Evidence Collection

    CMMC Evidence Collection: What Assessors Actually Want to See

    CMMC evidence collection is the work most teams underestimate. The standard is not "we have a policy" — it is a defensible chain from each of the 320 NIST 800-171A objectives back to the policy, procedure, configuration, log, screenshot, or interview that proves the control is operating. This page covers what evidence C3PAOs actually accept, the freshness windows that matter, and how to map evidence to objectives without losing the trail.

    Evidence coverage: 0 of 320 objectives

    A practice is only Met when every applicable objective under it is satisfied with evidence an assessor can examine, corroborate in interview, and where applicable test. 110 requirements decompose into 320 objectives — objectives, not practices, are what get assessed.

    Source: CMMC Assessment Guide - Level 2, Version 2.13 (CMMC-L2-v2.13); objective language per NIST SP 800-171A Rev. 2.

    Search and filter objectives

    Showing 320 objectives.

    • AC · Authorized Access Control [Cui Data]

    • AC · Authorized Access Control [Cui Data]

    • AC · Authorized Access Control [Cui Data]

    • AC · Authorized Access Control [Cui Data]

    • AC · Authorized Access Control [Cui Data]

    • AC · Authorized Access Control [Cui Data]

    • AC · Transaction & Function Control

    • AC · Transaction & Function Control

    • AC · Control Cui Flow

    • AC · Control Cui Flow

    • AC · Control Cui Flow

    • AC · Control Cui Flow

    • AC · Control Cui Flow

    • AC · Separation Of Duties

    • AC · Separation Of Duties

    • AC · Separation Of Duties

    • AC · Least Privilege

    • AC · Least Privilege

    • AC · Least Privilege

    • AC · Least Privilege

    • AC · Non-Privileged Account Use

    • AC · Non-Privileged Account Use

    • AC · Privileged Functions

    • AC · Privileged Functions

    • AC · Privileged Functions

    • AC · Privileged Functions

    • AC · Unsuccessful Logon Attempts

    • AC · Unsuccessful Logon Attempts

    • AC · Privacy & Security Notices

    • AC · Privacy & Security Notices

    • AC · Session Lock

    • AC · Session Lock

    • AC · Session Lock

    • AC · Session Termination

    • AC · Session Termination

    • AC · Control Remote Access

    • AC · Control Remote Access

    • AC · Control Remote Access

    • AC · Control Remote Access

    • AC · Remote Access Confidentiality

    • AC · Remote Access Confidentiality

    • AC · Remote Access Routing

    • AC · Remote Access Routing

    • AC · Privileged Remote Access

    • AC · Privileged Remote Access

    • AC · Privileged Remote Access

    • AC · Privileged Remote Access

    • AC · Wireless Access Authorization

    • AC · Wireless Access Authorization

    • AC · Wireless Access Protection

    • AC · Wireless Access Protection

    • AC · Mobile Device Connection

    • AC · Mobile Device Connection

    • AC · Mobile Device Connection

    • AC · Encrypt Cui On Mobile

    • AC · Encrypt Cui On Mobile

    • AC · External Connections [Cui Data]

    • AC · External Connections [Cui Data]

    • AC · External Connections [Cui Data]

    • AC · External Connections [Cui Data]

    • AC · External Connections [Cui Data]

    • AC · External Connections [Cui Data]

    • AC · Portable Storage Use

    • AC · Portable Storage Use

    • AC · Portable Storage Use

    • AC · Control Public Information [Cui Data]

    • AC · Control Public Information [Cui Data]

    • AC · Control Public Information [Cui Data]

    • AC · Control Public Information [Cui Data]

    • AC · Control Public Information [Cui Data]

