Many companies preparing for CMMC Level 2 focus on putting controls in place, then discover that implementing a control and proving it are two different jobs. Assessors evaluate each requirement using examination of documents, interviews with staff, and testing of systems. If you cannot show evidence, a control that works may still be scored as not met.
Collecting evidence is a continuous habit, not a last-minute scramble. Here is a practical approach for contractors working to NIST SP 800-171.
Understand the Three Kinds of Evidence
Assessment methods are commonly described as examine, interview, and test. Prepare for each:
- Examine. Policies, procedures, system security plans, diagrams, configurations, logs, and records
- Interview. Staff who can describe, in their own words, how the control operates day to day
- Test. Demonstrations of systems behaving as described, such as a user attempting a blocked action
Good evidence supports all three. A written policy with no practice behind it, or a practice nobody can explain, both create problems.
Build an Evidence Index
Create a simple index, often a spreadsheet, listing each requirement and linking to its evidence. For each, record:
- The requirement identifier and a plain-English description
- How your organization meets it
- Where the supporting documents or screenshots live
- The responsible person
- The last review date
- Any gaps and the related plan of action
Keep the index consistent with your System Security Plan. The two documents should tell the same story.
Collect Evidence by Type
Policies and Procedures
Write them to describe what you actually do. Overly ambitious policies that nobody follows are a liability. Include approval dates, owners, and review cycles.
Configuration Evidence
Screenshots or exports showing settings: password and lockout policies, multifactor enforcement, encryption status, audit log configuration, and firewall rules. Capture the date, the system, and the source. Prefer exports that include a timestamp.
Records of Activity
Show that processes run repeatedly:
- Access reviews with sign-offs
- Onboarding and offboarding tickets
- Patch and vulnerability scan reports
- Security training completion records
- Incident response test notes
- Backup and restore test results
- Visitor logs and physical access records
Records over time are more convincing than a single snapshot.
Inventories and Diagrams
Maintain current asset inventories, network and data flow diagrams, and a list of users authorized to handle CUI. Outdated diagrams are a common finding.
Protect the Evidence Itself
Evidence often contains sensitive details about your environment. Store it in a restricted location with access limited to those who need it, and treat it according to your own security standards. Be careful about sending screenshots by email or storing them in broadly shared folders.
Keep It Current
Evidence goes stale. Assign owners and set review reminders. A practical rhythm:
- Monthly: scan and patch records, log review notes
- Quarterly: access reviews, backup test results, diagram checks
- Annually: policy reviews, training, incident response exercise, scope review
When you change a system, update the evidence at the same time.
Prepare Your People
Staff will be interviewed. Make sure they understand the controls that apply to them and can explain them honestly. Do not script answers, but do brief people on what an assessment looks like. Employees who handle CUI should know how to describe how they identify, mark, store, and share it.
Avoid Common Pitfalls
- Collecting evidence only in the weeks before an assessment
- Screenshots with no date or source
- Policies copied from templates that do not match your environment
- Evidence stored on the same system it describes, which may be unavailable
- No owner for each requirement
Use Gaps as Planning Tools
If you cannot find evidence for a requirement, that is a finding you can act on now. Record it in a plan of action with a realistic timeline, and understand which items can be deferred under the program rules and which cannot. Check the official requirements for your target level.
Support Along the Way
Ironfield Cyber helps defense subcontractors build evidence collection routines, organize documentation, and prepare staff for assessment. If you would like help setting up an evidence index, we can start with a gap review.