Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What is the difference between an SSP and…
Governance, Ownership & Risk

What is the difference between an SSP and a POA&M in CMMC compliance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Governance, Ownership & Risk

An SSP describes the security program as it exists today, including the boundary, assets, connections, and implemented NIST SP 800-171 controls. A POA&M records deficiencies, remediation steps, owners, and due dates. In practice, the SSP shows how the environment is protected now, while the POA&M shows how approved gaps will be closed within the required timeframe.

How the SSP and POA&M play different roles in CMMC

The split is functional, not cosmetic. An SSP is the system’s current-state security narrative: it defines scope, boundary, assets, external connections, and how required controls are implemented today. A POA&M is the gap register: it captures deficiencies, assigns remediation ownership, and tracks target dates so the organisation can close approved shortcomings in a controlled way.

For CMMC work, that distinction matters because assessors are not looking for a single blended document. They want to see that the organisation can explain its present control environment clearly and, separately, can manage unresolved items without pretending they are already fixed. That separation is what makes the evidence review and remediation planning auditable.

  • The SSP answers, “What is protected, where is it protected, and how are the required controls operating now?”
  • The POA&M answers, “What is not yet fully in place, who owns the fix, and by when will it be closed?”
  • An SSP can be complete even when some controls are not yet perfect, but it must be accurate about the current state.
  • A POA&M should never be a vague wish list; it needs specific corrective actions and accountable dates.

That difference is why the two documents are usually reviewed together. The SSP establishes the baseline, while the POA&M shows whether the organisation can manage exceptions without losing control of the compliance programme. In a mature programme, the two documents should align cleanly, with every open gap traceable back to a documented deficiency and every remediation item tied to the relevant scope and control.

What to look for in each document

The SSP should be rich in architecture and control detail, but still readable. Practitioners should expect an accurate boundary statement, a clear inventory of in-scope systems and connections, and enough control narrative to demonstrate how the implementation works in practice. If the SSP is too generic, it becomes hard to judge whether the environment really satisfies the required CMMC evidence.

The POA&M should be more operational. A useful POA&M usually identifies the specific gap, the remediation task, the responsible owner, milestones or due dates, and any dependencies that could delay closure. That makes it a management tool, not just an audit artefact.

One practical way to differentiate them is to ask what would break if the document were removed. If the SSP disappeared, the assessor would lose the map of the environment and the logic of how controls are implemented. If the POA&M disappeared, the organisation would lose visibility into unresolved deficiencies and the ability to prove that remediation is being actively governed.

  • SSP quality signal: the document should let a reviewer trace controls from scope to implementation without guesswork.
  • POA&M quality signal: each entry should be actionable, owned, and time-bound.
  • Cross-check: every open item in the POA&M should correspond to a real deficiency, not a duplicated or outdated finding.
  • Cross-check: the SSP should not quietly claim a control is effective if the POA&M still shows it as open without an approved exception.

In practice, teams often use the SSP as the authoritative source for current-state evidence and the POA&M as the operational follow-up record. That helps avoid a common failure mode where remediation activity exists, but no one can show how it is tied back to the control environment being assessed.

Why the distinction matters for audit readiness and remediation discipline

The real value of keeping SSP and POA&M separate is control integrity. If the SSP is allowed to absorb unresolved gaps, the current-state picture becomes misleading. If the POA&M is treated as a dumping ground for everything, it stops being useful as a governed remediation tracker. CMMC compliance depends on both accuracy and accountability, so the separation itself is part of the evidence story.

For practitioners, the key judgement is not just whether a gap exists, but whether it is documented in the right place and handled with the right level of formality. Strong programmes keep the SSP stable enough to describe the environment, while allowing the POA&M to change as remediation progresses. That makes it much easier to explain status, risk acceptance, and closure progress during an assessment.

Documentation discipline also helps during change management. When systems, connections, or control implementations change, the SSP should be updated to reflect the new state. When a gap is found, the POA&M should capture the corrective path. Treating those as separate records reduces confusion, avoids stale evidence, and improves the credibility of both documents.

Practitioner Guidance: Keep the SSP anchored to evidence of how the environment works now, and keep the POA&M anchored to how each approved deficiency will be closed. If a control is still open, do not blur the boundary between “implemented” and “planned” just because remediation is underway.

Practitioner takeaway: The SSP proves current-state control design and implementation, while the POA&M proves disciplined gap management, and CMMC reviewers expect both to be internally consistent.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategySSP and POA&M together show current-state controls and managed remediation.
ID.IM-01 — Improvements Are IdentifiedPOA&M entries are the formal record of identified improvement actions.
Recommendation — Define how gaps are recorded, prioritized, and tracked to closure. Track identified deficiencies as owned improvements with due dates.
CIS Controls v85.1 — Establish and Maintain an Inventory of Enterprise AssetsSSP scope and boundary depend on accurate in-scope asset inventory.
8.1 — Audit Log ManagementAssessment evidence and remediation status depend on traceable records.
Recommendation — Maintain a current asset inventory that supports the system boundary in the SSP. Retain evidence and logging that supports control implementation and POA&M closure.
NIST SP 800-63IAL1 — Identity Proofing RequirementsIdentity evidence often underpins control implementation narratives in system documentation.
Recommendation — Document identity assurance assumptions where access controls depend on them.
NIST Zero Trust (SP 800-207)PR.AC-4 — Access Permissions ManagementSSP narratives commonly describe how access is limited and governed today.
Recommendation — Describe how access decisions are enforced within the assessed boundary.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org