Gathering Evidence for NIST 800-171: What to Keep and How

Assessors want proof, not promises. Learn what evidence to collect for NIST SP 800-171 controls, how to organize it, and how to keep it current between reviews.

3 min readBy Ironfield Cyber Team

Many companies preparing for CMMC Level 2 focus on putting controls in place, then discover that implementing a control and proving it are two different jobs. Assessors evaluate each requirement using examination of documents, interviews with staff, and testing of systems. If you cannot show evidence, a control that works may still be scored as not met.

Collecting evidence is a continuous habit, not a last-minute scramble. Here is a practical approach for contractors working to NIST SP 800-171.

Understand the Three Kinds of Evidence

Assessment methods are commonly described as examine, interview, and test. Prepare for each:

  • Examine. Policies, procedures, system security plans, diagrams, configurations, logs, and records
  • Interview. Staff who can describe, in their own words, how the control operates day to day
  • Test. Demonstrations of systems behaving as described, such as a user attempting a blocked action

Good evidence supports all three. A written policy with no practice behind it, or a practice nobody can explain, both create problems.

Build an Evidence Index

Create a simple index, often a spreadsheet, listing each requirement and linking to its evidence. For each, record:

  1. The requirement identifier and a plain-English description
  2. How your organization meets it
  3. Where the supporting documents or screenshots live
  4. The responsible person
  5. The last review date
  6. Any gaps and the related plan of action

Keep the index consistent with your System Security Plan. The two documents should tell the same story.

Collect Evidence by Type

Policies and Procedures

Write them to describe what you actually do. Overly ambitious policies that nobody follows are a liability. Include approval dates, owners, and review cycles.

Configuration Evidence

Screenshots or exports showing settings: password and lockout policies, multifactor enforcement, encryption status, audit log configuration, and firewall rules. Capture the date, the system, and the source. Prefer exports that include a timestamp.

Records of Activity

Show that processes run repeatedly:

  • Access reviews with sign-offs
  • Onboarding and offboarding tickets
  • Patch and vulnerability scan reports
  • Security training completion records
  • Incident response test notes
  • Backup and restore test results
  • Visitor logs and physical access records

Records over time are more convincing than a single snapshot.

Inventories and Diagrams

Maintain current asset inventories, network and data flow diagrams, and a list of users authorized to handle CUI. Outdated diagrams are a common finding.

Protect the Evidence Itself

Evidence often contains sensitive details about your environment. Store it in a restricted location with access limited to those who need it, and treat it according to your own security standards. Be careful about sending screenshots by email or storing them in broadly shared folders.

Keep It Current

Evidence goes stale. Assign owners and set review reminders. A practical rhythm:

  • Monthly: scan and patch records, log review notes
  • Quarterly: access reviews, backup test results, diagram checks
  • Annually: policy reviews, training, incident response exercise, scope review

When you change a system, update the evidence at the same time.

Prepare Your People

Staff will be interviewed. Make sure they understand the controls that apply to them and can explain them honestly. Do not script answers, but do brief people on what an assessment looks like. Employees who handle CUI should know how to describe how they identify, mark, store, and share it.

Avoid Common Pitfalls

  • Collecting evidence only in the weeks before an assessment
  • Screenshots with no date or source
  • Policies copied from templates that do not match your environment
  • Evidence stored on the same system it describes, which may be unavailable
  • No owner for each requirement

Use Gaps as Planning Tools

If you cannot find evidence for a requirement, that is a finding you can act on now. Record it in a plan of action with a realistic timeline, and understand which items can be deferred under the program rules and which cannot. Check the official requirements for your target level.

Support Along the Way

Ironfield Cyber helps defense subcontractors build evidence collection routines, organize documentation, and prepare staff for assessment. If you would like help setting up an evidence index, we can start with a gap review.