CMMC Program Cadence: Keep SSP, POA&M, and SPRS Defensible
Quick answer: After remediation, defensibility dies from drift—not from one bad week. Run a standing cadence: change-triggered reviews, quarterly high-weight sampling, living SSP/POA&M updates, training refresh, and a deliberate gate before any SPRS re-affirmation. Annual Maintenance retainers help if you want time-boxed outside help.
Key takeaways
- Cadence beats heroics; schedule reviews before primes ask.
- Change control must re-open affected register rows.
- Quarterly sample high-weight Satisfied marks—do not trust last year.
- SPRS is a gate, not a calendar pop-up without evidence.
- Maintenance SKU is for documentation currency—not a managed SOC.
From project to program
The remediation roadmap gets you out of crisis. Cadence keeps you out of the next one.
Ops should treat CMMC / 800-171 readiness like any other controlled process: triggers, owners, calendars, and gates.
Standing calendar
| Cadence | Activity |
|---|---|
| Weekly (light) | POA&M slip review; open critical incidents affecting controls |
| Monthly | Register health: % Satisfied / Partial / Not; owner backlog |
| Quarterly | Sample high-weight Satisfied controls for evidence still true |
| On change | Any enclave, identity, MSP, or major app change → reopen rows |
| Before SPRS / prime attestation | Full sign-off checklist + independent challenge sample |
| Annually | Broader re-assessment posture; policy set review; training cycle |
Change control → register
Minimum rule:
If production changes could affect a control, the related register rows return to Partial or Not until re-evidenced.
Examples: new remote access path, MSP swap, cloud tenant change, plant network merge, backup vendor change.
SSP and POA&M as living objects
| Object | Cadence rule |
|---|---|
| SSP | Update when boundary, data flows, or major implementations change—not only before audits (SSP guidance) |
| POA&M | Every open Partial/Not that is formally tracked; milestones not “someday” |
| Evidence index | Paths still valid after file-share migrations |
| Training | Role-based refresh for CUI handlers |
Quarterly sample (lightweight)
- Pull top 10–20 weight-5/3 Satisfied rows
- Re-pull evidence or re-demonstrate
- Downgrade anything stale
- Adjust residual risk for leadership
This is cheaper than discovering fiction when a prime or assessor asks.
SPRS re-entry gate
Before anyone updates or re-affirms a score (still need SPRS?):
- Register current
- High-weight sample done this quarter
- Sign-off checklist complete
- Residual risk briefed to sponsor
- Explicit decision recorded
No gate → no submission.
Metrics ops can report
| Metric | Why |
|---|---|
| Open weighted points | Progress without vanity score chasing |
| % rows with owner + evidence location | Hygiene |
| Overdue POA&M milestones | Execution |
| Days since last high-weight sample | Drift risk |
| Signature go/no-go | Executive clarity |
When to buy help
| Need | Option |
|---|---|
| DIY templates for SSP/POA&M/scoring | Pro Pack |
| Annual documentation pass | Annual Maintenance ($2,995/yr, up to 14 hours) |
| Environment changed hard | New Gap or Review |
| Still can’t sign | Stop—fix, don’t certify |
Anti-patterns
- Annual panic before a solicitation
- “Green dashboard” from tools nobody samples
- SSP updated only by find-and-replace of the year
- Maintenance that never re-opens register rows
Next
- Put quarterly sampling on the real calendar
- Wire change tickets to register re-open rules
- Keep status mapping as the system of record
- Use sources when policy shifts—verify before you rewrite the program
Frequently asked questions
How often should we re-score SPRS?
When the environment or control status materially changes, or when contracts/primes require an update—not on a vanity monthly cycle. Always re-validate evidence before re-affirming.
What is Annual Maintenance for?
A time-boxed yearly engagement (our SKU: up to 14 hours) to keep SSP/POA&M current as systems change. It is not unlimited consulting or 24/7 monitoring.
Who owns cadence if we have an MSP?
You do. MSPs execute agreed controls; the contractor owns the register, signature risk, and prime representations.
What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).