
CMMC Level 1
Do You Need an SSP for CMMC Level 1?
Whether a System Security Plan is required for CMMC Level 1, what documentation Level 1 actually calls for, and why a central record still helps.
You started your Level 1 self-assessment and hit a documentation question that the guides answer three different ways. Do you need a System Security Plan? Some people say yes, some say no, and a few built a spreadsheet placemat instead. Here is the straight answer and what Level 1 actually calls for.
The short version. A System Security Plan is not required at CMMC Level 1. It is a Level 2 requirement. That said, keeping one organized record of how you meet each requirement, with the evidence attached, makes your assessment defensible and your annual affirmation far easier. Recommended, not required.
The Direct Answer
Level 1 does not require an SSP. The formal System Security Plan requirement lives at Level 2, under NIST SP 800-171. Level 1 asks you to meet 15 requirements and assess against 59 objectives, and to be able to show the result. It does not mandate a specific document called an SSP.
So if someone told you that you must produce an SSP to complete Level 1, that is not accurate. You will not fail Level 1 for lacking one.
Why People Keep One Anyway
Not required is not the same as not useful. Almost every experienced practitioner recommends keeping a central record for Level 1, for three practical reasons.
- The affirmation is annual. You reassess and re-affirm every year. A single organized record means you are updating last year's work, not rebuilding it from memory.
- It makes the result defensible. If anyone ever asks how you met a requirement, a central record with the evidence attached is your answer.
- It helps if you ever move to Level 2. If CUI enters your world later, the requirement becomes mandatory, and having the habit already in place saves real time.
The mistake is treating the improvised version as good enough. A folder per requirement, a Teams channel, or a spreadsheet with a tab per requirement all work until someone leaves or a laptop is replaced and the reasoning behind a determination is gone.
What Documentation Level 1 Actually Calls For
Keep it proportional. Level 1 is basic safeguarding, not a Level 2 documentation program. In practice a defensible Level 1 record holds:
- Your determination for each of the 59 objectives, MET, NOT MET, or N/A.
- The evidence behind each one, a screenshot, a configuration export, a short procedure, or a photo.
- A short note for anything marked N/A explaining why it does not apply.
- A retention plan, because you keep the assessment and its evidence for six years under 32 CFR 170.15.
That is the record. Whether you call it an SSP or not matters less than whether it is organized, complete, and findable next year.
The Central Record, Without the Level 2 Overhead
AssessrLog is that central record, built for Level 1. Each determination sits beside its evidence, the history is preserved, and next year the record is already there to update rather than rebuild. You get the benefit an SSP-style document provides without a heavy Level 2 documentation program you do not need. The product overview shows how that record is laid out.
Frequently Asked Questions
Is a System Security Plan required for CMMC Level 1? No. The SSP requirement is at Level 2. Level 1 does not mandate one.
Should I create an SSP for Level 1 anyway? A central record is strongly recommended, whether or not you call it an SSP. It makes the assessment defensible and the annual affirmation easier.
What documentation does Level 1 actually require? A determination for each objective, the evidence behind it, a note for anything marked N/A, and a plan to retain it all for six years.
Will I fail Level 1 without an SSP? No. Level 1 does not require an SSP, so lacking one is not a failure. Lacking any organized record is what causes problems later.
How long do I keep the record? Six years, under 32 CFR 170.15, including the assessment and its evidence.
