Evidence Collection

    CMMC Evidence Collection: What Assessors Actually Want to See

    CMMC evidence collection is the work most teams underestimate. The standard is not "we have a policy" — it is a defensible chain from each of the 320 NIST 800-171A objectives back to the policy, procedure, configuration, log, screenshot, or interview that proves the control is operating. This page covers what evidence C3PAOs actually accept, the freshness windows that matter, and how to map evidence to objectives without losing the trail.

    The 320-objective problem

    CMMC Level 2 has 110 controls. NIST 800-171A breaks those 110 controls into 320 discrete assessment objectives. A C3PAO grades you against the objectives, not the controls. A spreadsheet with 110 rows cannot capture which objectives within a partially-implemented control are met, which are not, and what evidence backs each. This is why most manual evidence collection efforts collapse: the unit of work is the objective, not the control.

    Evidence types C3PAOs accept

    • Policy. The "what we do" document — signed, dated, version-controlled.
    • Procedure. The "how we do it" document — referenced from the policy, with named owners.
    • Configuration. A baseline export, group policy dump, IaC manifest, or system-generated configuration report.
    • Log / telemetry. SIEM output, EDR alerts, authentication logs, vulnerability scan results — operational proof the control is running.
    • Screenshot. Time-stamped UI capture for controls that cannot be exported as data (e.g., admin console settings).
    • Interview. Auditor interview with the named responsible party. Backed by documentation, not the only evidence.
    • Inherited evidence. Cloud provider or MSSP artifacts surfaced through your SRM.

    Mapping evidence to objectives

    A worked example for five common controls:

    • AC.L2-3.1.1 (account management): identity provider user export + JML procedure + recent provisioning ticket.
    • AU.L2-3.3.1 (audit logging): SIEM ingest configuration + 90-day log sample + log retention policy.
    • CM.L2-3.4.1 (baseline configuration): baseline document + IaC manifest + drift detection report.
    • IA.L2-3.5.3 (MFA): MFA enforcement policy + admin console screenshot + 30-day MFA challenge log.
    • SI.L2-3.14.1 (flaw remediation): patch policy + vulnerability scan output + closed remediation tickets.

    Each row is one objective, multiple evidence artifacts, mapped at ingest. The trail does not work if the mapping happens at export time.

    Freshness — why a 14-month-old screenshot fails

    C3PAOs expect evidence that proves the control is operating currently, not that it operated once. The accepted freshness window varies by evidence type: configuration baselines within 90 days, log samples covering the last 30–90 days, policies reviewed in the last 12 months, screenshots dated within 30 days of submission. A screenshot from a year ago is not evidence — it is a historical artifact. Athena's evidence freshness radar tags every artifact with its age and flags drift before the C3PAO sees it.

    How Athena automates this

    Athena ingests evidence from your stack — identity provider, EDR, SIEM, vulnerability scanner, configuration tools, document repositories — and auto-links it to the NIST 800-171A objectives it satisfies. Reviewers approve or reject each link. The SSP, POA&M, and assessor evidence bundle all generate from the same ledger, so the three artifacts tell the same story by assessment day. See the workflow automation pillar for the full pipeline.

    Frequently asked questions

    What is the difference between evidence and artifacts?

    Practically interchangeable in CMMC conversations. 'Artifact' tends to refer to the discrete file (a policy PDF, a log export). 'Evidence' refers to artifacts in the context of proving a specific objective. A single artifact can serve as evidence for multiple objectives.

    How fresh does CMMC evidence have to be?

    Depends on the evidence type. Configuration baselines and screenshots within 30–90 days; log samples covering the last 30–90 days; policies reviewed annually. The C3PAO judgment is whether the evidence proves the control operates today, not whether it operated once.

    Does a screenshot count as evidence?

    Yes, for controls that cannot be exported as data — admin console settings, UI configurations, dashboards. Screenshots must be time-stamped, dated within 30 days of submission, and supported by procedure documentation. They should not be the only evidence for a technical control.

    Can I reuse SOC 2 or ISO 27001 evidence for CMMC?

    Some, with caveats. SOC 2 and ISO controls overlap with NIST 800-171 in the 60–70% range. The mapping is not 1:1 — a SOC 2 control may satisfy two NIST objectives and miss a third. Reuse evidence where the underlying control is identical; supplement where it is not.

    What if I cannot produce evidence for a control?

    If the control is POA&M-eligible, document the gap in the POA&M with a closure plan and date. If it is not POA&M-eligible (some controls are not, per the final rule), you must close the gap before assessment. The C3PAO will not accept 'we are working on it' as evidence.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.