A software development company is applying for a CMMC Level 2 assessment. As the Lead Assessor, you request access to the company’s System Security Plan (SSP) as part of the initial objective evidence for validating the scope. Which of the following is true about the software development company’s obligations in honoring the request?
Submit