Services / Module B: SSP Build/Rebuild
Documentation · Module B

An SSP that describes your environment as it actually is

For contractors whose SSP is missing, template-built, or describing an environment that doesn’t exist.
Build My SSP 1 concurrent build
Lumos runs one SSP Build at a time — your engagement gets the practitioner’s full attention, and the queue is stated plainly before you commit.
$14,500
Fixed fee — no hourly meter
3 weeks
One concurrent engagement at a time
110 practices
Every practice addressed, honestly

The most dangerous SSP is the optimistic one

An SSP that describes controls you intend to have is not a plan — it’s a liability. Your SPRS affirmation rests on that document, and under the False Claims Act, "we meant to implement it" is not a defense.
Module B builds an SSP with one discipline at its core: the document describes the environment as it IS. Aspirations go in the POA&M, where they legally belong. That distinction is what keeps your affirmation defensible.

What you get in 3 weeks

Complete System Security Plan

All 110 practices addressed against your real environment — the central artifact of every Level 2 path, self-assessed or C3PAO.

Honest implementation statements

Each practice describes what exists today, in language assessors recognize — no template boilerplate, no aspirational tense.

Aligned POA&M

Everything not yet implemented goes here, with milestones — keeping your SSP truthful and your gap-closure plan official.

Updated SPRS worksheet

Your score recalculated from the finished SSP, so the number you affirm matches the document behind it.

Three weeks, week by week

1
Gate

Your clock starts here

SOW signed + payment + document checklist complete = your clock starts. Until then, nothing is counting against you.
2
Week 1

Environment deep-dive

Your scope artifacts, gap findings, and system documentation become the SSP foundation; plain-language worksheets for every practice still needing facts go out in batches — all issued during Week 1, each on a short turnaround.
3
Week 2

Drafting, practice by practice

Implementation statements written against evidence. Where reality falls short, the gap moves to the POA&M — never into wishful SSP language.
4
Week 3

Review, revision, finalization

Your one consolidated revision round, then final SSP, POA&M, and SPRS worksheet delivered together — reconciled so all three tell one story per practice.
5
Week 3 · close

90-minute review call

A 90-minute walkthrough of every practice status and deliverable with your named reviewer — the working session behind your consolidated revision round.

What we need from you

This checklist is how your timeline stays protected — the clock starts when it's complete, so nothing stalls mid-engagement.
Completed scope documentation, asset inventory, and MSP responsibility matrix (Module A, or equivalent from your Sprint)
Completed diagnostic findings — your Sprint report or Gap Analysis (a gating input: the clock doesn't start without it)
A named IT or MSP contact for technical questions, and timely worksheet returns — each batch carries a 5-business-day turnaround
A single owner on your side for the consolidated revision round, confirmed available during the Week-3 review window

Is Module B what you need?

Module B works well for:

  • Contractors with no SSP and a Level 2 path ahead
  • Teams with a template SSP full of blanks and borrowed language
  • Organizations whose environment changed and whose SSP didn’t
  • Anyone affirming an SPRS score they couldn’t defend in an audit

Not the right fit:

  • Scope undocumented — Module A (or the Sprint) comes first; an SSP without a boundary is fiction
  • You want the SSP to describe planned controls as current — that's exactly the liability this engagement removes
  • Organizations wanting Lumos to perform the formal assessment — a C3PAO must do that
  • Looking for hands-on technical implementation — your IT staff or MSP performs that work
Lumos is a solo practice led by a Cyber AB Registered Practitioner providing readiness advisory and documentation only — formal CMMC assessments are conducted by certified C3PAOs, and technical implementation is performed by your IT staff or MSP. CMMC readiness consulting is generally an allowable cost under FAR 31.205-33; confirm with your contracts team.
CISSP · ISSEP · CCSP · CSSLP · CISA · CISM · PMP Cyber AB Registered Practitioner 28 NIST engagements since 2017 Veteran & Native Hawaiian-Owned

Where this leads

With the SSP built, Module C gives every practice its policy backing and evidence trail. Snapshot clients: $1,000 credits here. Sprint clients: $2,000 credits here.

Questions about this engagement

Why only one SSP Build at a time? +
A 110-practice SSP written honestly requires sustained attention to one environment. Running builds in parallel is how template language creeps in. One at a time is the quality control — ask about the queue on the free call.
What does "describes the environment as it IS" mean in practice? +
If multifactor authentication is deployed on 9 of 11 systems, the SSP says 9 of 11 — and the other two go on the POA&M with dates. The alternative, writing "MFA is implemented," is the kind of statement that becomes False Claims Act exposure the moment you affirm your score.
We already have an SSP. Rebuild or repair? +
The 48-Hour Snapshot answers exactly that for $4,950, and credits $1,000 toward the rebuild if that’s the verdict. Most template SSPs are rebuilds — repair costs more than starting honest.
Who maintains the SSP afterward? +
You do — it's your document and your affirmation. The Readiness Retainer exists for clients who want quarterly upkeep, but the SSP is delivered fully yours: editable, documented, explained on the 90-minute review call.

Affirm a number your documents can defend

Free 30-minute readiness call first — I'll tell you if this is the wrong starting point.