Audit Readiness
SSP, POAM, and audit package generation
NIST SP 800-18r2 (June 2026) supersedes NIST SP 800-18r1, published February 2006.
Audit readiness capabilities ensure organizations are prepared for assessments with complete documentation and evidence packages. Thalorin generates system security plans, manages plans of action and milestones, and assembles comprehensive audit packages aligned with assessor expectations.
The guidance that shaped almost every system security plan in federal service was published in February 2006. NIST replaced it in June 2026 with SP 800-18r2, Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems, and the replacement changes the object rather than the template. The system security plan is now one of three system plans, alongside a system privacy plan and a C-SCRM plan. The revision also deprecates general support system, major application and minor application, and renames system boundary to authorization boundary — terms still sitting in packages currently under review.
An assessor does not read a plan; an assessor reads a package, and every regime assembles a different one. Under NIST SP 800-37 Rev 2, Task R-1 submits security and privacy plans, assessment reports, the plan of action and milestones and supporting evidence to the authorizing official as a single authorization package with an executive summary. ISO/IEC 27001:2022 instead wants a Statement of Applicability under clause 6.1.3 d), reconciled against a normative Annex A. FedRAMP has gone furthest: under its Consolidated Rules for 2026 the base System Security Plan gives way to a Security Decision Record, binding on 20x certifications since 4 July 2026 and on Rev5 from 1 January 2027.
What gets underestimated is that the POA&M is a register, not a punch list. NIST SP 800-37 Rev 2 places it inside the authorization package and populates it from deficiencies found during control assessment and during continuous monitoring, so it is open by design and is never reconciled to zero for an assessor's benefit. The related error is treating documentation drift as cosmetic. FedRAMP now states the position without softening it: an out-of-date control statement in the Security Decision Record is a vulnerability, to be detected and remediated like any other.
Thalorin holds one control state and renders the package from it. A System Security Plan, a Statement of Applicability and a POA&M become three views of the same assertions, each carrying the evidence behind it and the date that evidence was produced. Because the artifact is derived rather than edited, a control that changes surfaces in every document that cited it — including packages already submitted — instead of leaving a plan that describes the system as it stood on the day someone last drafted it.
Compliance operations need modern infrastructure
A 2006 template under a 2026 standard
SP 800-18r1 dated from February 2006 and set the shape of most SSP templates still in service. Its replacement restructures the plan, splits it three ways and retires vocabulary that remains in live documents.
The POA&M does not close
It sits inside the authorization package and takes entries from both control assessment and ongoing monitoring. Treating it as a list to be emptied before an assessment misreads what an authorizing official is reading it for.
One system, three package conventions
An RMF authorization package, an ISO Statement of Applicability and a FedRAMP Security Decision Record in JSON describe the same controls in incompatible structures. Maintained separately, they reliably end up disagreeing.
Certificates that expired underneath the package
IAF MD 26:2023 set the ISO/IEC 27001:2022 transition at 36 months from publication, ending 31 October 2025, and required all 2013-based certifications to expire or be withdrawn. A package citing one now cites nothing.
How Thalorin helps
SSP generation and maintenance
Build the plan against the elements SP 800-18r2 sets out, with the authorization boundary, control implementation detail and responsible roles drawn from the same records the assessment will read.
POA&M management
Carry each item with the deficiency that created it, whether assessment or ongoing monitoring raised it, the remediation owner and the milestone dates — the form NIST SP 800-37 Rev 2 expects inside the authorization package.
Audit package assembly
Collect the Task R-1 inputs — plans, assessment reports, POA&M and supporting evidence — into one package with an executive summary, versioned so a submitted package stays reproducible after the system moves on.
Assessor collaboration portal
Give an assessor scoped access to the evidence behind a named control rather than a folder of exports, so a sampling request resolves to the record that produced it.
Finding management
Track each finding from the assessment procedure that raised it, through management response, to closure, keeping the assessor's own wording rather than an internal paraphrase.
Remediation tracking
Bind remediation work to the control it restores, so closing an item updates the plan, the POA&M and the evidence set together instead of in three separate passes.
Audit Readiness: common questions
What replaced NIST SP 800-18 Rev 1 for writing a system security plan?
NIST SP 800-18r2, finalised on 30 June 2026 and titled Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. It supersedes SP 800-18r1 from February 2006. Rev 2 treats the system security plan, the system privacy plan and the C-SCRM plan collectively as system plans, includes technical content from other NIST publications by reference rather than repeating it, and deprecates general support system, major application and minor application for consistency with OMB Circular A-130.
Is the system security plan still one document?
Not as SP 800-18r2 frames it. The security plan, the privacy plan and the C-SCRM plan are distinct but complementary documents, issued with separate example outlines and referred to collectively as system plans. Much of what they need is the same information — authorization boundary, roles, control implementation — seen from three risk perspectives, so they can share content. What has changed is that the privacy and supply chain views are no longer optional appendices to a security document.
Does FedRAMP still require a System Security Plan?
Not under the FedRAMP Consolidated Rules for 2026. The Security Decision Record replaces the traditional System Security Plan with a persistently maintained, verified and validated record of the security decisions a provider has made across the life of its cloud service offering, supplied in both human-readable and JSON formats, and a separate Certification Package Overview takes the place of what was the base System Security Plan under Rev 5. The rules bind 20x certifications from 4 July 2026 and Rev5 from 1 January 2027, so a Rev5 package today still carries an SSP.
What actually goes into an RMF authorization package?
Under NIST SP 800-37 Rev 2, Task R-1 assembles security and privacy plans, security and privacy assessment reports, the plan of action and milestones, and supporting assessment evidence, then submits them to the authorizing official as a package with an executive summary. The publication encourages generating that package from a management tool rather than assembling hard copy. It also notes that once the plan has been approved, subsequent authorization-related actions such as reauthorization provide an inherent review and approval of it, because the plan sits inside the package.
Are ISO 27001:2013 certificates still valid?
No. IAF MD 26:2023 set the transition to ISO/IEC 27001:2022 at 36 months from the last day of the publication month, ending 31 October 2025, and requires that all certifications based on the 2013 edition expire or be withdrawn at the end of that period. A certification body that did not complete its own transition assessment in time lost its accreditation for the 2013 edition no later than the same point. An audit package or a customer questionnaire still citing a 2013 certificate is citing a document with nothing behind it.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Audit Readiness.
See how one evidence artifact satisfies Audit Readiness requirements alongside every other framework you carry.