CMMC ANSWER ENGINE

How fresh does my evidence need to be for a CMMC assessment?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-16
Quick answer. Ask your C3PAO what they consider current before you spend weeks collecting evidence. Different C3PAOs may have different norms, and you do not want to find out at kickoff that you have to redo it all. The 90-day window is a defensible default. Neither NIST SP 800-171A nor 32 CFR Part 170 sets a specific freshness window; the assessor evaluates whether the control is currently operating.

Freshness is judgment-based, not regulation-based. Neither NIST SP 800-171A nor the CMMC Final Rule prescribes a specific number of days. What the assessor evaluates is whether each assessment objective is currently MET, which requires evidence that shows the control operating now.

Ask your C3PAO what they expect, early

Before you spend weeks screenshotting your environment, ask the C3PAO that will be doing your assessment what they consider current. The 90-day window below is the default I use, and it is defensible, but different C3PAOs may have different norms for screenshot freshness, log-review cadence, and the age of artifacts they will accept. Finding out at the kickoff that you have to redo your entire evidence pack is expensive. Ask early, get the C3PAO's expectations in writing if you can, and collect evidence at the cadence they expect. The point is to do the work once.

The 90-day practical bar

Per the Wrightbrained Assessment Preparation Master Guide, screenshots and reports should be dated within 90 days of the assessment. The reasons:

  • It matches the rhythm at which most contractors run vulnerability scans, review user access, refresh training, and rotate audit log reviews.
  • It is recent enough that the assessor can credibly conclude the control is currently operating.
  • It leaves enough slack that you do not have to re-capture every screenshot the day before the assessment.

What needs to be from the most recent cycle

  • Anything an assessor will demonstrate live during the assessment. Live demonstration trumps screenshots regardless of freshness.
  • Recurring control activities. Vulnerability scans, audit log reviews, patch compliance reports. Use the most recent cycle's evidence at whatever cadence your SSP defines.

What is allowed to follow a longer natural cadence

  • Annual training rosters. If the practice is annual, the most-recent annual cycle's record is correct, even if it is 10 months old.
  • Annual access reviews. Same rationale as training.
  • Policy documents and procedures. Policies establish the design of the control; what matters is that they are current and approved, not that they were recently updated.
  • Network diagrams. Current accuracy matters more than recent date. A 9-month-old diagram that still matches the environment is fine; a 30-day-old diagram that is already out of date is a finding.

How to actually manage freshness

  1. Tie evidence collection to the cadence each practice already runs on. The SSP should describe that cadence, and the evidence collection should match.
  2. Use automation where possible, such as scripted reports timestamped and console exports scheduled.
  3. Refresh the entire evidence pack 60 to 30 days before the assessment as part of pre-assessment activities (per the APREP timeline).
  4. For demonstrably live controls, plan to show the assessor the control operating rather than relying on a screenshot at all.

Common errors

  • Screenshots from initial implementation. A six-month-old screenshot from when the control was first set up does not demonstrate that the control still works.
  • Annual evidence dated more than 12 months ago. If the cycle is annual, the most-recent cycle must be within the last 12 months. A 13-month-old roster is a finding.
  • Audit log evidence pulled at assessment time but no review history. The freshness of the pull is not the issue; the assessor wants to see the review cadence operating, which means historical review records.
  • Collecting all the evidence before asking the C3PAO what they expect. If their norm differs from yours, you redo the work. Ask first.

Sources

  • Wrightbrained Security, CMMC Assessment Preparation Master Guide. Section 2.3: Evidence Quality Rules; Section 1.3: Assessment Timeline. link
  • NIST SP 800-171A, Assessment methods. link
Rulebook version: NIST SP 800-171A; CMMC 2.0 Final Rule

Build an evidence pack that ages well.

The CMMC Compliance Engine includes the APREP-MASTER-01_Assessment_Preparation_Master_Guide (Section 2.3: Evidence Quality Rules; Section 1.3: Assessment Timeline) and the EVD-01_Evidence_Catalog for mapping each practice to the evidence that supports it and the cadence at which it is captured.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.