CMMC Level 2 Control Evidence Library
25 in-depth guides covering NIST SP 800-171 / CMMC Level 2 controls — what each requirement actually asks for, what a C3PAO or DIBCAC assessor will examine, interview, and test, concrete evidence examples, and the failure patterns that sink assessments.
Grouped by the 14 NIST 800-171 control families. Updated June 22, 2026.
ACAccess Control(3)
Who and what is allowed to reach the system, and what they're allowed to do once inside.
AUAudit and Accountability(1)
Generating, protecting, and reviewing the records that prove what happened.
CASecurity Assessment(3)
Assessing controls, tracking gaps in a POA&M, and maintaining the SSP.
CMConfiguration Management(2)
Defining a secure baseline and enforcing it across systems.
IAIdentification and Authentication(4)
Uniquely identifying users and devices and proving they are who they claim to be.
IRIncident Response(2)
Handling incidents and meeting the DFARS 7012 / DIBNet 72-hour reporting path.
MPMedia Protection(1)
Sanitizing or destroying media that has held CUI before disposal or reuse.
RARisk Assessment(1)
Identifying vulnerabilities in systems that process CUI.
SCSystem and Communications Protection(5)
Boundary defense, network architecture, and encryption in transit.
SISystem and Information Integrity(3)
Patching flaws and monitoring systems for malicious activity.