI should trigger an SSP review. Add one question to your IT change process: "Does this affect the SSP?"

    Review on a schedule

    Quarterly is reasonable for most mid-size firms. Walk through each section and confirm it still matches.

    Keep evidence next to the claim

    For each practice, record where the proof lives and when it was last checked. When the SSP says something is true, you should be able to show it in minutes.

    Write in plain language

    The SSP should be understandable by the people who run your systems. Control language has its place, but each section should also say plainly what you actually do.

    Where AI helps, and where it does not

    It helps with:

    • Comparing the current environment against what the SSP describes and flagging differences
    • Drafting plain-language updates for a human to review
    • Reminding owners when reviews or evidence checks are due

    It does not replace:

    • Accountable people signing off on the plan
    • Decisions about how to meet a control
    • The assessment itself

    What matters: accuracy. Never let an AI-drafted SSP section stand without review. The SSP is a statement your firm stands behind.

    How we approach it

    IQ-CMMC helps PM/CM/AEC firms keep CMMC current as ongoing work rather than an annual project, including policies, training, and evidence that stay up to date.

    A useful next step

    Open your SSP and pick one section, such as where CUI is stored. Ask the person who runs that system whether it is still accurate. If the answer takes more than a minute, your SSP has drifted. Talk to us about getting it back in step.

    Ready to simplify IT and CMMC?

    Join hundreds of AEC teams already saving hours every week.