KB-031

Collecting evidence for CMMC Level 1: where to start

Applies to
All plans
Last reviewed
October 1, 2026
Version
1.0

EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE

What evidence is, what good evidence looks like, and how to organize it

KB-031 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support

If you are getting ready for your CMMC Level 1 self-assessment and are not sure what "evidence" means or how much you need, this guide is the place to start. It explains what to collect, how to organize it, and how to divide the work between your team and your IT provider.

What evidence is

Evidence is the record that shows a safeguard is actually in place. It can be a screenshot of a setting, a short written policy, a log, a list, or a receipt. For each of the 15 CMMC Level 1 requirements, you want at least one piece of evidence that shows how your company meets it today.

Why it matters

For CMMC Level 1, your company completes an annual self-assessment and a senior official submits an annual affirmation in SPRS. You do not upload your evidence to SPRS. Evidence matters because it is what supports that affirmation.

  • It gives your affirming official confidence. The person who signs the affirmation is making a formal statement to the government. Evidence lets them see, rather than assume, that each requirement is met.
  • It makes reviews easy. If a prime contractor or the government asks how you meet a requirement, you can answer in minutes instead of scrambling.
  • It makes next year faster. When it is time to reaffirm, you refresh your evidence rather than starting over.

The DoD's CMMC Level 1 assessment guidance describes three ways a requirement can be checked: examining documents, interviewing the people involved, and testing that a safeguard works. Good evidence prepares you for all three.

What good evidence looks like

Good evidence is...What that means in practice
CurrentIt reflects how things work today. Collect or refresh it within the 12 months before your affirmation.
DatedThe date is visible on it or in the file name. For screenshots, include the taskbar clock or a date in the file name.
SpecificIt shows the actual setting or record, not just a statement that you do something.
CompleteIt covers your whole company: every user, every computer, every office location that handles Federal Contract Information.
SafeIt never shows passwords, MFA codes, or other secrets. Crop or blur anything sensitive before saving.

Common types of evidence

  • Screenshots of system settings, such as multi-factor authentication or antivirus status.
  • Exports and reports, such as a list of user accounts or devices.
  • Short written policies or procedures. A single page in plain language is usually enough for a small business.
  • Logs and records, such as a visitor sign-in log or a list of who has office keys.
  • Receipts and certificates, such as a certificate of destruction from a shredding vendor.

Set up your evidence folder

Create one folder in a system your company already uses and controls, such as SharePoint, OneDrive, or a secure shared drive. Limit access to the people who need it. We recommend this structure, which matches the guides in this series:

FolderWhat goes in itGuide
CMMC L1 Evidence / 1 Access ControlRequirements 1 through 4KB-032
CMMC L1 Evidence / 2 Identification and AuthenticationRequirements 5 and 6KB-033
CMMC L1 Evidence / 3 Media ProtectionRequirement 7KB-034
CMMC L1 Evidence / 4 Physical ProtectionRequirements 8 and 9KB-035
CMMC L1 Evidence / 5 System and Communications ProtectionRequirements 10 and 11KB-036
CMMC L1 Evidence / 6 System and Information IntegrityRequirements 12 through 15KB-037

Name files with the date first so they sort in order, for example 2026-10 MFA policy screenshot.png or 2026-10 Visitor log Q3.pdf.

Who usually does what

In most small businesses, the work splits naturally between the office and the IT side:

AreaUsually handled by
Physical Protection (office locks, visitors, keys)Office manager or owner
Media Protection (disposing of old devices and records)Office manager, with IT provider for wiping devices
Access Control policies (outside systems, public posting)Owner or office manager
Technical settings (accounts, MFA, firewall, updates, antivirus)IT provider or internal IT person

If an IT provider manages your systems, send them the Evidence Request for Your IT Provider (KB-038). It lists exactly what to ask for, so you do not need to know the technical details yourself.

How AffirmReady fits in

As you collect each item, note what the evidence is and where it is saved. In AffirmReady, the evidence register tracks the location rather than the file, so your evidence never leaves your own systems.

A few important reminders

The examples in these guides are common ways small businesses meet each requirement. They are not the only acceptable approach.

Evidence supports your self-assessment. It does not by itself prove compliance. If evidence shows a gap, mark the requirement as not met in AffirmReady and fix the gap before your company affirms.

Never email evidence as attachments. Share it through your secure file system instead.

Need help?

If you are not sure where to begin, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.

For CMMC Level 1 readiness purposes only. Not legal advice. Your company is responsible for the accuracy of its self-assessment and affirmation.

Did the steps match what you see?

Microsoft and other software change their screens often. If something here looks different on your screen, let us know and we'll update this article.

Please don't include passwords or sensitive company information.
Cloudflare verification

Loading verification…