Documentation & scoring

Your SSP, POA&M, and SPRS score — built to hold up.

These three artifacts are how a defense contractor demonstrates NIST SP 800-171 compliance on paper, and they are the first things an assessor reads. Most of the ones we see describe an environment nobody is actually running. Cyberneza builds documentation that matches reality, tracks what is genuinely open, and produces a score you can defend line by line.

Score your SPRS self-assessment →

Personal reply within one business day.

What each one is

Three artifacts, three different jobs

System Security Plan (SSP)

Describes your system boundary and how each of the 110 NIST SP 800-171 requirements is met within it. It is a description of the environment as it runs — not a policy statement and not an aspiration. An SSP that does not match what an assessor observes is worse than a thin one.

Plan of Action & Milestones (POA&M)

Tracks requirements not yet met: what is open, who owns it, and by when. A credible POA&M with real dates reads better than an SSP claiming full implementation that evidence does not support.

SPRS score

A numeric summary of your 800-171 implementation submitted to the Supplier Performance Risk System. Scoring starts at 110 and deducts weighted points for each unmet requirement, so the score is only as good as the assessment behind it.

Why the number has to be honest

An SPRS score is a representation made to the government in connection with contract eligibility. Submitting a score the underlying environment does not support is not a documentation problem — it is a representation problem, and it is the kind of thing that gets revisited long after award.

A lower score that is accurate, paired with a POA&M showing real movement, is a defensible position. An inflated score is not. We will not help you produce the second one.

What we do and do not do

  • We do: assess implementation against the 110 requirements and document what we find.
  • We do: build the SSP and POA&M, and help you compute a supportable score.
  • You do: perform and submit the self-assessment. It is your representation, not ours.
  • We do not: assess for certification. That is a C3PAO's role. C3PAO preparation →
What we do

Documentation support

SSP development or rebuild

Write a System Security Plan from the environment as it stands, or rebuild an inherited one that no longer describes anything real.

POA&M construction

Turn open findings into tracked items with owners, dates, and enough detail that progress is verifiable rather than asserted.

Scoring walkthrough

Work through the scoring methodology requirement by requirement so you understand every deduction and can defend the total.

Evidence mapping

Connect each claim in the SSP to the operating record that demonstrates it — the step that separates a document from a defensible one.

Pre-assessment review

Read your existing SSP and POA&M the way an assessor will, and tell you where they will not survive contact.

Ongoing maintenance

These are living documents. Environments drift, and a stale SSP is a finding in itself.

Get the documentation right

Send us what you have — an inherited SSP, a spreadsheet, or nothing at all. We will tell you where it stands and what it takes to make it defensible.