Screenshots are everywhere in CMMC evidence packs, and they work when done correctly. The quality bar from my Assessment Preparation Master Guide is below.
What makes a screenshot acceptable
- Complete frame. Show the full screen, not a cropped window. Cropping can suggest content was hidden or selected.
- Date and time visible. Either in the operating system clock or in the application UI. The assessor must be able to verify when the screenshot was taken.
- System identifier visible. The system name, hostname, tenant name, or environment identifier must be in the screenshot. "Generic console showing MFA enabled" does not tell the assessor which system it belongs to.
- Setting name AND value for configuration evidence. A screenshot of a configuration page should show both the name of the setting and the value it is set to. "MFA is on" is less useful than "Conditional Access policy 'Require MFA for All Users' is Enabled, applied to all cloud apps."
- Recently captured. Screenshots and reports dated within 90 days of the assessment. Older screenshots imply the control may have changed since.
- Filename follows a consistent naming convention, such as
[Control-Number]_[Evidence-Type]_[Date].[ext]. This is a Wrightbrained best practice, not a regulatory requirement, but it makes the evidence pack far easier for the assessor to navigate.
When a screenshot is not enough
NIST SP 800-171A specifies Test as one of the methods for many assessment objectives. Test means exercising the mechanism under specified conditions, and screenshots do not satisfy Test. Examples:
- MFA at sign-in. The assessor will want to see an actual MFA challenge against a privileged account.
- Account deactivation. The assessor will want to see access attempted with a deactivated account and rejected.
- Audit log generation. The assessor will want to see an event generated, logged, and reviewed.
- Patch deployment. The assessor will want to see a patch pushed, applied, and confirmed.
For these objectives, live demonstration trumps screenshots. When an assessor asks for demonstration, do it from a live system rather than from a screenshot. Live demonstration dramatically improves the credibility of the evidence.
Multi-screenshot evidence patterns
For complex configurations, a single screenshot is often not enough:
- Conditional Access policy. One screenshot of the policy summary, one of the assignments, one of the conditions, one of the access controls.
- Firewall rule set. One screenshot of the rule list, one of the specific rule's source, destination, port, and action.
- EDR coverage. One screenshot of the deployed-agents count, one of policy assignment, one of a recent action taken.
Common errors
- Cropped screenshots. Crop only by trimming whitespace, never to hide content.
- Anonymized screenshots. Blanking out system names defeats correlation to the SSP.
- Stock product screenshots from vendor documentation. They do not reflect your environment and are not evidence.
- Edited screenshots. Modifying a screenshot in any way (hiding content, changing values, composite-editing) undermines the chain of custody and the credibility of the evidence.
Sources
Build screenshot evidence that holds at assessment.
The CMMC Compliance Engine includes the APREP-MASTER-01_Assessment_Preparation_Master_Guide (Section 2.3: Evidence Quality Rules) and the EVD-01_Evidence_Catalog for mapping each practice to the screenshot or live-demonstration evidence that supports it.
Get the CMMC Compliance Engine