CMMC ANSWER ENGINE

What evidence do CMMC assessors actually look for?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Per NIST SP 800-171A, an assessor uses three methods to determine whether each assessment objective for each practice is MET or NOT MET. The methods and the evidence that supports them are summarized below.

The three NIST SP 800-171A assessment methods

MethodWhat it isTypical evidence
ExamineReviewing, inspecting, observing, studying, or analyzing assessment objectsPolicies, procedures, SSP sections, network diagrams, configuration screenshots, audit logs, training records, access review reports, vulnerability scan reports, baseline configurations
InterviewHolding discussions with individuals or groups to obtain understanding, clarification, or evidenceConversations with the CISO, system administrators, security analysts, end users, HR, and facilities staff, structured around the practice the assessor is evaluating
TestExercising assessment objects under specified conditions to compare actual versus expected behaviorLive demonstration of MFA enrollment, attempted access to a CUI system from an unauthorized account, observed patch deployment, observed audit log generation, observed sanitization of media

What "objective" means in this context

NIST SP 800-171A breaks each of the 110 practices into discrete assessment objectives, the specific things the assessor must determine. Each objective has potential methods (some combination of Examine, Interview, Test) and potential objects (specific items to examine, individuals to interview, or mechanisms to test). The assessor's determination of MET for a practice requires that every assessment objective for that practice be supported.

Example: IA.L2-3.5.3 (MFA) and its assessment objectives

Practice 3.5.3 (Multi-Factor Authentication) breaks into three assessment objectives in NIST SP 800-171A:

  • 3.5.3[a] multifactor authentication is implemented for local access to privileged accounts.
  • 3.5.3[b] multifactor authentication is implemented for network access to privileged accounts.
  • 3.5.3[c] multifactor authentication is implemented for network access to non-privileged accounts.

If [a] and [b] are MET but [c] is NOT MET, the entire practice 3.5.3 is NOT MET, even though two of the three objectives were satisfied. Every assessment objective for a practice must be MET for the practice to be MET. This is why writing the SSP and organizing evidence at the assessment-objective level matters: a gap in one objective fails the whole practice.

Assessor discretion: adequate and sufficient evidence

NIST SP 800-171A lists "Potential Assessment Methods and Objects" for each objective. The word potential matters. The assessor exercises discretion within those potential methods to determine whether the evidence presented is adequate and sufficient to support a determination of MET for each assessment objective.

  • Adequate evidence directly supports the specific assessment objective being evaluated. Evidence that is tangentially related, or that supports a different objective than the one being assessed, does not count toward that objective.
  • Sufficient evidence is enough evidence to support the determination. A single screenshot of one user's MFA enrollment does not show that MFA is enforced for all privileged accounts; the assessor needs broader evidence such as a configuration export or a sample across multiple accounts.

The practical consequence: the assessor may ask for additional artifacts beyond what the OSA initially presented, or may exercise more than one of the potential methods (Examine plus Test, for example) when one method alone is not enough to support the determination. The assessor's question is always whether the evidence as a whole supports the objective, not whether a checkbox was ticked. Be ready to produce additional evidence on request.

What evidence looks like in practice

Examine is documents and artifacts. The typical artifacts are SSP entries, policies and procedures, audit log excerpts, configuration screenshots and exports, training records, access review reports, vulnerability scan reports, and baseline configurations.

Interview requires the right people in the room. Make sure the person responsible for the practice or assessment objective is in the room when the interview happens. This is not the time to run down the hall and get somebody. Identify the responsible role for every practice and every objective during pre-assessment prep, and confirm those people are available during assessment week.

Test is usually a screenshare, and may also be done on-site. The assessor watches you exercise the control on the live system to confirm that what is in the SSP is how things really work at the location. Test is how the assessor verifies that the documented procedure matches operating reality.

Each piece of evidence should map clearly to a specific assessment objective in NIST 800-171A.

Prepare for the assessor to ask to see things during a screenshare

The assessor will often ask to see a specific configuration, dashboard, log view, or report during a Test screenshare. A practical tip: build yourself a short guide to how to get to each configuration, dashboard, and report you might need to demonstrate. Capture the click paths, menu locations, URLs, and which account to log in with. Fumbling around to find a setting under time pressure does not make a good impression and lengthens the assessment.

The practical bar for evidence (Wrightbrained guidance)

From my Assessment Preparation Master Guide, evidence that holds up under assessment must be:

  • Current. Screenshots and reports dated within 90 days of the assessment.
  • Complete. Show the full screen with date and time visible.
  • System-identifiable. The system name or identifier must be visible so the assessor can correlate the evidence to your SSP.
  • Contextual for logs. Raw logs alone are insufficient; show who reviewed them and when.
  • Setting-and-value for configurations. Configuration screenshots should show the setting name and its value.
  • Unaltered. The system output or screenshot you produce is the evidence. Do not edit, crop to hide content, or otherwise modify what the system produced.
  • Quickly retrievable. Evidence the assessor cannot locate quickly lengthens the assessment and signals weaker evidence management.

Common failures

  • Evidence that proves design but not operation. A policy without supporting records is half an answer.
  • Stale evidence. A screenshot from six months ago does not show that the control is operating now.
  • Anonymized screenshots. If the assessor cannot tell which system the screenshot is from, the evidence is not credible.
  • Single-method evidence on a multi-method objective. If NIST 800-171A specifies Examine AND Test for an objective, providing only Examine evidence is insufficient.

Sources

  • NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. Assessment methods and objectives. link
  • Wrightbrained Security, CMMC Assessment Preparation Master Guide. Section 2: Evidence Organization; Section 1.2: Evidence Types. link
  • CMMC Assessment Process (CAP) v2.0. link
Rulebook version: NIST SP 800-171A; CMMC 2.0 Final Rule (32 CFR 170); CAP v2.0

Use the Evidence Catalog I built for assessment prep.

The CMMC Compliance Engine includes the EVD-01_Evidence_Catalog workbook, mapping every practice to the documents, records, mechanisms, and people the assessor will examine.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.