🕸️ Ada Research Browser

Evidence-Standards.md
← Back

Evidence Standards – Open CMMC

Purpose

This document defines the evidence standards used throughout the Open CMMC framework. It exists to eliminate ambiguity, reduce assessor interpretation, and ensure organizations collect sufficient and repeatable evidence for CMMC Level 2.

CMMC does not prescribe specific tools. However, assessors require clear proof that controls are implemented and operating.


Evidence Design Principles

All evidence must:


Evidence Types

Acceptable evidence types include:

Policies alone are never sufficient.


Screenshot Standards

All screenshots must show:

Redaction is permitted but must not obscure relevance.


Naming Convention

Recommended filename format: [ControlID]-[EvidenceType]-[System]-YYYY-MM-DD.ext

Example


Platform-Specific Evidence Examples

Open CMMC provides illustrative examples using common platforms such as:

These examples are not endorsements and do not exclude other valid solutions.


Evidence Anti-Patterns (Explicitly Not Acceptable)


Evidence Retention

Evidence should be retained in accordance with organizational policy and contractual requirements.

Evidence must be available for assessment upon request.


Assessor Perspective

Assessors evaluate evidence based on: - Sufficiency - Specificity - Traceability - Consistency with SSP narratives

This standard is designed to meet those expectations.