    • AT · Role-Based Risk Awareness

    • AT · Role-Based Risk Awareness

    • AT · Role-Based Risk Awareness

    • AT · Role-Based Risk Awareness

    • AT · Role-Based Training

    • AT · Role-Based Training

    • AT · Role-Based Training

    • AT · Insider Threat Awareness

    • AT · Insider Threat Awareness

    • AU · System Auditing

    • AU · System Auditing

    • AU · System Auditing

    • AU · System Auditing

    • AU · System Auditing

    • AU · System Auditing

    • AU · User Accountability

    • AU · User Accountability

    • AU · Event Review

    • AU · Event Review

    • AU · Event Review

    • AU · Audit Failure Alerting

    • AU · Audit Failure Alerting

    • AU · Audit Failure Alerting

    • AU · Audit Correlation

    • AU · Audit Correlation

    • AU · Reduction & Reporting

    • AU · Reduction & Reporting

    • AU · Authoritative Time Source

    • AU · Authoritative Time Source

    • AU · Authoritative Time Source

    • AU · Audit Protection

    • AU · Audit Protection

    • AU · Audit Protection

    • AU · Audit Protection

    • AU · Audit Protection

    • AU · Audit Protection

    • AU · Audit Management

    • AU · Audit Management

    • CM · System Baselining

    • CM · System Baselining

    • CM · System Baselining

    • CM · System Baselining

    • CM · System Baselining

    • CM · System Baselining

    • CM · Security Configuration Enforcement

    • CM · Security Configuration Enforcement

    • CM · System Change Management

    • CM · System Change Management

    • CM · System Change Management

    • CM · System Change Management

    • CM · Security Impact Analysis

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Access Restrictions For Change

    • CM · Least Functionality

    • CM · Least Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Nonessential Functionality

    • CM · Application Execution Policy

    • CM · Application Execution Policy

    • CM · Application Execution Policy

    • CM · User-Installed Software

    • CM · User-Installed Software

    • CM · User-Installed Software

    • IA · Identification [Cui Data]

    • IA · Identification [Cui Data]

    • IA · Identification [Cui Data]

    • IA · Authentication [Cui Data]

    • IA · Authentication [Cui Data]

    • IA · Authentication [Cui Data]

    • IA · Multifactor Authentication

    • IA · Multifactor Authentication

    • IA · Multifactor Authentication

    • IA · Multifactor Authentication

    • IA · Replay-Resistant Authentication

    • IA · Identifier Reuse

    • IA · Identifier Reuse

    • IA · Identifier Handling

    • IA · Identifier Handling

    • IA · Password Complexity

    • IA · Password Complexity

    • IA · Password Complexity

    • IA · Password Complexity

    • IA · Password Reuse

    • IA · Password Reuse

    • IA · Temporary Passwords

    • IA · Cryptographically-Protected Passwords

    • IA · Cryptographically-Protected Passwords

    • IA · Obscure Feedback

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Handling

    • IR · Incident Reporting

    • IR · Incident Reporting

    • IR · Incident Reporting

    • IR · Incident Reporting

    • IR · Incident Reporting

    • IR · Incident Reporting

    • IR · Incident Response Testing

    • MA · Perform Maintenance

    • MA · System Maintenance Control

    • MA · System Maintenance Control

    • MA · System Maintenance Control

    • MA · System Maintenance Control

    • MA · Equipment Sanitization

    • MA · Media Inspection

    • MA · Nonlocal Maintenance

    • MA · Nonlocal Maintenance

    • MA · Maintenance Personnel

    • MP · Media Protection

    • MP · Media Protection

    • MP · Media Protection

    • MP · Media Protection

    • MP · Media Access

    • MP · Media Disposal [Cui Data]

    • MP · Media Disposal [Cui Data]

    • MP · Media Markings

    • MP · Media Markings

    • MP · Media Accountability

    • MP · Media Accountability

    • MP · Portable Storage Encryption

    • MP · Removeable Media

    • MP · Shared Media

    • MP · Protect Backups

    • PS · Screen Individuals

    • PS · Personnel Actions

    • PS · Personnel Actions

    • PS · Personnel Actions

    • PE · Limit Physical Access [Cui Data]

    • PE · Limit Physical Access [Cui Data]

    • PE · Limit Physical Access [Cui Data]

    • PE · Limit Physical Access [Cui Data]

    • PE · Monitor Facility

    • PE · Monitor Facility

    • PE · Monitor Facility

    • PE · Monitor Facility

    • PE · Escort Visitors [Cui Data]

    • PE · Escort Visitors [Cui Data]

    • PE · Physical Access Logs [Cui Data]

