CMMC ANSWER ENGINE

How should I name and organize my CMMC evidence files?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Ask your C3PAO early how they prefer evidence named and organized. Different C3PAOs may ask for evidence in a certain structure, and you do not want to be renaming and re-organizing at the last minute. The structure below is the one I use on engagements. The way I like things organized may be different than other assessors, but in general I have found that assessors like things organized in pretty close to the same way, so this is a reasonable starting point if your C3PAO does not have a specific preference.

Build an evidence index, or ask the C3PAO for an evidence plan to populate. The index (sometimes called an evidence catalog or evidence plan) maps every NIST 800-171A assessment objective to the specific file that supports it. Some C3PAOs will provide a blank evidence plan you fill in; otherwise build one yourself. Either way, the index is what lets the assessor jump from an objective straight to the evidence without searching through folders, and it forces you to confirm coverage of every objective before the assessment begins.

Evidence organization is one of the few aspects of CMMC preparation that pays back in assessment time and assessor goodwill. The standard from my Assessment Preparation Master Guide is below.

The folder structure: an SSP folder plus 14 domain folders

/Evidence/SSP/
/Evidence/AC-Access-Control/
/Evidence/AT-Awareness-Training/
/Evidence/AU-Audit-Accountability/
/Evidence/CA-Security-Assessment/
/Evidence/CM-Configuration-Management/
/Evidence/IA-Identification-Authentication/
/Evidence/IR-Incident-Response/
/Evidence/MA-Maintenance/
/Evidence/MP-Media-Protection/
/Evidence/PE-Physical-Protection/
/Evidence/PS-Personnel-Security/
/Evidence/RA-Risk-Assessment/
/Evidence/SC-System-Communications/
/Evidence/SI-System-Integrity/

What goes in /Evidence/SSP/

The SSP folder holds the System Security Plan itself plus the high-level artifacts the assessor pulls up early in the engagement. These are the documents that describe the whole environment, not evidence for a single practice. Typical contents:

  • The System Security Plan (the current, signed version).
  • The network diagram of the CMMC Assessment Scope.
  • The data flow diagram for CUI.
  • The asset inventory (CUI Assets, Security Protection Assets, CRMAs, and Specialized Assets).
  • The hardware and software inventories.
  • The user inventory or account roster, if maintained separately.
  • ESP service descriptions and the Customer Responsibility Matrix (CRM) for each ESP.
  • Any FedRAMP packages and the Body of Evidence (BoE) for cloud services in scope.
  • The POA&M.

What goes in the 14 domain folders

Each domain folder holds the evidence supporting the practices in that NIST 800-171 family, named with the convention below.

File naming convention

Format: [Control-Number]_[Evidence-Type]_[Date].[ext]

Examples:

  • 3.1.1_User-Account-List_2024-11-01.xlsx
  • 3.3.1_Audit-Log-Screenshot_2024-11-15.png
  • 3.5.3_MFA-Config-Screenshot_2024-11-01.png

Why this format works for assessors

  • Control number first means the assessor sees the practice at a glance and the file sorts alphabetically by NIST control hierarchy.
  • Evidence type second distinguishes multiple evidence files for the same control (User-Account-List vs Privileged-User-Review vs Account-Termination-Log).
  • Date last (YYYY-MM-DD) sorts chronologically and makes freshness immediately visible.
  • Underscores between parts, hyphens within parts means filenames work cross-platform and stay parseable.

Why organization matters at assessment

If the assessor asks for evidence supporting a specific assessment objective, you should be able to navigate to it directly. Slow evidence retrieval:

  • Lengthens the assessment, increasing C3PAO time and cost.
  • Signals that the OSA is unorganized and unprepared.
  • Creates the impression that evidence is being curated on the fly, which prompts deeper assessor scrutiny.

Practical setup

  1. Create the 14 folders before evidence collection begins. Build the empty structure first.
  2. Add a top-level Evidence_Catalog.xlsx that maps every practice (and every assessment objective from NIST 800-171A) to the evidence files supporting it.
  3. Maintain a chain-of-custody log next to the catalog. Capture who produced each file and when.
  4. Before the assessment, verify every entry in the catalog points to a current file (within 90 days).
  5. Open the evidence folders before the assessor arrives. Anything not pre-staged is something you'll fumble to find.

Common errors

  • Domain-named folders without control-numbered files. Folders without standardized file naming forces the assessor to open and read each file to know what it covers.
  • Multiple files for the same evidence with no clear current version. If three screenshots of MFA config exist across three dates, the assessor can't tell which is authoritative.
  • Evidence catalog out of sync with the folders. The catalog must reflect the folder state at assessment time, not the planned state from six months ago.

Sources

  • Wrightbrained Security, CMMC Assessment Preparation Master Guide. Section 2.1: Evidence Folder Structure; Section 2.2: Evidence File Naming Convention. link
  • NIST SP 800-171 Rev 2, 14 NIST 800-171 domains. link
Rulebook version: Wrightbrained Assessment Preparation Master Guide; NIST SP 800-171 Rev 2

Use the evidence organization I use on assessments.

The CMMC Compliance Engine includes the EVD-01_Evidence_Catalog workbook plus the APREP-MASTER-01_Assessment_Preparation_Master_Guide, which together establish the 14-folder structure and file-naming convention.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.