Starters. Not filled-in artifacts.
Download these, edit them, and replace every example. They are blank structure for an inventory, a system security plan section, and a vendor split. An assessor will want your facts, not this wording.
Not legal advice. This is a plain-language reading aid for contractors and the providers who support them. It is not a CMMC assessment, not a FedRAMP determination, and not a substitute for 32 CFR Part 170, the contract, or advice from counsel. Templates and worksheet results are starters. Replace every example with your own facts.
Markdown
SPA inventory and data-flow
Blank inventory columns plus a data-flow table. One example row, marked as an example.
CSV
SPA inventory spreadsheet
Same inventory columns in a file a spreadsheet can open. Delete the example row.
Markdown
SSP section for Security Protection Assets
Starter language for how the system security plan treats SPAs. Not a filled plan.
Markdown
Shared responsibility matrix
Topics to split between the contractor and an SPA vendor. Every cell is a prompt.
Markdown
Vendor due-diligence questionnaire
The same questions as the survey page, in a file you can send.
How the pieces fit
The Level 2 Scoping Guide says to document each in-scope asset in an inventory, and it says there is no requirement to embed each asset in the system security plan. The plan documents treatment. The network diagram shows the assets. For an external provider, § 170.19 asks for the relationship and the services in the plan, and for a customer responsibility matrix from the provider.
Use the inventory for names and data flows. Use the SSP section for treatment. Use the matrix for who does what. Use the questionnaire when the vendor has to answer before you can fill either one.