Yes. A System Security Plan is the foundational document of a NIST SP 800-171 self-assessment — without one you have no defined system boundary to score, and the DoD Assessment Methodology treats the assessment as unable to be completed. No SSP, no legitimate SPRS submission.
What the SSP must cover
- System boundary: where CUI lives, flows and is processed
- How each of the 110 requirements is implemented (or POA&M-ed)
- Network diagrams, asset inventories, responsibility assignments
The SSP is also the first artifact a C3PAO reads — a weak one stalls the whole assessment. Our readiness team writes assessment-grade SSPs, and the SPRS calculator flags the SSP requirement explicitly before letting you score.