The Program Protection Plan (PPP) is the single source document used to coordinate and integrate all protection efforts. It’s designed to deny access to Critical Program Information (CPI) to anyone not authorized, not having a need to know and prevent inadvertent disclosure of leading-edge technology to foreign interests.
Definition: The Program Protection Plan (PPP) is a security-focused document to guide efforts to manage the security risks to Critical Program Information (CPI) and mission-critical functions and components for a system and program.
Program Protection Plan (PPP) Purpose
The purpose of the PPP is to coordinate and integrate all security efforts throughout the entire system’s life cycle to ensure that there is adequate protection against hostile activities against a program.
Program Protection Plan (PPP) Approval
The PPP is approved by the Program Manager (PM) after an Initial Capabilities Document (ICD) has been validated and is part of the Security Classification Guide (SCG). A draft is due for the Development RFP Release Decision and is approved at Milestone B. [1,2]
Developing the Program Protection Plan (PPP)
The following guidance describes the process used to prepare a PPP when one is required: 
- Any program, product, technology demonstrator, or other item developed as part of a separate acquisition process and used as a component, subsystem, or modification of another program should publish a PPP.
- The effectiveness of the PPP is highly dependent upon the quality and currency of the information available to the program office.
- Coordination between the Program Management Office (PMO) and supporting Counterintelligence (CI) and security activities is critical to ensure that any changes in the system CPI, threat, or environmental conditions are communicated to the proper organizations.
- Intelligence and CI organizations supporting the program protection effort should provide timely notification to the PM of any information on adverse foreign interests targeting their CPI without waiting for a periodic production request.
Program Protection Plan (PPP) References
Program Protection Plan (PPP) Content
While there is no specific format for PPPs, they normally include the following: 
- System and program description
- All program and support points of contact
- A list of program CPI
- Counterintelligence Analysis of CPI
- Vulnerabilities of CPI
- All Research and Technology Protection countermeasures (e.g., anti-tamper techniques, system security engineering) and Militarily Critical Technology List citations for applicable CPI
- All RTP associated costs, by Fiscal Year, to include PPP development and execution
- Foreign disclosure, direct commercial sales, co-production, import, export license or other export authorization requirements, and/or Technology Assessment/Control Plan
- Delegation of Disclosure Authority Letter (DDL), if appropriate
- Program Security Instruction, if appropriate
Example Program Protection Plan (PPP) Format
The following is an example format that program managers and security managers can follow when developing the PPP.
- Section 1: Introduction
- Section 2: Summary
- Section 3: Critical Program Information (CPI)
- Section 4: Horizontal Protection
- Section 5: Threats, Vulnerabilities, and Countermeasures
- Section 6: Other system-related plans and documents
- Section 7: Risks
- Section 8: Foreign Involvement
- Section 9: Process for Management and Implementation of PPP
- Section 10: Process for monitoring and Reporting Compromises
- Section 11: Program Protection Costs
The PPP document includes five (5) Appendices:
- Appendix 1: Security Classification Guide (SCG)
- Appendix 2: Counterintelligence Support Plan (CISP)
- Appendix 3: Criticality Analysis
- Appendix 4: Anti-Tamper (AT) Plan
- Appendix 5: Cybersecurity Strategy
A draft update is due for the Development RFP Release Decision and is approved at Milestone B. The PPP includes appropriate appendixes or links to required information. 
DoD Instruction (DoDI) 5000.02, Change 3 requires that the PPP document be submitted five times for Milestone Decision Authority (MDA) review and approval at Milestone A, Development RFP Release Decision, Milestone B, Milestone C, and Full-Rate Production Decision Review (FRPDR).
- Detailed descriptions of program protection activities are provided in the Defense Acquisition Guidebook Chapter 13
AcqLinks and References:
-  Defense Acquisition Guidebook (DAG) – Chapter 9
-  DoD Instruction 5000.02 “Operation of the Defense Acquisition System”
- Guide: USAF Weapon System PP and SSE Guidebook v2.0
- Template: Program Protection Plan (PPP) Template v3.2 – Jul 11