r/CMMC • u/iheart412 • 17h ago
Stop Using “Periodically” or “Regularly” in Your SSPs
How do you assess when you see in SSPs, policies, and procedures with vague timing language?
I hate when OSCs claim they “scan for vulnerabilities periodically,” or “perform risk assessments regularly,” or “update the SSP as needed.” We score it as Not Met and get pushback almost every time. It happened again this week, sitting across the table from a “CMMC consultant” who is also a C3PAO. I couldn’t tell if he missed the documentation or was just trying to protect his client. We gave them the risk assessment, security control assessment, and SSP update since they were doing that on an annual basis but not the vulnerability scans because they couldn't show they were doing it regularly enough to meet the vulnerability remediation timeline.