BriefingAssessmentReviewed July 23, 2026

Briefings · Assessment

What evidence does CMMC Level 2 actually require?

CMMC Level 2 is assessed against the 110 requirements of NIST SP 800-171, broken down into 320 assessment objectives by NIST SP 800-171A. Every objective needs objective evidence, meaning documents to examine, people to interview, and systems to test, and each requirement is met only when all of its objectives are.

Evidence · at a glance

Artifacts and hash list retained6 years
Objectives320 · NIST SP 800-171A
Artifact classes4 carry the assessment
FreshnessLast 90 days · technical
ReviewedJuly 23, 2026

The short version

An assessor never grades intentions. Each of the 320 assessment objectives gets a verdict, met or not met, based on evidence that is adequate (it actually proves that objective) and sufficient (there is enough of it, across systems and across time). The system security plan is the anchor artifact: it is what everything else is checked against.

The mechanics

How evidence is judged

The 110 requirements sound manageable until you see how they are assessed. NIST SP 800-171A decomposes each requirement into determination statements, 320 assessment objectives in total, and an assessment works objective by objective, not requirement by requirement. "Limit system access to authorized users" is not one question; it is several, each needing its own proof.

Assessors collect that proof through three methods, and expect them to agree. Examine: policies, procedures, plans, configuration exports, records. Interview: the people who own and operate the control, to confirm the documents describe reality. Test: the system itself, demonstrating the control does what the paper says. A policy that interviews contradict, or a setting that exists nowhere in writing, is a finding either way.

Two words carry the standard. Evidence must be adequate, proving the specific objective and not something adjacent to it, and sufficient, covering the systems in scope and showing the control operating over time rather than posed for a screenshot. One artifact can honestly serve many objectives; a well-run access review touches identification, authorization, and account management at once. The discipline is the mapping, and the assessment team is not allowed to coach you toward better evidence mid-assessment. You arrive with the case you have.

The artifacts

What actually carries a Level 2 assessment

Four kinds of evidence do nearly all the work.

01

System security plan The anchor

The document the whole assessment is conducted against: your boundary, your assets, and how each of the 110 requirements is implemented in your environment. Without a current SSP there is nothing to assess, and its absence cannot be deferred to a plan of action.

02

Policies and procedures The rules

Written rules and the operational steps that carry them out: versioned, approved, dated, and assigned to named roles. Assessors read the revision history as evidence too: a document set created in one week tells its own story.

03

Technical exports The machine's word

Configuration baselines, policy-enforcement exports, scan results, screenshots of enforced settings, and for cryptography, the specific validated module and certificate numbers, since "encryption is on" and "FIPS-validated cryptography" are different claims.

04

Operating records The habit

Logs and their reviews, access recertifications, training rosters, incident-response exercises, visitor records, change approvals. These are the artifacts that cannot be produced retroactively, which is exactly why they are persuasive.

Custody

Freshness, hashing, and the six-year shelf

Freshness · last 90 days Assessment day SHA-256 hash at capture Six-year retention · artifacts + hash list Band: last 90 days · Point: SHA-256 at capture · Span: six years in your custody

Evidence has a shelf life in both directions. It must be fresh enough to describe the system as it runs, and in assessment practice the working yardstick for technical artifacts is roughly the last 90 days. It must also reach far enough back to show the control operating as a habit rather than a preparation. Centralized logging enabled the month before an assessment produces technically valid artifacts that persuade no one.

In a certification assessment, the artifact set does not travel with the assessors. The C3PAO records a cryptographic hash (SHA-256) of each artifact at the close of the assessment, and you retain the artifacts and the hash list for six years, so the integrity record proves later that the evidence reviewed is the evidence kept. Treating evidence as a managed, versioned collection from day one is dramatically cheaper than reconstructing one under deadline.

That is the design philosophy behind our program: in a 93-step implementation, every step names what it produces and where it files, so the evidence collection assembles as a byproduct of doing the work, not as a binder sprint the month before the assessor arrives.

Straight answers

Asked and answered

Q01

Is a written policy enough?

No. The three methods have to agree: the policy states the rule, interviews confirm people follow it, tests show the system enforces it. Paper without practice is a finding, and so is practice without paper.

Q02

How current must evidence be?

Current enough to describe the running system, with roughly the last 90 days as the working yardstick for technical artifacts, and with enough history behind it to show the control is operated, not staged.

Q03

Do interviews count as proof?

They corroborate. An assessor triangulates what people say against what documents state and what systems demonstrate, and a disagreement among the three is itself a finding.

Q04

Can gaps ride on a POA&M?

Barely. Conditional status needs a minimum score of 88 of 110, only one-point requirements can be deferred (with a single encryption exception), and the plan must close within 180 days. The details live in the readiness-gaps briefing.