EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE
A ready-to-send request listing the technical evidence needed for your CMMC Level 1 self-assessment
KB-038 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support
How to use this document
Fill in the fields below, then send this document to your IT provider or internal IT contact. It lists every technical item from the AffirmReady evidence guides, so you do not need to know the details yourself.
Ask them to deliver the evidence through your secure file system, such as a SharePoint or OneDrive folder you share with them, rather than as email attachments.
Company name: _______________________________
Requested by: _______________________________
IT provider or contact: _______________________________________
Date requested: ________________________________
Requested by date: ________________________________
Where to save evidence: _______________________________________
Request
We are preparing for our annual CMMC Level 1 self-assessment and affirmation in SPRS, which covers the 15 basic safeguarding requirements in FAR 52.204-21. We use AffirmReady to track our readiness. Please provide the items below. Where a screenshot is requested, please make sure the date is visible or included in the file name, and please do not include passwords, codes, or other secrets.
If something is not currently in place, please let us know rather than leaving it out. That helps us fix gaps before we affirm.
Accounts and access
| Req. | Please provide | Done |
|---|---|---|
| 1, 5 | Export of all user accounts, noting any shared, generic, or service accounts and their purpose | ☐ |
| 1, 5 | List of all company devices with name, user, and serial number | ☐ |
| 2 | List of users holding administrator roles in Microsoft 365 or other systems | ☐ |
| 2 | Confirmation that everyday users are not local administrators on their computers | ☐ |
| 2 | Permissions for sensitive folders such as accounting and contract files | ☐ |
| 3 | Settings that block automatic forwarding to outside email and limit external file sharing, if configured | ☐ |
Sign-in and authentication
| Req. | Please provide | Done |
|---|---|---|
| 6 | Screenshot of the setting that requires multi-factor authentication (Security defaults or Conditional Access) | ☐ |
| 6 | MFA registration report for all users | ☐ |
| 6 | Password requirements in effect | ☐ |
| 6 | Confirmation and date that default passwords were changed on the firewall, router, Wi-Fi, and printers | ☐ |
Devices and disposal
| Req. | Please provide | Done |
|---|---|---|
| 7 | Description of how devices are wiped before reuse or disposal, and records of any completed in the last 12 months | ☐ |
Network
| Req. | Please provide | Done |
|---|---|---|
| 10 | Office firewall status screenshot with model and firmware version | ☐ |
| 10 | Summary of firewall rules, or confirmation that inbound traffic is denied by default | ☐ |
| 10 | Confirmation the built-in firewall is on for all company computers | ☐ |
| 11 | Screenshot showing guest Wi-Fi is separated from the business network | ☐ |
| 11 | Simple network diagram or description | ☐ |
Updates and malware protection
| Req. | Please provide | Done |
|---|---|---|
| 12 | Patch or update status report for all company computers | ☐ |
| 12 | Update policy showing updates install automatically or on a schedule | ☐ |
| 12 | Confirmation that no unsupported operating systems are in use, or a replacement plan | ☐ |
| 13 | Antivirus or endpoint protection console report listing all protected devices | ☐ |
| 14 | Date of most recent protection update and the automatic update setting | ☐ |
| 15 | Real-time protection status and scheduled scan setting | ☐ |
| 15 | Email attachment scanning policy, if available | ☐ |
Thank you
Please contact the person listed above with any questions about this request. Thank you for helping us keep our company secure and ready.
Note for IT providers
AffirmReady is readiness software used by your client. It does not connect to or change any customer systems, and it does not store evidence files. Evidence stays in the client's own environment.