A useful CMMC evidence package is an index, not a document dump. It should let the assessment team move from a requirement and assessment objective to the relevant policy or process, system configuration, operating record, and person who can explain it.
For a resource-constrained defense contractor, the practical test is not whether a policy exists on paper, but whether the requirement is implemented inside the defined FCI/CUI boundary, assigned to an owner, and backed by current, checkable evidence.
The rule in plain English
The Level 2 Assessment Guide uses examine, interview, and test methods. Evidence therefore includes documents and records, knowledgeable personnel, and live or controlled demonstrations of technical behavior.
One artifact can support multiple objectives, but only if the mapping is clear and the artifact actually demonstrates those objectives.
How to implement it without overbuilding
Organize by requirement/objective or by evidence domain with a crosswalk. Use stable names, dates, owners, and links. Separate sensitive evidence that needs controlled access.
Run a sample review where someone outside the compliance project must find and understand evidence without verbal coaching from the person who assembled it.
What evidence to keep
Typical evidence includes SSP sections, policies and procedures, asset inventories, diagrams, directory exports, configuration reports, logs, tickets, training records, access reviews, vulnerability and patch records, backup tests, and incident/tabletop records.
Version evidence so the assessment team can tell which environment and time period it represents.
Where teams get into trouble
The worst package is thousands of screenshots with no mapping. Another failure is stale evidence that conflicts with the current SSP or live configuration.
Organize evidence at the assessment-objective level
The Level 2 assessment process works below the headline requirement. NIST SP 800-171A and the CMMC Level 2 Assessment Guide break requirements into assessment objectives and allow assessors to use examine, interview, and test methods. A strong evidence index therefore maps an objective to the artifact or live system, the responsible person, and the test or demonstration that can support the finding.
Do not create hundreds of duplicate files simply to obtain a one-to-one folder structure. One authoritative identity-policy export, network diagram, change ticket, or training record can support multiple objectives. The index should point to that source of truth and explain what part of the evidence is relevant.
- Objective identifier and plain-English intent.
- Evidence item and authoritative storage location.
- Owner/interviewee who operates or explains the control.
- Expected test or demonstration when a technical behavior must be observed.
Evidence must be final, current, and tied to the assessed scope
32 CFR 170.24 says evidence used to support a MET finding must be in final form; drafts and unofficial or unapproved policies are not acceptable evidence. That makes document status part of readiness. A beautifully written draft procedure is not the same thing as an approved procedure that employees actually use.
For Level 2 certification assessments, 32 CFR 170.17 also includes artifact-retention and integrity requirements: hashed artifacts used as evidence are retained for six years from the CMMC Status Date, with hash information provided through the assessment process. Build the evidence handoff so final-form artifacts can be frozen, identified, and retained without destroying the working copies the business still needs.
Run a three-method rehearsal before the assessment
Pick ten requirements across different families. For each one, ask what the assessor could examine, who would be interviewed, and what could be tested. Then verify that all three views tell the same story. If the SSP says remote access is restricted to a managed gateway, the diagram should show that gateway, the administrator should describe it, the configuration should enforce it, and a test should not reveal a second unmanaged path.
Use the rehearsal to find evidence gaps rather than coach employees to recite answers. The strongest interviews are from people who actually perform the work and can explain normal operation, exceptions, and escalation. When a provider performs part of a control, make sure the provider evidence is retrievable before assessment week.
A folder structure that supports the assessor without duplicating the source of truth
Keep authoritative evidence in the system that creates it whenever practical: identity exports from the directory, tickets from the service-management system, vulnerability reports from the scanner, configuration from the management platform, and approved policies from the document repository. The assessment index can point to a frozen copy or controlled export without turning the evidence folder into a second unmanaged system.
Use an evidence manifest with artifact name, source system, owner, collection date, applicable objectives, sensitivity, and retention/hash status. That manifest becomes especially important for certification-assessment artifacts subject to six-year retention and integrity requirements. It also helps the contractor remove duplicates before the assessor sees five slightly different versions of the same policy.
- Final-form policy/procedure references.
- System-generated configuration and status exports.
- Operating records such as tickets, reviews, and logs.
- Interview owner and backup.
- Expected test/demonstration.
- Artifact hash/retention fields for certification evidence.
Create a pre-assessment evidence freeze without freezing operations
Before the active assessment period, create a controlled evidence manifest that records each artifact's source, collection date, owner, applicable objectives, and hash/retention information where required. Continue normal operations; the freeze is an index of what evidence represented the environment at the assessment point, not an instruction to stop changes.
If a configuration changes during assessment, record the change normally and tell the assessment coordinator which evidence became superseded. This preserves traceability without manufacturing a static environment.
Final operating detail
Run one dry retrieval with a person who did not build the evidence library. If that person can locate the current artifact, source system, owner, objective mapping, and collection date without help, the package is much less likely to fail under assessment pressure.
Before assessment week
- ✓Build an objective-to-evidence index.
- ✓Use dated exports and records.
- ✓Name evidence owners.
- ✓Remove duplicates and stale copies.
- ✓Separate sensitive artifacts.
- ✓Run a blind retrieval test.
Common questions
Does every assessment objective need a unique file?
No. One artifact may support multiple objectives, but the mapping must be clear and defensible.
Are screenshots acceptable?
They can be useful, but exports, logs, records, and controlled tests often provide stronger context and traceability.
Will the assessor interview staff?
The assessment methodology includes interview as a method, so people operating controls should be able to explain them.
Should we give the assessor our entire security drive?
No. Provide organized, relevant evidence through the agreed assessment process rather than an uncontrolled document dump.
What should be re-checked immediately before using this guide for a contract decision?
Re-open the controlling government source, confirm the solicitation or contract language for the specific information system, and verify that the provider or program status cited here has not changed since September 4, 2026.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.


