EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE
What evidence is, what good evidence looks like, and how to organize it
KB-031 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support
If you are getting ready for your CMMC Level 1 self-assessment and are not sure what "evidence" means or how much you need, this guide is the place to start. It explains what to collect, how to organize it, and how to divide the work between your team and your IT provider.
What evidence is
Evidence is the record that shows a safeguard is actually in place. It can be a screenshot of a setting, a short written policy, a log, a list, or a receipt. For each of the 15 CMMC Level 1 requirements, you want at least one piece of evidence that shows how your company meets it today.
Why it matters
For CMMC Level 1, your company completes an annual self-assessment and a senior official submits an annual affirmation in SPRS. You do not upload your evidence to SPRS. Evidence matters because it is what supports that affirmation.
- It gives your affirming official confidence. The person who signs the affirmation is making a formal statement to the government. Evidence lets them see, rather than assume, that each requirement is met.
- It makes reviews easy. If a prime contractor or the government asks how you meet a requirement, you can answer in minutes instead of scrambling.
- It makes next year faster. When it is time to reaffirm, you refresh your evidence rather than starting over.
The DoD's CMMC Level 1 assessment guidance describes three ways a requirement can be checked: examining documents, interviewing the people involved, and testing that a safeguard works. Good evidence prepares you for all three.
What good evidence looks like
| Good evidence is... | What that means in practice |
|---|---|
| Current | It reflects how things work today. Collect or refresh it within the 12 months before your affirmation. |
| Dated | The date is visible on it or in the file name. For screenshots, include the taskbar clock or a date in the file name. |
| Specific | It shows the actual setting or record, not just a statement that you do something. |
| Complete | It covers your whole company: every user, every computer, every office location that handles Federal Contract Information. |
| Safe | It never shows passwords, MFA codes, or other secrets. Crop or blur anything sensitive before saving. |
Common types of evidence
- Screenshots of system settings, such as multi-factor authentication or antivirus status.
- Exports and reports, such as a list of user accounts or devices.
- Short written policies or procedures. A single page in plain language is usually enough for a small business.
- Logs and records, such as a visitor sign-in log or a list of who has office keys.
- Receipts and certificates, such as a certificate of destruction from a shredding vendor.
Set up your evidence folder
Create one folder in a system your company already uses and controls, such as SharePoint, OneDrive, or a secure shared drive. Limit access to the people who need it. We recommend this structure, which matches the guides in this series:
| Folder | What goes in it | Guide |
|---|---|---|
| CMMC L1 Evidence / 1 Access Control | Requirements 1 through 4 | KB-032 |
| CMMC L1 Evidence / 2 Identification and Authentication | Requirements 5 and 6 | KB-033 |
| CMMC L1 Evidence / 3 Media Protection | Requirement 7 | KB-034 |
| CMMC L1 Evidence / 4 Physical Protection | Requirements 8 and 9 | KB-035 |
| CMMC L1 Evidence / 5 System and Communications Protection | Requirements 10 and 11 | KB-036 |
| CMMC L1 Evidence / 6 System and Information Integrity | Requirements 12 through 15 | KB-037 |
Name files with the date first so they sort in order, for example 2026-10 MFA policy screenshot.png or 2026-10 Visitor log Q3.pdf.
Who usually does what
In most small businesses, the work splits naturally between the office and the IT side:
| Area | Usually handled by |
|---|---|
| Physical Protection (office locks, visitors, keys) | Office manager or owner |
| Media Protection (disposing of old devices and records) | Office manager, with IT provider for wiping devices |
| Access Control policies (outside systems, public posting) | Owner or office manager |
| Technical settings (accounts, MFA, firewall, updates, antivirus) | IT provider or internal IT person |
If an IT provider manages your systems, send them the Evidence Request for Your IT Provider (KB-038). It lists exactly what to ask for, so you do not need to know the technical details yourself.
How AffirmReady fits in
As you collect each item, note what the evidence is and where it is saved. In AffirmReady, the evidence register tracks the location rather than the file, so your evidence never leaves your own systems.
A few important reminders
The examples in these guides are common ways small businesses meet each requirement. They are not the only acceptable approach.
Evidence supports your self-assessment. It does not by itself prove compliance. If evidence shows a gap, mark the requirement as not met in AffirmReady and fix the gap before your company affirms.
Never email evidence as attachments. Share it through your secure file system instead.
Need help?
If you are not sure where to begin, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.