Guide

CMMC Program Cadence: Keep SSP, POA&M, and SPRS Defensible

Last verified: First published:

Quick answer: After remediation, defensibility dies from drift—not from one bad week. Run a standing cadence: change-triggered reviews, quarterly high-weight sampling, living SSP/POA&M updates, training refresh, and a deliberate gate before any SPRS re-affirmation. Annual Maintenance retainers help if you want time-boxed outside help.

Key takeaways

  • Cadence beats heroics; schedule reviews before primes ask.
  • Change control must re-open affected register rows.
  • Quarterly sample high-weight Satisfied marks—do not trust last year.
  • SPRS is a gate, not a calendar pop-up without evidence.
  • Maintenance SKU is for documentation currency—not a managed SOC.

From project to program

The remediation roadmap gets you out of crisis. Cadence keeps you out of the next one.

Ops should treat CMMC / 800-171 readiness like any other controlled process: triggers, owners, calendars, and gates.

Standing calendar

Cadence Activity
Weekly (light) POA&M slip review; open critical incidents affecting controls
Monthly Register health: % Satisfied / Partial / Not; owner backlog
Quarterly Sample high-weight Satisfied controls for evidence still true
On change Any enclave, identity, MSP, or major app change → reopen rows
Before SPRS / prime attestation Full sign-off checklist + independent challenge sample
Annually Broader re-assessment posture; policy set review; training cycle

Change control → register

Minimum rule:

If production changes could affect a control, the related register rows return to Partial or Not until re-evidenced.

Examples: new remote access path, MSP swap, cloud tenant change, plant network merge, backup vendor change.

SSP and POA&M as living objects

Object Cadence rule
SSP Update when boundary, data flows, or major implementations change—not only before audits (SSP guidance)
POA&M Every open Partial/Not that is formally tracked; milestones not “someday”
Evidence index Paths still valid after file-share migrations
Training Role-based refresh for CUI handlers

Quarterly sample (lightweight)

  1. Pull top 10–20 weight-5/3 Satisfied rows
  2. Re-pull evidence or re-demonstrate
  3. Downgrade anything stale
  4. Adjust residual risk for leadership

This is cheaper than discovering fiction when a prime or assessor asks.

SPRS re-entry gate

Before anyone updates or re-affirms a score (still need SPRS?):

  1. Register current
  2. High-weight sample done this quarter
  3. Sign-off checklist complete
  4. Residual risk briefed to sponsor
  5. Explicit decision recorded

No gate → no submission.

Metrics ops can report

Metric Why
Open weighted points Progress without vanity score chasing
% rows with owner + evidence location Hygiene
Overdue POA&M milestones Execution
Days since last high-weight sample Drift risk
Signature go/no-go Executive clarity

When to buy help

Need Option
DIY templates for SSP/POA&M/scoring Pro Pack
Annual documentation pass Annual Maintenance ($2,995/yr, up to 14 hours)
Environment changed hard New Gap or Review
Still can’t sign Stop—fix, don’t certify

Anti-patterns

  • Annual panic before a solicitation
  • “Green dashboard” from tools nobody samples
  • SSP updated only by find-and-replace of the year
  • Maintenance that never re-opens register rows

Next

  1. Put quarterly sampling on the real calendar
  2. Wire change tickets to register re-open rules
  3. Keep status mapping as the system of record
  4. Use sources when policy shifts—verify before you rewrite the program

Frequently asked questions

How often should we re-score SPRS?

When the environment or control status materially changes, or when contracts/primes require an update—not on a vanity monthly cycle. Always re-validate evidence before re-affirming.

What is Annual Maintenance for?

A time-boxed yearly engagement (our SKU: up to 14 hours) to keep SSP/POA&M current as systems change. It is not unlimited consulting or 24/7 monitoring.

Who owns cadence if we have an MSP?

You do. MSPs execute agreed controls; the contractor owns the register, signature risk, and prime representations.

What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).