What Evidence Does a CMMC Assessor Actually Ask For?
Assessors do not assess requirements. They assess assessment objectives, and there are 320 of them behind the 110 requirements. Each one is a determination statement that has to be met by something you can show.
So "what evidence do I need" has a precise answer, and it is per objective rather than per requirement.
What counts as evidence?
Assessment uses three methods: examine a document or artifact, interview the people who do the work, and test the mechanism. Most of what a small program can prepare in advance is the examine half: a named artifact, in a known place, that someone owns.
Evidence is not a screenshot folder. A usable evidence item has four properties: it is named, it has a system of record, it has an owner, and it has a refresh interval. Miss the last one and you have a snapshot rather than a control.
What does that look like for one requirement?
AC.L2-3.1.1 is a single line of regulation. It decomposes into six assessment objectives, and each one needs its own artifact:
| Obj | What must be determined | Artifact that shows it | Refresh |
|---|---|---|---|
| [a] | authorized users are identified. | Authorized user register Evidence/AC/3.1.1-a/ | monthly |
| [b] | processes acting on behalf of authorized users are identified. | Service and automation account register Evidence/AC/3.1.1-b/ | quarterly |
| [c] | devices (including other systems) authorized to connect to the system are identified. | Asset inventory export Evidence/AC/3.1.1-c/ | monthly |
| [d] | system access is limited to authorized users. | Directory group membership export Evidence/AC/3.1.1-d/ | monthly |
| [e] | system access is limited to processes acting on behalf of authorized users. | Service account permission report Evidence/AC/3.1.1-e/ | quarterly |
| [f] | system access is limited to authorized devices (including other systems). | Device enrollment and compliance report Evidence/AC/3.1.1-f/ | monthly |
One requirement. Six artifacts. Four different refresh intervals. Multiply that across 110 requirements and the reason evidence collapses in small programs stops being mysterious.
Why does evidence need a cadence at all?
Because the objective is usually written in the present tense. "System access is limited to authorized users" is a claim about now, not about the day you exported the list. An export from fourteen months ago does not show that the statement is true today, and an assessor reads dates.
This is where evidence and continuous monitoring stop being two topics. The refresh interval on an evidence item is your monitoring cadence for that objective.
What makes evidence fail an assessment?
- It proves the wrong statement. A policy that says accounts are reviewed does not satisfy an objective requiring that access is limited. Intent is not implementation.
- It is undated or unowned. An artifact nobody owns is an artifact nobody refreshed.
- It exists once. An assessor asks for the last three months, not the last one.
- It contradicts the SSP. The fastest way to lose an assessment is a document that says one thing and a record that shows another.
- It is a screenshot with no source. An assessor cannot re-derive it, so it proves nothing beyond that a screenshot exists.
How do you build the map?
- Work from the 320 objectives, not the 110 requirements. The requirements are too coarse to plan evidence against.
- For each objective, name one artifact and where it lives. A consistent path scheme costs nothing and saves the assessment.
- Assign an owning role, not a person.
- Set the refresh interval at the same moment. That single field is what turns a document set into a monitoring program.
Objective wording is from NIST SP 800-171A. The artifacts and intervals shown are one worked example of how a Level 2 program can be structured, not a required answer. This is not legal advice, not an assessment finding, and not a substitute for a C3PAO.
This page shows the pattern for one requirement. The CMMC Operator SSP template carries it as a worked register for the whole Access Control family: all 70 assessment objectives, each with a named artifact, a storage path, an owning role and a refresh interval, ready to extend across the remaining families.
See what is in the suiteMac-first, one-time purchase, no subscription.
- Why evidence needs a cadence the refresh interval on an evidence item is your monitoring cadence.
- How much evidence each asset generates a CUI Asset and a risk-managed asset do not carry the same load.
- All 110 requirements with SPRS point values and where each is settled on a Mac fleet.