EVIDENCE COLLECTION GUIDE • COLLECTING EVIDENCE
Requirements 5 and 6: knowing who is on your systems and verifying identity before access
KB-033 | Applies to: All plans | Last reviewed: October 1, 2026 | Maintained by AffirmReady Support
Identification and Authentication is about making sure every user and device can be identified, and that people prove who they are before getting in. For most small businesses, this is where multi-factor authentication evidence lives.
Who usually collects this
Your IT provider, for nearly everything in this guide.
Requirement 5: Know who and what is on your systems
What you are showing: each person has their own named account, there are no shared logins, and devices are identifiable.
- The user account list from the Access Control guide, reviewed for shared or generic accounts. If a shared mailbox exists, show that no one signs in to it directly.
- The company device list, with each device named or tagged so it can be identified.
- A short note confirming shared logins are not used, or listing any service accounts and what they are for.
Requirement 6: Verify identity before granting access
What you are showing: people must sign in with strong credentials, ideally with multi-factor authentication, and default passwords on devices have been changed.
- A screenshot showing how multi-factor authentication is required. In Microsoft 365, this is either Security defaults turned on, or the Conditional Access policy that requires it, both in the Microsoft Entra admin center.
- A report showing which users have registered for multi-factor authentication. In the Entra admin center, the Authentication methods area includes a user registration report.
- Your password requirements, either as a screenshot of the setting or a one paragraph written standard.
- A short record showing default passwords on network equipment, such as the firewall, router, Wi-Fi, and printers, were changed, with the date. Never record the passwords themselves.
If your IT provider manages Microsoft 365,
AffirmReady never connects to your Microsoft 365 account. If your IT provider manages these settings, KB-038 gives you a ready-to-send request for the evidence.
Checklist
| # | Evidence | Typically from | Collected |
|---|---|---|---|
| 5 | User list reviewed for shared accounts | IT provider | ☐ |
| 5 | Named or tagged device list | IT provider | ☐ |
| 5 | Note on shared or service accounts | IT provider | ☐ |
| 6 | MFA requirement setting | IT provider | ☐ |
| 6 | MFA registration report | IT provider | ☐ |
| 6 | Password requirements | IT provider | ☐ |
| 6 | Default passwords changed record | IT provider | ☐ |
Where to save it
Save everything from this guide in your own evidence folder under CMMC L1 Evidence / 2 Identification and Authentication, then record the location in AffirmReady for each requirement. AffirmReady does not store evidence files, so your evidence stays in systems your company controls.
Need help?
If you have questions about sign-in or MFA evidence, Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and typically responds within one business day.