FutureFeed · CMMC Thursday Education Series
Security Assessment (CA): 3.12.1 to 3.12.4
The short version
If you’re responsible for CMMC compliance, here’s what these four requirements come down to. You need to:
- Check whether your security controls actually work, on a regular schedule
- Write and follow a Plan of Action & Milestones (POA&M) to fix any gaps you find
- Keep watching your controls over time, not just once a year
- Keep your System Security Plan (SSP) written down and up to date
If you already have those things and can prove them, you’re well on your way. Now let’s talk about what each one actually looks like.
In plain English
This family is the engine that keeps you compliant after the setup work is done.
It’s a loop you run again and again, and it has four moving parts.
- Assess: check whether your controls are really working, not just whether they exist on paper.
- Plan the fixes: when you find a gap, write it into a Plan of Action & Milestones (POA&M) with an owner and a due date, and work it.
- Monitor: keep an eye on your controls all year, so you catch drift before your next assessment does.
- Document: keep your System Security Plan (SSP) current. It’s the master document describing how you meet each requirement.
Run that loop and your program stays honest. Skip it and everything you built quietly falls out of date.
Once a year you run a self-assessment against the requirements and find three controls that aren’t fully in place. For each one you add a line to your POA&M: what’s wrong, who owns it, and the date it will be fixed. Through the year you check in on those controls and the rest to make sure they’re still working, and when something changes you update your SSP so it always matches reality. That’s the loop these requirements are asking you to run.
What you need to have in place
To be compliant, each of those boxes needs to be real and repeatable:
- A repeatable self-assessment against the requirements, done on a schedule (at least yearly).
- A working POA&M that lists gaps, owners, and target dates, with evidence you’re actually closing them.
- Ongoing monitoring of your controls, not a single once-a-year snapshot.
- A living SSP that describes your system boundaries, environment, and how each requirement is met, kept current.
- Dated records of assessments, POA&M updates, and SSP revisions.
The SSP and the POA&M are the two documents an assessor asks for first. If those are current and honest, the rest of the conversation gets easier.
A new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
What you need to prove it
Think in three buckets. An assessor will want all three, so it helps to build them at the same time.
People
- Someone who owns the assessment and the SSP (your security or compliance lead)
- Control owners responsible for their piece of the program
- Whoever reviews POA&M progress and monitoring results
Tools
- Your assessment method and scoring approach
- Somewhere to track the POA&M through to closure
- Monitoring tools or a GRC platform to keep it all in one place
Documents
- The completed self-assessment, dated, with a score
- The POA&M with owners and target dates
- Monitoring records and control-review logs
- The current SSP with a revision history
- These live at the center of your program, not in a drawer
You don’t need heavy tooling to start. You need to show the loop is running: you assess, you plan fixes, you watch, and you keep the paperwork true.
When should I work on this
I’d build this right after Risk Assessment. The two are a pair: risk tells you what matters, and this family is the machinery that keeps every other control honest over time. Stand it up early, because from here on every control you implement gets described in your SSP and every gap gets tracked in your POA&M. Having that engine running before you start the technical families gives you somewhere to record the results as you go, instead of scrambling to reconstruct them later.
Common challenges
The SSP is out of date the day after it’s written.
Why it happens: It gets created for an assessment and then never touched as systems and controls change.
Recommendation: Treat it as a living document. Update it whenever a control or system changes, and keep a revision history.
The POA&M is a list nobody works.
Why it happens: Gaps get written down, but no one owns the fix or the date, so items just sit there.
Recommendation: Give every item an owner and a target date, and review progress on a set schedule until it closes.
Assessment happens once a year, then nothing.
Why it happens: Monitoring is treated as a yearly event instead of an ongoing habit, so drift goes unnoticed.
Recommendation: Check your controls throughout the year, not just at assessment time. That is what “on an ongoing basis” means.
What good looks like
A compliant contractor can usually answer yes to all of these:
- Do you assess your controls on a regular schedule, not just once?
- Do you track gaps in a POA&M with owners and target dates?
- Do you monitor your controls throughout the year?
- Is your SSP current, and does it match how things actually work?
If any answer is no, that’s your next place to start.
A POA&M is not a permanent parking lot for requirements you’d rather not do. It’s for closing gaps on a timeline. Under the CMMC program, some requirements cannot go on a POA&M at all, and those that can must be closed within a limited window. Treat it as a short-term fix-it list, not long-term storage.
How this connects to other controls
This family doesn’t stand alone. A few close relationships:
- Risk Assessment: the risk decisions from that family feed what you prioritize here. Together they are your compliance engine.
- Every technical family: each control you implement gets described in your SSP, and any gap gets tracked in your POA&M, so this family touches all the others.
- Configuration Management: as your systems change, your SSP has to keep up, which ties change management directly to this family.
The requirements, word for word
For your reference, here’s the exact language so you’re working from the source and not a paraphrase:
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
Every organization implements these controls a little differently. If you’re not sure whether your approach would satisfy an assessor, join one of our upcoming webinars or schedule a 15 Minutes with FutureFeed session. We’d rather answer your questions now than have you discover them during an assessment.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Sources
- NIST SP 800-171 Rev 2, Security Assessment (3.12): the source for 3.12.1, 3.12.2, 3.12.3, and 3.12.4
- Related standards: NIST SP 800-53 Rev 5 (CA-2, CA-5, CA-7, PL-2)
- DFARS 252.204-7012