CMMC Evidence Planning: Common Assessment Considerations
Review illustrative evidence categories for selected NIST SP 800-171 families. Actual evidence depends on scope, implementation, assessment objectives, and the assessment method used.
Table of Contents(18 sections)
Evidence Supports Assessment Findings
An implementation claim needs objective evidence during an assessment. CMMC Level 2 uses 320 assessment objectives and the examine, interview, and test methods in the current DoD Level 2 Assessment Guide. During the Phase 2 suspension, Level 2 requirements designated under Phase 1 are self-assessed. A future C3PAO assessment uses the applicable guide when contractually required.
There is no universal artifact checklist, retention period, interview answer, or review cadence for every organization. Evidence must match the validated assessment scope, the objective being assessed, the implementation in use, and any applicable contractual or regulatory requirement.
Evidence Types
NIST SP 800-171A defines three assessment methods:
Examine
Review of documents, records, and configurations:
- Policies and procedures
- System configuration settings
- Access control lists
- Audit logs
- Network diagrams
- Training records
Interview
Conversations with personnel:
- Can they describe their security responsibilities?
- Do they know the incident reporting process?
- Can they explain CUI handling procedures?
- Do they understand their role in the security program?
Test
Active verification of security controls:
- Attempt access with revoked credentials (should fail)
- Verify MFA is enforced (test a login)
- Check that audit logs capture required events
- Validate that encryption is active on CUI in transit
Illustrative Evidence Considerations by Selected Family
Access Control (AC) 22 Controls
Possible artifacts, depending on scope and implementation:
- Screenshots of user access lists and permission groups
- Role-based access control (RBAC) documentation
- Remote access policy and VPN configuration
- Wireless access point configurations
- Mobile device management (MDM) policy and enrollment screenshots
- Session timeout configuration screenshots
Validate whether:
- Generic admin accounts still active
- No documented process for access revocation when employees leave
- Remote access without MFA
Awareness & Training (AT) 3 Controls
Possible artifacts, depending on scope and implementation:
- Training completion records with dates and scores
- Training content/curriculum documentation
- Insider threat awareness training records
- New hire training evidence
- Refresher training evidence at the organization-defined or otherwise applicable cadence
Validate whether:
- No documented training for contractors/subcontractors
- Training records missing for recently hired employees
- No evidence of insider threat-specific training
Audit & Accountability (AU) 9 Controls
Possible artifacts, depending on scope and implementation:
- Audit log samples showing required events (login/logout, file access, privilege escalation)
- Log retention policy and evidence that actual retention matches defined and applicable requirements
- Log protection mechanisms (write-once, separate storage)
- Evidence of log review at the organization-defined or otherwise applicable cadence
- Time synchronization configuration (NTP settings)
Validate whether:
- Logs exist but nobody reviews them
- Actual retention differs from documented or applicable requirements
- No alerting on suspicious events
Identification & Authentication (IA) 11 Controls
Possible artifacts, depending on scope and implementation:
- MFA enrollment screenshots for all CUI-access accounts
- Password and authenticator policy configuration relevant to the assessed implementation
- Account lockout settings
- Service account inventory and justification
- Certificate-based authentication evidence (if applicable)
Validate whether:
- MFA not enforced for all CUI-access accounts
- Shared or generic accounts without justification
- Authentication settings align with the assessed requirement and the organization's applicable parameters
Incident Response (IR) 3 Controls
Possible artifacts, depending on scope and implementation:
- Incident response plan document
- IR team roster with roles and contact information
- Tabletop exercise or drill documentation at the organization-defined or otherwise applicable cadence
- Incident tracking log (even if empty shows the process exists)
- Evidence of IR plan distribution to relevant personnel
Validate whether:
- IR plan exists but was never tested
- Exercise and test records match the documented and applicable cadence
- IR team members unaware of their roles
System & Communications Protection (SC) 16 Controls
Possible artifacts, depending on scope and implementation:
- Network diagrams showing CUI boundary segmentation
- Firewall rules and configurations
- Encryption settings for data in transit (TLS, VPN)
- Encryption settings for data at rest
- DNS filtering or web proxy configuration
- VOIP security settings (if applicable)
Validate whether:
- CUI boundary not clearly defined in network diagrams
- Encryption not enabled for all CUI transmission paths
- No network segmentation between CUI and general systems
Evidence Organization Strategy
By Control Family
Organize evidence in folders matching NIST control families:
/Evidence
/AC - Access Control
/3.1.1 - Authorized Access
/3.1.2 - Transaction Types
...
/AT - Awareness Training
/3.2.1 - Security Awareness
...
Naming Convention
Use descriptive names with dates:
AC-3.1.1-AD-Group-Membership-Screenshot-2026-03-01.png
AU-3.3.1-SIEM-Audit-Log-Sample-2026-02-15.pdf
IR-3.6.1-Incident-Response-Plan-v2.3.pdf
Evidence Currency
- Screenshots and configs: Current enough to demonstrate the implementation during the assessment period agreed in the assessment plan
- Policies: Current, approved under the organization's review cycle, and consistent with actual implementation
- Training records: Cover the applicable personnel and periods needed to demonstrate the requirement
- Audit logs: Continuous coverage and retention appropriate to the requirement, contract, and assessment plan
- Vulnerability scans: Current enough to demonstrate the implemented scanning and remediation process
Using an Evidence Vault
A centralized evidence vault (like CMMC Command's) provides:
- Expiration tracking: Know when evidence needs refreshing
- Control mapping: Evidence linked directly to controls
- Storage and limited marker screening: Store permitted evidence and run a best-effort check for limited CUI or classification markers. The check does not determine whether a file contains CUI, and users must not upload CUI or classified material
- Audit trail: Track who uploaded what and when
- Quick retrieval: Find any evidence in seconds during assessment
The Golden Rule
An implementation claim needs adequate objective evidence. Depending on the assessment objective and assessment plan, evidence may come from documents, interviews, and tests; there is no universal one-file-per-requirement rule.
Build your evidence vault. Centralized storage and expiration tracking for permitted evidence. Do not upload CUI or classified material; limited marker screening is best-effort and is not a CUI determination.
Related Resources
Organize your CMMC preparation
Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.