KB-032

Evidence guide: Access Control

Applies to
All plans
Last reviewed
October 1, 2026
Version
1.0

EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE

Requirements 1 through 4: who can use your systems, what they can do, outside systems, and public content

KB-032 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support

Access Control is about making sure only the right people use your systems, that they can only do what their job requires, that outside systems are kept under control, and that nothing private ends up somewhere public.

Who usually collects this

Your IT provider handles requirements 1 and 2 and the technical part of 3. The owner or office manager handles the written rules for requirements 3 and 4.

Requirement 1: Only authorized people and devices use your systems

What you are showing: every person has their own account, accounts are removed when people leave, and only company devices are used for company work.

  • A current list of user accounts, compared against your current employee list. In Microsoft 365, this is the Active users list in the Microsoft 365 admin center, which can be exported.
  • A list of company computers and devices. If you use Microsoft Intune, the All devices list in the Intune admin center works well. Otherwise, a simple spreadsheet with device name, user, and serial number is fine.
  • A short offboarding procedure or checklist showing accounts are disabled on an employee's last day, with one or two completed examples if you have them.

Requirement 2: People can only do what their job requires

What you are showing: administrator rights are limited to the few people who need them, and sensitive folders are limited to the right people.

  • A screenshot or export of who holds administrator roles. In Microsoft 365, see Roles and then Role assignments in the admin center.
  • A screenshot showing that everyday users are not local administrators on their computers, or a note from your IT provider confirming it.
  • Permission screenshots for one or two sensitive folders, such as accounting or contract files, showing access is limited.

Requirement 3: Control connections to outside systems

What you are showing: you know which outside systems are used for company work, such as personal devices, personal email, or personal cloud storage, and you control their use.

  • A short written rule, often part of an acceptable use policy, stating which systems may be used for company information and that personal email and personal cloud storage may not.
  • A list of approved outside services, such as Microsoft 365 and your accounting system.
  • Supporting settings if you have them, such as a screenshot showing automatic forwarding to outside email is blocked, or external sharing settings in SharePoint.

Requirement 4: Control what is posted publicly

What you are showing: a named person reviews anything posted publicly, such as your website or social media, so private information is not released.

  • A one paragraph procedure naming who approves public posts and website changes.
  • A list of the people who can publish to your website and social media accounts.
  • One example of a review, such as an approval email, if you have one.

Checklist

#EvidenceTypically fromCollected
1User account list compared to employee listIT provider☐
1Company device listIT provider☐
1Offboarding procedure or checklistOwner or office☐
2Administrator role assignmentsIT provider☐
2Users are not local administratorsIT provider☐
2Permissions on sensitive foldersIT provider☐
3Acceptable use rule for outside systemsOwner or office☐
3List of approved outside servicesOwner or office☐
4Public posting review procedureOwner or office☐
4List of who can publish publiclyOwner or office☐

Where to save it

Save everything from this guide in your own evidence folder under CMMC L1 Evidence / 1 Access Control, then record the location in AffirmReady for each requirement. AffirmReady does not store evidence files, so your evidence stays in systems your company controls.

Need help?

If you have questions about Access Control evidence, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.

For CMMC Level 1 readiness purposes only. Not legal advice. Your company is responsible for the accuracy of its self-assessment and affirmation.

Did the steps match what you see?

Microsoft and other software change their screens often. If something here looks different on your screen, let us know and we'll update this article.

Please don't include passwords or sensitive company information.
Cloudflare verification

Loading verification…