    • PE · Manage Physical Access [Cui Data]

    • PE · Manage Physical Access [Cui Data]

    • PE · Manage Physical Access [Cui Data]

    • PE · Alternative Work Sites

    • PE · Alternative Work Sites

    • RA · Risk Assessments

    • RA · Risk Assessments

    • RA · Vulnerability Scan

    • RA · Vulnerability Scan

    • RA · Vulnerability Scan

    • RA · Vulnerability Scan

    • RA · Vulnerability Scan

    • RA · Vulnerability Remediation

    • RA · Vulnerability Remediation

    • CA · Security Control Assessment

    • CA · Security Control Assessment

    • CA · Operational Plan Of Action

    • CA · Operational Plan Of Action

    • CA · Operational Plan Of Action

    • CA · Security Control Monitoring

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • CA · System Security Plan

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Boundary Protection [Cui Data]

    • SC · Security Engineering

    • SC · Security Engineering

    • SC · Security Engineering

    • SC · Security Engineering

    • SC · Security Engineering

    • SC · Security Engineering

    • SC · Role Separation

    • SC · Role Separation

    • SC · Role Separation

    • SC · Shared Resource Control

    • SC · Public-Access System Separation [Cui Data]

    • SC · Public-Access System Separation [Cui Data]

    • SC · Network Communication By Exception

    • SC · Network Communication By Exception

    • SC · Split Tunneling

    • SC · Data In Transit

    • SC · Data In Transit

    • SC · Data In Transit

    • SC · Connections Termination

    • SC · Connections Termination

    • SC · Connections Termination

    • SC · Key Management

    • SC · Key Management

    • SC · Cui Encryption

    • SC · Collaborative Device Control

    • SC · Collaborative Device Control

    • SC · Collaborative Device Control

    • SC · Mobile Code

    • SC · Mobile Code

    • SC · Voice Over Internet Protocol

    • SC · Voice Over Internet Protocol

    • SC · Communications Authenticity

    • SC · Data At Rest

    • SI · Flaw Remediation [Cui Data]

    • SI · Flaw Remediation [Cui Data]

    • SI · Flaw Remediation [Cui Data]

    • SI · Flaw Remediation [Cui Data]

    • SI · Flaw Remediation [Cui Data]

    • SI · Flaw Remediation [Cui Data]

    • SI · Malicious Code Protection [Cui Data]

    • SI · Malicious Code Protection [Cui Data]

    • SI · Security Alerts & Advisories

    • SI · Security Alerts & Advisories

    • SI · Security Alerts & Advisories

    • SI · Update Malicious Code Protection [Cui Data]

    • SI · System & File Scanning [Cui Data]

    • SI · System & File Scanning [Cui Data]

    • SI · System & File Scanning [Cui Data]

    • SI · Monitor Communications For Attacks

    • SI · Monitor Communications For Attacks

    • SI · Monitor Communications For Attacks

    • SI · Identify Unauthorized Use

    • SI · Identify Unauthorized Use

    Sanitized example

    Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.

    For 3.1.1[c] Northgate Precision plans: "Device inventory export from endpoint manager, reviewed quarterly; procedure section 4.2 defines authorization; interview the IT lead; test by attempting to join an unenrolled laptop." That single line names the artifact, the corroborating interview, and the test — which is what an assessor needs, and it contains no CUI.

    One path forward

    Free result → $129 CMMC Survival Report → Athena workspace

    1. Free, right now: keep the result and downloads from this tool. No account, no e-mail required.
    2. $129 CMMC Survival Report: an objective-level readiness snapshot with your weakest practices, prioritized remediation order, and an assessor-facing narrative.
    3. Athena workspace / evidence sprint: continuous objective-level tracking, evidence defensibility scoring, and assessor-ready artifacts.

    Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.

    The other free CMMC tools

    Score all 110 requirements with official weighted deductions.
    Met / Not Met / N/A across 110 requirements with a gap report.
    Categorize assets and define your assessment boundary.
    Build a DoD-oriented POA&M with eligibility warnings.
    Day-one evidence list, mock intake, and readiness verdict.

    Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.

