CMMC LEVEL 2 · ASSESSMENT PREP

What Evidence Does a C3PAO Actually Ask For?

Certification isn't a quiz — it's an evidence exercise. Here's how assessors actually evaluate your controls, and what to have ready.

Assessment is about proof, not promises

A CMMC Level 2 assessment evaluates your implementation of the NIST SP 800-171 security requirements against their assessment objectives — the specific, testable sub-parts of each requirement defined in NIST SP 800-171A.

The assessor's job is to gather objective evidence for each objective. Not to take your word for it. Not to accept a policy document as proof the policy is followed. The bar is "show me," and every marked-met objective needs something behind it.

The three ways assessors gather evidence

NIST SP 800-171A defines three assessment methods. Most objectives are evaluated with some combination of them.

Examine

Reviewing artifacts — policies, your System Security Plan (SSP), configurations, logs, and records.

Interview

Talking to the people who operate the controls to confirm they're understood and followed.

Test

Observing a control actually working — watching a mechanism behave as intended.

For most controls, assessors want more than a document. They want to see the control operating and see the records it produces.

What "evidence" looks like, by control area

Access control

User and role configurations, plus access records that show who could do what and when.

Identification & authentication

MFA configuration and enforcement, account records, and evidence that authenticators are managed.

Audit & accountability

The audit logs themselves, proof they're protected from tampering, and records that show monitoring and review are happening.

Across all controls

Your SSP describing how each requirement is met — and the artifacts that back each statement up.

Where contractors get caught short

The Audit & Accountability area is a frequent gap, because it demands living evidence — logs that exist, are protected from tampering, are actually reviewed, and can be produced on demand.

A policy that says "we log and review" isn't enough if you can't show the logs and the review. This is where evidence packages fall apart most often on assessment week.

How to prepare an evidence package

  • Keep your SSP current and mapped to each requirement.
  • Collect artifacts per requirement, organized so you can find them fast.
  • For logging controls, be able to produce the actual audit records and show they're protected and reviewed.
  • Package evidence so an assessor can verify it independently.

How Attestor helps

For the audit logging and monitoring requirements, Attestor produces the living evidence assessors look for. It collects your security events inside your own enclave, maps each event to the NIST 800-171 / CMMC controls it supports, and generates cryptographically signed evidence bundles a C3PAO can verify independently.

It won't produce evidence for controls outside logging and monitoring — but for that area, it turns "we log and review" into something you can hand over.

See it on your own logs — start a free 14-day evaluation.

Start evaluation

Related reading: the CMMC audit logging guide · CMMC audit log retention.

Frequently asked questions

This guide is general education, not compliance or legal advice — confirm specifics with your C3PAO or RPO.

Turn "we log and review" into evidence you can hand over.