Many contractors implement real security controls and still struggle in an assessment because they cannot show the work. Policies live in different folders, screenshots are missing, logs have rolled over and the person who knew how a control works has left. Assessors, insurers and primes do not take your word for it. They look for evidence.
An organized evidence folder, maintained all year, turns an assessment from a scramble into a review.
What counts as evidence
Evidence generally falls into three categories:
- Documents: policies, procedures, plans, diagrams and training materials that say what you do
- Configurations and screenshots: proof that systems are set up the way your documents describe
- Records: logs, tickets, reports, meeting notes and sign-offs that show the control operating over time
Strong evidence connects all three. A policy says you review access quarterly, a configuration shows how access is managed, and a record shows that reviews actually happened.
Organize around the requirements
Structure the folder to mirror the framework you are measured against, such as the NIST SP 800-171 requirement families or the CMMC practices. For each requirement, keep:
- The requirement or practice identifier and a brief description
- How you meet it, in plain language
- Links or files for supporting policies and procedures
- Technical evidence, such as screenshots or exports
- Operating records, such as logs or review sign-offs
- The owner responsible and the date last reviewed
- Any gaps and the related plan of action
A simple spreadsheet index pointing to files in an organized folder tree works well.
Good evidence is dated, specific and attributable
- Dated: screenshots and exports should show the date. Note when you captured them.
- Specific: show actual settings, not a generic vendor feature page.
- Attributable: identify the system and who produced the evidence.
- Current: evidence from three years ago will not convince anyone.
Examples of useful evidence
Access control
- An access control policy
- An export of user accounts and group memberships with review sign-offs
- A screenshot of MFA enforcement settings
- Onboarding and offboarding tickets showing timely changes
Training
- A training policy and curriculum
- Attendance records
- Phishing exercise reports and follow-up actions
Incident response
- An incident response plan with contacts
- Tabletop exercise notes and lessons learned
- Records of past incidents and how they were handled
Backup and recovery
- A backup policy
- Job reports showing successful completion
- Results from restore tests
Configuration and patching
- Baseline configuration documents
- Patch reports showing coverage and timelines
- Records of approved exceptions
Physical security
- Visitor logs and access lists
- Photos or descriptions of locked storage areas
Make evidence collection routine
- Assign owners for each control area, with backups.
- Set a calendar for recurring evidence: monthly exports, quarterly access reviews, annual training and tests.
- Automate where possible. Many tools can schedule reports and send them to a shared location.
- Use consistent naming. A convention like requirement ID, description and date helps people find things.
- Protect the evidence. Limit access, keep backups and remember that evidence may contain sensitive configuration details.
- Review quarterly. Check for gaps and stale items.
Avoid common mistakes
- Collecting evidence only when an assessment is announced
- Storing everything in one person's email or desktop
- Using screenshots that do not show dates or system names
- Policies that describe controls you do not actually perform
- Letting logs expire before you capture what you need
- Ignoring gaps rather than documenting them with a plan
Honesty matters. A documented gap with a realistic plan is much better than an overstated claim that falls apart under questioning.
A hypothetical example
Consider a hypothetical subcontractor that runs quarterly access reviews but only discusses them in meetings. When asked for proof, nobody can show what was reviewed or who approved changes. Adding a one-page review form with names, dates and actions turns the same activity into usable evidence.
Keep it manageable
Start with the highest-risk controls and build outward. A modest, accurate evidence set beats a sprawling one nobody maintains.
Getting help
Ironfield Cyber helps contractors and energy companies set up evidence structures, assign owners and gather the technical proof behind their policies. If you are preparing for CMMC, an insurance review or a prime contractor audit, we can help you organize what you have and identify what is missing.