Alvor Advisory · SSP as a Service
We scope your boundary, build the system of record behind it, and write the SSP and POA&M from that record: for NIST 800-171 and CMMC, FedRAMP's document path, or the ISM and IRAP. The document takes days once the record exists. The record takes the real work, and you keep it.
Document-first
Record-first
Two ways to produce the same document
When teams bring us in
“There is a DFARS clause in the contract we just signed, and it asks for a score we do not have.”
A defence prime's paperwork arrives with DFARS 252.204-7012 and a CMMC level in it, and the SPRS score it presumes rests on an SSP nobody has written.
Our response · We scope the CUI boundary, run the gap against the 110 requirements, and deliver the SSP, POA&M, and a defensible score, in that order, because the score is meaningless without the plan.
“The IRAP assessor asked for our SSP and annex before the first workshop.”
An Australian government deal reaches the security stage, and the ISM's system security plan with its control annex is the entry ticket, not a formality at the end.
Our response · We build the SSP and annex the way ISM-0041 describes them: a system overview an authorising officer can approve, and a control annex that reflects what is actually implemented.
“Our prime wants our SPRS score by the end of the quarter.”
Flow-down lands on the subcontractor with the smallest security team, and the affirmation a named official must sign carries more legal weight than most small teams expect.
Our response · We do the assessment work that makes the affirmation honest: implementation status verified per requirement, the POA&M kept inside the rules, and the working papers retained.
“The template has two hundred headings and the assessment is booked.”
The free official template turned out to be the easy part. Every heading needs content that is true, specific, and consistent with what an assessor will actually find.
Our response · We fill nothing in from a library of stock sentences. The system is documented as a record first; the template is populated from it, so the document matches what an assessor will actually find.
The method
Where the sensitive data actually lives, what can be kept out, and whether an enclave changes the economics. The boundary decision sets the cost of everything after it, which is why it comes first and is drawn as a diagram, not described in a paragraph.
The asset inventory, the architecture and data-flow diagrams, control applicability, and verified implementation status, in Alvor, against your framework: the 110 requirements and 320 objectives for 800-171, or the ISM controls for an annex. This is where the weeks go, and it is the part you keep.
The SSP and POA&M, or the SSP and annex, drafted from the record rather than invented at the keyboard. This is why the document takes days: by the time writing starts, every fact in it already exists, verified, in one place.
Change-triggered updates instead of an annual rewrite: the record moves when the environment does, evidence carries freshness dates, and the annual affirmation or reassessment starts from a current plan instead of an archaeology project.
Days, not months
SSP writing is slow when every sentence has to be discovered at the keyboard: what the boundary contains, which controls apply, what is actually implemented, where the evidence is. Months disappear into that discovery, and the answers go stale as fast as they are typed.
We do the discovery as structured work in Alvor instead: boundary drawn, assets inventoried, every requirement given a verified status. Then the document is produced from the record. The first assessor-ready draft lands in days once the record exists, because by then nothing in it is being invented.
The record is where the weeks go, and unlike a document, it compounds: the next framework, the next affirmation, and the next assessment start from a maintained record instead of a stale file.
What we will not do
Assessors flag templated and machine-padded SSPs on sight, and they are right to. Every implementation statement we write traces to a verified record of your system.
The affirmation a named official signs carries legal exposure. If a requirement is not met, it goes on the POA&M or into the plan of work, never into fiction.
We build the posture and the plan; the assessment belongs to a C3PAO, DIBCAC, an IRAP assessor, or an independent assessor, by design. The same separation we keep everywhere.
Both hemispheres
The official templates are free, and we use them where they fit. What you are paying for is the accurate content, and the record it is written from.
United States
The SSP and POA&M for the self-assessment era: 110 requirements, 320 assessment objectives, SPRS scoring, and POA&M rules honoured as written.
CMMC explainedPackage documentation for teams on the legacy path, and record-first readiness for teams heading to 20x, where the SSP gives way to Key Security Indicators.
FedRAMP explainedAustralia
The SSP and control annex of ISM-0041, prepared for authorising officers and IRAP assessments. We take you to assessor-ready and stop: the IRAP assessment itself is conducted by an endorsed assessor.
Essential Eight & the ISMAustralian companies entering US programs under AUKUS carry both hemispheres at once. One record answers the ISM at home and 800-171 flow-down abroad.
Regulated & SovereignCommon questions
The questions a security or delivery lead brings to a first conversation about having the plan written.
Tell us which clause, assessor, or authorising officer is asking, and what the system holds. We scope the work in writing before anything starts: the boundary, the record, the plan, and, if you want it, the upkeep.