Home / Article

What Counts as Evidence for CMMC Level 2?

September 27, 2026 · cmmc, evidence, level-2

CMMC Level 2 assesses 110 practices drawn from NIST SP 800-171 Revision 2 (32 CFR Part 170). Each practice needs proof that you follow it in daily work. That proof is what assessors call evidence.

Assessors gather evidence with three methods from NIST SP 800-171A Revision 2 (assessment procedures). The methods are Examine, Interview, and Test. Each requirement lists the methods that apply and the objects the assessor may check.

Who checks the evidence?

A CMMC Third-Party Assessment Organization (C3PAO) runs third-party Level 2 assessments (32 CFR Part 170). The assessor samples your evidence across the three methods above.

What does the Examine method cover?

Examine means reading your documents and records. The assessor reviews policies, procedures, plans, logs, and settings to obtain evidence.

For access enforcement, the assessor may examine the access control policy, the system security plan, and approved authorization lists. System audit logs and configuration settings are also on the list (SP 800-171A). For separation of duties, the list adds system access authorizations and audit records.

What to prepare: store the policy, the plan, and the current settings in one place. Name each file with the requirement number it supports. Dated exports beat undated ones every time.

What does the Interview method cover?

Interview means talking with your people. The assessor discusses the control with staff to obtain evidence.

For access enforcement, interviews may include staff with access enforcement duties, system administrators, and network administrators (SP 800-171A). For maintenance, they may include staff with maintenance duties and staff who sanitize media.

What to prepare: assign one owner to each control. Make sure owners can explain the process in plain words. Short honest answers beat long rehearsed ones.

What does the Test method cover?

Test means exercising the control to see if it works. The assessor runs a control under set conditions and compares actual behavior with expected behavior (SP 800-171A).

For access enforcement, the test may target the mechanisms that enforce the access policy. For separation of duties, it may target the mechanisms that enforce the separation policy. For maintenance, it may cover the processes that sanitize system components.

What to prepare: test each control yourself first. Try the blocked login and confirm the alert fires. Fix what fails and record the retest date.

Are screenshots good enough?

Screenshots are the weakest form of evidence. A screenshot captures one moment and can go stale the next day.

Screenshots suit one-time events like a completed training certificate or a signed policy. They are weak for live settings like firewall rules or access lists. System-generated exports and logs carry more weight because the system produced them directly.

How much evidence is enough?

Plan on at least one item per practice, and often one per method. Many practices need a document (Examine), an owner who can explain it (Interview), and a live check (Test).

Coverage matters more than volume. If a practice spans many systems, show evidence from each one. Organize every file by requirement number so the assessor can trace each item in minutes.

How fresh should evidence be?

Refresh evidence on a schedule, not only before the audit. Update proof after big changes like new servers, new staff, or changed firewall rules.

Keep old logs instead of deleting them. A history across months shows the control runs as a habit. Fresh dated evidence shortens the assessment because the assessor stops asking for newer proof.

For Azure shops, PolicyCortex reads this proof from live configuration with 33 collectors.

Sources

Next step

Your assessor will ask for proof, not promises. See how PolicyCortex reads that proof straight from your live Azure settings.