System Security Plan · The Living Record
An SSP is a description of a system. Every tool sells a faster way to write the description; Alvor keeps the system of record it should be written from. Boundary, assets, controls, evidence, sign-offs: maintained as live records, and produced as whichever document your assessor asks for.
The documents are generated from the record
SSP Drift
An SSP is authored once, as a file. The environment it describes changes weekly. An identity provider migration, a new tenant, a replaced agent, a reorganised team: each invalidates a handful of narratives, and nothing in a static document signals which ones.
Assessors notice first. The fastest way to lose an assessor's confidence is a plan that describes a system they are not looking at; that mismatch between the document and the real environment is the most common assessment failure, and overstating what is implemented is a legal exposure, not a shortcut.
The fix is not writing the document faster. It is keeping the record the document comes from.
Since signing
The document was true in March. The assessment is in October.
The Record
NIST's own direction of travel, in SP 800-18 Rev 2, is system plans built on structured, machine-readable data collected automatically. That is not a document practice. It is a system of record, and it is what Alvor is.
The authorization boundary is a diagram before it is a paragraph. In Secure by Design it is a named, versioned artefact: components, data flows, and trust boundaries an assessor can walk, with every change after baseline recorded with its reason.
Secure by DesignThe system description rests on an inventory that is actually maintained: assets with owners, criticality, and location, adapters pulling cloud accounts, instances, databases, and repositories in, and a dependency view of what relies on what.
Asset ManagementAlvor's public NIST 800-53 alignment map rates the Planning family plainly, PL-2 System Security and Privacy Plans among them: maintain the control set, applicability, and implementation status that make up the system security plan. That wording comes straight from our published map, and you can check it.
NIST 800-53 alignmentEvidence is uploaded once, linked to every control it satisfies, and carries a freshness state with notice before it goes stale. The screenshot folder assembled the week before assessment stops being a ritual.
ComplianceAssessors reject boilerplate on sight, and AI-generated filler most of all. What they expect is narrative grounded in your own system, and that is the only kind Alvor's assistant can produce: it drafts from what the record already knows, the control's status, its evidence, the components it touches, and a person edits, approves, and signs. Nothing publishes itself.
Alongside the drafts: a Statement of Applicability on screen and as CSV, and project records exported as branded PDFs carrying diagrams, threat tables, and the sign-off matrix. Bring your own model, including one you host: for classified and air-gapped work, the AI never leaves your boundary either.
Implementation narrative
Drafted from record3.1.1 · Limit system access
Nothing publishes itself
One Record, Both Hemispheres
The document structures differ; the substance does not. A boundary, a control set, implementation status, evidence. Keep that once, as a record, and each regime's document becomes a formatting exercise instead of a rewrite.
110 requirements assessed against 320 objectives, and the DoD methodology is explicit: without an SSP, a Level 2 assessment cannot be completed.
CMMC explainedThe narrative centrepiece of the legacy path, moving to machine-readable packages from September 2026. The 20x path replaces it with Key Security Indicators; the record behind it stays the same.
FedRAMP explainedISM-0041 gives every system an SSP with a control annex the authorising officer approves, and IRAP assessments are anchored on it. Same artefact name, other hemisphere.
SSP as a ServiceNot an SSP by name, but the Statement of Applicability does the same job: which controls apply, how, and why not where they don't. Alvor renders it on screen and as CSV.
ISO 27001Where It Runs
An SSP names your boundary, your components, and your gaps. Teams doing CUI, sovereign, or classified-adjacent work should not have to park that in someone else's multi-tenant SaaS, and with Alvor they don't: dedicated cloud in your region, on-premise, or fully air-gapped.
A CUI enclave's security record belongs inside the enclave. Alvor deploys on-premise and fully air-gapped, with the AI pointed at models you host.
Sovereignty obligations follow the data, and the SSP describes everything. Run the record in your region, on your infrastructure, or disconnected entirely.
The team preparing the package needs its own system of record with an audit trail, not another spreadsheet. Single-tenant in every deployment model, because it was built that way.
Questions
A System Security Plan (SSP) is the formal document that describes a system: its purpose, its authorization boundary, its operating environment and data flows, the people responsible for it, and how each required security control is implemented or planned. The concept comes from NIST SP 800-18, revised in June 2026, and versions of the artefact are required by NIST 800-171 and CMMC, FedRAMP's Rev 5 path, FISMA, and Australia's Information Security Manual.
The essentials are stable across regimes: a system description and purpose; the authorization boundary, usually with boundary and data-flow diagrams; the operating environment and connections to other systems; roles and responsibilities; and an implementation statement for every applicable control. In practice the package also carries attachments: the asset inventory, policies, an incident response plan, and a POA&M for what is not yet done. The free official templates give you the headings; the months of work are the accurate content.
A living SSP is one produced from a maintained system of record rather than authored as a static file. The boundary is a versioned diagram, controls carry real implementation status, evidence has freshness dates, and the document is generated from that record when someone needs it, so it reflects the system as it is, not as it was when last rewritten. NIST SP 800-18 Rev 2 points the same direction: system plans built on structured, machine-readable data collected automatically.
Alvor maintains the record an SSP describes: boundary diagrams, the asset inventory, control applicability and implementation status, evidence, and sign-offs. From that record the AI assistant drafts implementation narrative for a person to edit and approve, the Statement of Applicability renders on screen and as CSV, and project records export as PDFs with diagrams and sign-off matrices. What Alvor deliberately does not do is publish an unreviewed document: assessors reject boilerplate, so every draft is grounded in your record and signed by a person. If you want the document written for you, Alvor Advisory does exactly that, from the same record.
SSP drift is the gap that opens between a signed SSP and the system it describes. The document is authored once; the environment changes weekly, and nothing in a static file signals which narratives an identity migration or a new tenant just invalidated. Drift is the classic assessment failure: the fastest way to lose an assessor's confidence is a plan describing a system they are not looking at, and overstating implemented controls carries legal exposure. The remedy is keeping the record current and treating the document as a view of it.
CMMC Level 2 and NIST SP 800-171 require one explicitly (requirement 3.12.4): without an SSP the assessment cannot be completed. FedRAMP's legacy Rev 5 path is built around the SSP, moving to machine-readable packages from late 2026, while the new 20x path replaces it with Key Security Indicators and a Security Decision Record. FISMA and the RMF require system plans for federal systems. In Australia, ISM control ISM-0041 requires an SSP with a control annex for every system, and IRAP assessments are anchored on it. ISO 27001's Statement of Applicability plays the equivalent role.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.