Companies preparing for a CMMC assessment often focus on implementing controls: turning on multi-factor authentication, encrypting laptops, writing policies. Those steps matter. But an assessor cannot see into your head. They evaluate evidence that each practice is implemented, and a control you cannot demonstrate is a control you will struggle to get credit for.
This post explains in general terms how evidence works and how a small defense contractor can organize it. Requirements are drawn from NIST SP 800-171 as used in the CMMC program, and your specific level and scope come from your contract and assessment type.
The Three Kinds of Evidence
Assessors generally gather information in three ways.
Documents
Policies, procedures, plans, diagrams, inventories and records. Examples include your system security plan, access control policy, incident response plan, network diagram, hardware and software inventory and training records.
Interviews
Assessors talk to people responsible for the controls and to ordinary employees. They want to hear that the procedure on paper matches what people actually do. If your IT lead and your project manager describe different processes, expect follow-up questions.
Demonstrations and observations
You show systems in operation: logging in with multi-factor authentication, displaying audit logs, showing encryption settings or walking through how a user is removed. Screenshots, configuration exports and live demos all count.
The most convincing evidence combines all three: a written policy, a person who can explain it and a system that behaves accordingly.
What Good Evidence Looks Like
- Specific. It names the system, setting, date and responsible person.
- Current. A policy last reviewed years ago, or a screenshot from before a system migration, invites doubt.
- Consistent. Documents, interviews and system settings agree.
- Traceable. Each item maps to a particular practice.
- Protected. Evidence itself may contain sensitive information, so store it securely.
Organizing the Evidence
A simple structure beats an elaborate one.
- Create a folder structure by control family. Examples include access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection and system and information integrity.
- Use a tracking list. For each practice, record how you meet it, who owns it, where the evidence is and when it was last updated.
- Name files clearly. Include the topic and date, such as "MFA configuration export, 2026-03."
- Keep a record of dates. Policies should show review dates and approvers.
- Store it in a controlled location with limited access, and keep a backup.
Evidence Examples by Topic
- Access control: account lists, role definitions, access request and removal records, remote access settings.
- Identification and authentication: multi-factor authentication settings and password policy configuration.
- Audit and accountability: log settings, retention evidence and samples of reviewed logs.
- Configuration management: baseline configurations, change records and the software inventory.
- Incident response: the plan, contact lists and results of a tabletop exercise.
- Media protection: encryption settings, sanitization records and rules for removable media.
- Personnel security: screening procedures, termination checklists and training completion.
- Risk assessment and vulnerability management: scan results and remediation records.
Common Evidence Gaps
- Policies exist but have never been approved or reviewed.
- Logs are collected but no one can show they are reviewed.
- Offboarding procedures exist but there is no record of them being followed.
- Training happened but attendance was not recorded.
- Inventories are incomplete or out of date.
- Configuration settings differ from what the plan says.
- Plans of action for known gaps are missing, or deadlines have passed.
Build Evidence as You Operate
The easiest evidence is generated by doing the work. When you remove an employee's access, save the ticket. When you review logs, record the date and findings. When you apply patches, keep the report. If you wait until three weeks before the assessment to reconstruct everything, you will miss details and invite errors.
Practice With a Mock Review
Have someone who did not implement the controls, such as an IT partner or consultant, act as the assessor. They ask for proof of each practice, and you produce it. Every item you cannot produce quickly shows where to improve. Do this at least once before the real assessment, with enough time to fix what you find.
Getting Ready
Ironfield Cyber helps defense subcontractors organize assessment evidence, build tracking lists and run mock reviews. If you are working toward a CMMC assessment, we can help you find the gaps while there is still time to close them.