Preparing for a CMMC Assessment: Evidence Folders That Work

Assessors ask you to show, not tell. Organize evidence by requirement now so your CMMC assessment is a smooth review rather than a scramble.

3 min readBy Ironfield Cyber Team

Many defense subcontractors work hard on the technical side of CMMC and then stumble on documentation. An assessor does not take your word that multi-factor authentication is enforced or that incidents are handled. They want to see policies, interviews, and demonstrations, and they want artifacts that prove practices operate consistently.

With the CMMC program rule in effect since December 16, 2024, and DFARS contract requirements phasing in since November 10, 2025, organizations are moving from planning to proving. Organizing your evidence now saves stress and cost later. This article offers a practical structure.

Understand How Assessors Work

Assessors generally use three methods: examining documents and configurations, interviewing personnel, and testing or observing systems. Your evidence should support all three. Each requirement in NIST SP 800-171 should map to something you can show.

Build the Structure

Create a top-level folder for each control family and a subfolder for each requirement. A simple naming pattern keeps things tidy. Inside each, place:

  1. The policy or procedure that covers the requirement
  2. Configuration evidence, such as screenshots or exports that show settings
  3. Operational evidence, such as logs, tickets, or reports showing the practice happening
  4. People evidence, such as training records or role assignments
  5. A short narrative explaining how the requirement is met, in plain language

What Good Evidence Looks Like

Dated and attributable

Screenshots should show the date, the system, and the setting. Exports should include timestamps. Evidence from many months ago may not prove current practice.

Specific

A general statement that "all users have MFA" is weak. A report from your identity system listing enforced MFA for all in-scope accounts is strong.

Repeatable

Show that something happens regularly. For access reviews, keep the completed review from each quarter. For patching, keep a record of cycles. For training, keep rosters and completion records.

Consistent with your system security plan

Statements in your plan must match the evidence. Differences invite questions.

Common Evidence Examples

  • Access control: account lists, approval tickets, access review records, offboarding checklists
  • Authentication: identity system settings, MFA enrollment reports, password policy screenshots
  • Audit logs: log configuration, sample log entries, review records, retention settings
  • Configuration management: baseline documents, change tickets, approved software lists
  • Incident response: the plan, contact lists, tabletop exercise notes, incident tickets
  • Media protection: marking procedures, destruction records, removable media rules
  • Risk assessment: the assessment document, vulnerability scan results, remediation tracking
  • Awareness and training: content, attendance, completion dates
  • Physical protection: visitor logs, badge or key records, area diagrams

Keep Evidence Alive

Do not wait until the assessment to gather it. Build collection into routine work:

  • Save the quarterly access review as a standard step.
  • Attach screenshots to change tickets.
  • Export monthly vulnerability reports and file them.
  • Record training completions as they happen.

A short monthly checklist for the IT lead keeps the folders current.

Protect the Evidence

Evidence may contain sensitive configuration details. Store it in a secured repository with restricted access, and handle it with the same care as other security documentation. Be careful not to include CUI in evidence screenshots unless required and protected.

Prepare People

Evidence is only half the story. Interviewees need to explain how things work in their own words. Run practice interviews with staff in roles such as system administrator, supervisor, and HR. Make sure they know where procedures live and can describe their responsibilities without reading from a script.

Do a Mock Review

Before the real assessment, have someone not involved in daily operations, such as an outside consultant, pick requirements at random and ask for proof. Gaps show up quickly. Note the missing items and fix them, and update your plan of action where a gap will take time.

Watch for Pitfalls

  • Evidence scattered across personal drives
  • Policies that do not match practice
  • Screenshots with no dates
  • Missing approvals or signatures
  • One person who holds all the knowledge

Support Available

Ironfield Cyber can help defense subcontractors set up an evidence repository, define what to collect for each requirement, and run a mock review so the real assessment holds few surprises.