← Custodia
Definition

System Security Plan

Also known as: SSP

A System Security Plan (SSP) is the written document that describes the boundary of a contractor's information system, the security controls implemented to protect it, and how each applicable requirement is satisfied. NIST SP 800-171 control 3.12.4 requires an SSP at Level 2; at Level 1 an SSP is not regulation-required but is considered a best-practice evidence artifact.

Primary source
NIST CSRC — SP 800-171

Related terms

Read more in the Library

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)