EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE
Requirements 1 through 4: who can use your systems, what they can do, outside systems, and public content
KB-032 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support
Access Control is about making sure only the right people use your systems, that they can only do what their job requires, that outside systems are kept under control, and that nothing private ends up somewhere public.
Who usually collects this
Your IT provider handles requirements 1 and 2 and the technical part of 3. The owner or office manager handles the written rules for requirements 3 and 4.
Requirement 1: Only authorized people and devices use your systems
What you are showing: every person has their own account, accounts are removed when people leave, and only company devices are used for company work.
- A current list of user accounts, compared against your current employee list. In Microsoft 365, this is the Active users list in the Microsoft 365 admin center, which can be exported.
- A list of company computers and devices. If you use Microsoft Intune, the All devices list in the Intune admin center works well. Otherwise, a simple spreadsheet with device name, user, and serial number is fine.
- A short offboarding procedure or checklist showing accounts are disabled on an employee's last day, with one or two completed examples if you have them.
Requirement 2: People can only do what their job requires
What you are showing: administrator rights are limited to the few people who need them, and sensitive folders are limited to the right people.
- A screenshot or export of who holds administrator roles. In Microsoft 365, see Roles and then Role assignments in the admin center.
- A screenshot showing that everyday users are not local administrators on their computers, or a note from your IT provider confirming it.
- Permission screenshots for one or two sensitive folders, such as accounting or contract files, showing access is limited.
Requirement 3: Control connections to outside systems
What you are showing: you know which outside systems are used for company work, such as personal devices, personal email, or personal cloud storage, and you control their use.
- A short written rule, often part of an acceptable use policy, stating which systems may be used for company information and that personal email and personal cloud storage may not.
- A list of approved outside services, such as Microsoft 365 and your accounting system.
- Supporting settings if you have them, such as a screenshot showing automatic forwarding to outside email is blocked, or external sharing settings in SharePoint.
Requirement 4: Control what is posted publicly
What you are showing: a named person reviews anything posted publicly, such as your website or social media, so private information is not released.
- A one paragraph procedure naming who approves public posts and website changes.
- A list of the people who can publish to your website and social media accounts.
- One example of a review, such as an approval email, if you have one.
Checklist
| # | Evidence | Typically from | Collected |
|---|---|---|---|
| 1 | User account list compared to employee list | IT provider | ☐ |
| 1 | Company device list | IT provider | ☐ |
| 1 | Offboarding procedure or checklist | Owner or office | ☐ |
| 2 | Administrator role assignments | IT provider | ☐ |
| 2 | Users are not local administrators | IT provider | ☐ |
| 2 | Permissions on sensitive folders | IT provider | ☐ |
| 3 | Acceptable use rule for outside systems | Owner or office | ☐ |
| 3 | List of approved outside services | Owner or office | ☐ |
| 4 | Public posting review procedure | Owner or office | ☐ |
| 4 | List of who can publish publicly | Owner or office | ☐ |
Where to save it
Save everything from this guide in your own evidence folder under CMMC L1 Evidence / 1 Access Control, then record the location in AffirmReady for each requirement. AffirmReady does not store evidence files, so your evidence stays in systems your company controls.
Need help?
If you have questions about Access Control evidence, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.