Why Your System Security Plan Will Reveal CMMC Scope You Didn’t Know You Had

Most DIB contractors view the System Security Plan (SSP) as a documentation hurdle, write down your security controls, describe your environment, check the box. But here’s what they discover too late: developing your SSP is actually when you find out your real CMMC scope is bigger than you thought. The SSP isn’t just paperwork. It’s […]

CMMC Level 1 Requires 17 Safeguards 15 Controls

The official FAR clause lists 15 safeguards, but CMMC documentation often references 17 practices. Here is why: 

CMMC inherited the DoD’s earlier mapping from the DFARS 252.204-21 “Basic Safeguarding” table, where two of the FAR requirements were split into multiple CMMC practice IDs during modeling. They are not additional requirements—just a structural carryover from the original DoD-to-NIST mapping exercise.