    The 320-objective problem

    CMMC Level 2 has 110 controls. NIST 800-171A breaks those 110 controls into 320 discrete assessment objectives. A C3PAO grades you against the objectives, not the controls. A spreadsheet with 110 rows cannot capture which objectives within a partially-implemented control are met, which are not, and what evidence backs each. This is why most manual evidence collection efforts collapse: the unit of work is the objective, not the control.

    Evidence types C3PAOs accept

    • Policy. The "what we do" document — signed, dated, version-controlled.
    • Procedure. The "how we do it" document — referenced from the policy, with named owners.
    • Configuration. A baseline export, group policy dump, IaC manifest, or system-generated configuration report.
    • Log / telemetry. SIEM output, EDR alerts, authentication logs, vulnerability scan results — operational proof the control is running.
    • Screenshot. Time-stamped UI capture for controls that cannot be exported as data (e.g., admin console settings).
    • Interview. Auditor interview with the named responsible party. Backed by documentation, not the only evidence.
    • Inherited evidence. Cloud provider or MSSP artifacts surfaced through your SRM.

    Mapping evidence to objectives

    A worked example for five common controls:

    • AC.L2-3.1.1 (account management): identity provider user export + JML procedure + recent provisioning ticket.
    • AU.L2-3.3.1 (audit logging): SIEM ingest configuration + 90-day log sample + log retention policy.
    • CM.L2-3.4.1 (baseline configuration): baseline document + IaC manifest + drift detection report.
    • IA.L2-3.5.3 (MFA): MFA enforcement policy + admin console screenshot + 30-day MFA challenge log.
    • SI.L2-3.14.1 (flaw remediation): patch policy + vulnerability scan output + closed remediation tickets.

    Each row is one objective, multiple evidence artifacts, mapped at ingest. The trail does not work if the mapping happens at export time.

    Freshness — why a 14-month-old screenshot fails

    C3PAOs expect evidence that proves the control is operating currently, not that it operated once. The accepted freshness window varies by evidence type: configuration baselines within 90 days, log samples covering the last 30–90 days, policies reviewed in the last 12 months, screenshots dated within 30 days of submission. A screenshot from a year ago is not evidence — it is a historical artifact. Athena's evidence freshness radar tags every artifact with its age and flags drift before the C3PAO sees it.

    How Athena automates this

    Athena ingests evidence from your stack — identity provider, EDR, SIEM, vulnerability scanner, configuration tools, document repositories — and auto-links it to the NIST 800-171A objectives it satisfies. Reviewers approve or reject each link. The SSP, POA&M, and assessor evidence bundle all generate from the same ledger, so the three artifacts tell the same story by assessment day. See the workflow automation pillar for the full pipeline.

    Frequently asked questions

    What is the difference between evidence and artifacts?

    Practically interchangeable in CMMC conversations. 'Artifact' tends to refer to the discrete file (a policy PDF, a log export). 'Evidence' refers to artifacts in the context of proving a specific objective. A single artifact can serve as evidence for multiple objectives.

    How fresh does CMMC evidence have to be?

    Depends on the evidence type. Configuration baselines and screenshots within 30–90 days; log samples covering the last 30–90 days; policies reviewed annually. The C3PAO judgment is whether the evidence proves the control operates today, not whether it operated once.

    Does a screenshot count as evidence?

    Yes, for controls that cannot be exported as data — admin console settings, UI configurations, dashboards. Screenshots must be time-stamped, dated within 30 days of submission, and supported by procedure documentation. They should not be the only evidence for a technical control.

    Can I reuse SOC 2 or ISO 27001 evidence for CMMC?

    Some, with caveats. SOC 2 and ISO controls overlap with NIST 800-171 in the 60–70% range. The mapping is not 1:1 — a SOC 2 control may satisfy two NIST objectives and miss a third. Reuse evidence where the underlying control is identical; supplement where it is not.

    What if I cannot produce evidence for a control?

    If the control is POA&M-eligible, document the gap in the POA&M with a closure plan and date. If it is not POA&M-eligible (some controls are not, per the final rule), you must close the gap before assessment. The C3PAO will not accept 'we are working on it' as evidence.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.