Home / Article

Doing CMMC Evidence by Hand vs Collecting It Automatically

September 28, 2026 · cmmc, evidence, automation

CMMC Level 2 needs proof for 110 practices from NIST SP 800-171 Revision 2 (32 CFR Part 170). How you gather that proof is your choice. This article compares the two common paths.

What does manual collection look like?

You log in to each system and take screenshots. You save them to a shared drive with names you can find later.

You track everything in a spreadsheet with control names and file links. You chase teammates for missing items. You repeat the whole hunt before each assessment.

Manual work starts cheap. It needs no new tools and no setup time. Small teams with few systems often begin here.

Where does manual work break down?

Screenshots go stale the day after you take them. A firewall rule can change with no one updating the file. The assessor will ask for fresh proof anyway.

Spreadsheets break under hand edits. Links rot, names drift, and rows vanish. By audit week no one trusts the sheet.

The work restarts from zero each cycle. Last year files rarely match this year systems. When staff leave, the knowledge of where proof lives leaves with them.

Time is the quiet cost. A midsize Azure setup can eat hundreds of hours of screenshot duty. That is engineering time spent on copy and paste.

What does automated collection do differently?

Automated collection reads settings straight from your cloud tenant. It pulls the same proof the same way every time. Nothing depends on who took the screenshot.

It maps each finding to the right control. The usual targets are NIST 800-53 and NIST 800-171. It reruns on a schedule, so drift shows up in days instead of months.

After you fix a problem, it checks the control again. It also builds the documents assessors ask for. The System Security Plan (SSP) describes your controls. The Security Assessment Report (SAR) records the test results. The Plan of Action and Milestones (POA&M) tracks open fixes.

Assessors examine documents, interview staff, and test controls, so the tool should feed all three methods (SP 800-171A).

How do the two compare side by side?

Manual wins on day one cost. Automated wins on every day after that. For cloud setups the crossover comes fast.

Manual evidence is a photo of the past. Automated evidence is a feed of the present. Assessors prefer the present.

Manual scales with people. Automated scales with systems. Cloud systems grow faster than teams do.

What are the limits of automation?

Automation only sees what its collectors can reach. On-prem servers, paper records, and hallway conversations stay out of reach. Plan manual collection for those from the start.

A tool is only as good as its control mapping. If a finding maps to the wrong requirement, the assessor will not trust it. Review the mapping before you rely on it.

Automation does not replace judgment. It gathers proof faster, but your team still decides what the proof means. Keep a human in the loop for every assessment.

When does manual work still make sense?

Manual fits one-time records. Training certificates and meeting notes need no automation. Some evidence only exists on paper.

Manual also fits tiny scopes. With five systems, screenshots may do the job. Past that point the math turns ugly.

Many teams mix the two. They automate cloud settings and hand-collect the rest. That split plays to each method's strength.

How do teams usually make the switch?

They start with the cloud tenant, where most evidence lives. They connect a read-only collector and let it pull settings on a schedule. They map the findings to controls once, then reuse the mapping every cycle.

They keep manual collection for paper evidence. Training records, signed policies, and meeting notes stay hand-gathered. The split keeps each method doing what it does best.

They assign one owner to review the automated findings. Automation collects the proof, but a human still reads it. The owner spots gaps, assigns fixes, and confirms the re-check.

PolicyCortex automates the Azure side: 33 collectors read live configuration and re-check controls after fixes. It checks settings against NIST 800-53 and 800-171 and builds SSP, SAR, and POA&M documents.

Sources

Next step

Still pasting screenshots before every audit? See how PolicyCortex collects the same proof from your Azure tenant automatically.