SSP template for a small business

Every defense contractor that handles CUI must have a System Security Plan — it's requirement 3.12.4 of NIST SP 800-171, and the DoD scoring methodology treats it as the one document without which an assessment can't even be conducted. If you're searching for a template, here's what the document actually has to contain, where templates help, and where they quietly fail a 10-person shop.

What an SSP must contain

NIST doesn't mandate a format, but assessors and primes expect the structure of the (now-retired but still conventional) NIST SSP template:

  1. System identification — system name, owner, the CAGE code(s) it covers, and who to contact.
  2. Environment description — what the covered system is: the machines, the network, the cloud services (e.g. Microsoft 365), who uses it, and where CUI flows or is stored.
  3. Scope / boundary— what's in and out, consistent with the DoD Level 2 scoping guidance (CUI assets, security protection assets, specialized assets like CNC machines).
  4. One implementation statement per requirement, all 110 — organized by the 14 control families, each stating whether the requirement is implemented, partially implemented, or planned, and how — naming your actual tools, settings, and responsible people.

The 14 family sections, with their control counts:

  • Access Control (AC) — 22 requirements
  • Awareness and Training (AT) — 3 requirements
  • Audit and Accountability (AU) — 9 requirements
  • Configuration Management (CM) — 9 requirements
  • Identification and Authentication (IA) — 11 requirements
  • Incident Response (IR) — 3 requirements
  • Maintenance (MA) — 6 requirements
  • Media Protection (MP) — 9 requirements
  • Personnel Security (PS) — 2 requirements
  • Physical Protection (PE) — 6 requirements
  • Risk Assessment (RA) — 3 requirements
  • Security Assessment (CA) — 4 requirements
  • System and Communications Protection (SC) — 16 requirements
  • System and Information Integrity (SI) — 7 requirements

Why blank templates stall small shops

A template gives you 110 empty boxes. The work — and the reason consultants charge $1,250–$1,500 a month — is filling each box with a statement that is specific enough to survive an assessor's "show me." Three failure modes show up constantly in small-business SSPs built from templates:

  • Copied boilerplatethat describes capabilities the company doesn't have. An assessor compares the statement to reality, and the False Claims Act applies to what you attest.
  • Restating the requirement instead of answering it— "the company limits system access to authorized users" says nothing about how.
  • Enterprise language that doesn't fit— a 10-person machine shop doesn't have a "security operations center," and pretending it does undermines the whole document.

The faster path: answers first, document second

The information an SSP needs is knowable by the owner: who has admin rights, whether laptops are encrypted, what happens when someone leaves, where CUI is stored. ClearPath asks ~60 plain-English questions about exactly those things, then drafts the full SSP — front matter, environment description, and one statement per control written from your actual answers, in your company's voice, exported to Word. Anything your answers don't support is marked for you to complete rather than invented, and every page carries a draft banner because the document is yours to review and own — we're a drafting tool, not an auditor. You can see your starting point first with the free SPRS score calculator.

Frequently asked questions

Is there an official NIST SSP template?
NIST published an SSP template alongside SP 800-171 but has since withdrawn it; its structure (system identification, environment, and per-requirement implementation statements) remains the convention assessors expect. Any format is acceptable if it covers how each of the 110 requirements is met.
How long should a small business SSP be?
Typically 40–80 pages for a small company. Length is not the goal — specificity is. One concrete, truthful paragraph per requirement beats five pages of boilerplate.
Does the SSP itself affect my SPRS score?
Requirement 3.12.4 (develop and maintain an SSP) carries no point deduction in the DoD methodology — because without an SSP, the methodology says an assessment cannot be conducted at all. No SSP means no score, which means no CUI-handling awards.
Can AI just write my SSP?
AI can draft it well from accurate inputs about your environment — that's exactly what ClearPath does. What it must never do is invent capabilities you don't have. Generated documents are drafts for your review, and where your answers don't support a statement, the draft says 'to be completed' instead of guessing.

Skip the blank template.

Answer plain-English questions about your shop; get a complete draft SSP in Word — every statement written from your answers, every gap marked honestly, plus the POA&M and SPRS score that go with it.

Draft my SSP →

Informational only — not a compliance determination, an assessment, or legal advice. Requirements are defined by NIST SP 800-171 Rev 2, NIST SP 800-171A, the DoD Assessment Methodology, and 32 CFR Part 170; always verify against the official publications.