Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
NIST 800-171 Control-by-Control Evidence Guide
When it comes to Cybersecurity Maturity Model Certification (CMMC) compliance, knowing what NIST 800-171security controls you need to implement is only half the battle. The other half is proving you’ve actually implemented them. Every one of the 110 security requirements in National Institute of Standards and Technology (NIST) Special Publication 800-171 requires evidence, and knowing what evidence to collect for each control can save you countless hours of frustration.
This guide walks through each of the 14 control families in NIST SP 800-171 and explains what types of evidence you should be collecting. Whether you’re just starting your compliance journey or preparing for a CMMC assessment, this control-by-control breakdown will help you build a complete and defensible evidence package.
How to Use This Guide
NIST SP 800-171 organizes its 110 security requirements into 14 families. Each family addresses a different aspect of cybersecurity, from access control to system integrity. For each family, this guide describes the types of evidence that demonstrate compliance with its requirements.
Keep in mind that evidence requirements can vary based on your specific environment and implementation choices. Use this guide as a starting point, then tailor your evidence collection to reflect how controls actually work in your organization.
Access Control (3.1) – 22 Requirements
The access control family is the largest in NIST SP 800-171, covering everything from user account management to remote access restrictions. Evidence for these controls typically includes both policy documentation and technical proof of implementation.
Key evidence to collect:
Access control policies that define who can access what systems and data. User account listings showing active accounts, their roles, and assigned permissions. Screenshots or exports from your identity management system demonstrating role-based access configurations. Evidence of account review processes, including documentation of periodic access reviews and any resulting changes.
For remote access requirements, collect Virtual Private Network (VPN) configuration documentation, multi-factor authentication setup evidence, and connection logs showing that remote sessions are properly secured. Wireless access controls require similar evidence—configuration screenshots from wireless controllers and documentation of encryption settings.
Session lock and termination settings need configuration evidence showing automatic lockout timeouts. Least privilege implementation requires documentation showing how you limit user permissions to only what’s needed for job functions.
NIST 800-171 Awareness and Training (3.2) – 3 Requirements
This family focuses on ensuring your workforce understands their security responsibilities. Evidence here is primarily operational records showing that training actually happens.
Key evidence to collect:
Security awareness training materials used in your program. Training completion records for all users, including dates and topics covered. Role-based training documentation for users with specialized security responsibilities, such as system administrators or incident responders.
Training records should show that new employees receive security training before accessing systems and that all personnel receive refresher training at defined intervals. If you use a third-party training platform, export completion reports that show individual names, completion dates, and course titles.
Audit and Accountability (3.3) – 9 Requirements
Audit controls ensure you’re tracking what happens in your systems and can identify who did what. Evidence for this family combines policy documents with technical configurations and actual audit records.
Key evidence to collect:
Audit policy defining what events your organization logs, how long logs are retained, and who reviews them. System configuration evidence showing that auditing is enabled on servers, workstations, network devices, and applications that process Controlled Unclassified Information (CUI).
Sample audit logs demonstrating that required events are actually being captured. Evidence of log review processes, such as review checklists or documented findings from periodic reviews. Log protection mechanisms, including access controls on log files and evidence of integrity monitoring.
Time synchronization configuration showing that all systems use a common time source ensures your logs can be correlated across systems. Audit storage capacity monitoring demonstrates you won’t lose logs due to full storage.
Configuration Management (3.4) – 9 Requirements
Configuration management controls ensure your systems are set up securely and stay that way. This family requires substantial technical documentation.
Key evidence to collect:
Baseline configurations for each type of system in your environment—servers, workstations, network devices, and mobile devices. These baselines should specify required security settings and prohibited configurations.
Change management policy and procedures explaining how configuration changes are requested, approved, tested, and implemented. Change request records showing that the process is actually followed. Evidence of configuration monitoring or scanning that identifies deviations from baselines.
Application whitelisting or software restriction evidence showing how you control what software can run on systems. Documentation of essential system functions and how you’ve restricted unnecessary capabilities, ports, protocols, and services.
Identification and Authentication (3.5) – 11 Requirements
These controls ensure that users and devices are properly identified before gaining access. Evidence combines policy with technical configuration proof.
Key evidence to collect:
Account management policy covering account creation, modification, and termination processes. Evidence showing unique account identifiers for each user—screenshots of user directories or account listings work well.
Multi-factor authentication configuration evidence for all network access, remote access, and privileged access. This is one of the most scrutinized requirements, so collect clear screenshots showing multi-factor authentication is required and cannot be bypassed.
Password policy configuration showing complexity requirements, expiration settings, and reuse restrictions. For systems using other authenticators like tokens or certificates, document how those authenticators are managed, protected, and refreshed.
Device identification and authentication evidence showing how network devices are authenticated before connecting to your network. This might include certificate-based authentication configurations or network access control settings.
Incident Response (3.6) – 3 Requirements
Incident response controls ensure you can detect, respond to, and recover from security incidents. Evidence here is primarily procedural but should include records of actual activities.
Key evidence to collect:
Incident response plan documenting your procedures for handling security incidents, including roles, responsibilities, communication protocols, and escalation procedures. The plan should address detection, analysis, containment, eradication, and recovery phases.
Evidence of incident response testing, such as tabletop exercise documentation, after-action reports, or drill records. Training records showing that incident response team members understand their roles.
If you’ve experienced actual incidents, sanitized incident documentation demonstrates your process works in practice. Incident tracking logs show how you document and manage incidents through resolution.
Maintenance (3.7) – 6 Requirements
Maintenance controls address how you service your systems while maintaining security. Evidence focuses on maintenance procedures and records.
Key evidence to collect:
Maintenance policy covering how maintenance is performed, who can perform it, and what approvals are required. Maintenance logs documenting when maintenance occurred, what was done, and who performed it.
For remote maintenance, evidence showing how remote maintenance sessions are authorized, monitored, and logged. Documentation of tools used for remote maintenance and how they’re controlled.
Procedures for sanitizing equipment before maintenance when the maintenance is performed by external parties or when equipment leaves your facility. Evidence that maintenance personnel are authorized and supervised appropriately.
Media Protection (3.8) – 9 Requirements
Media protection controls govern how you handle storage media containing CUI. Evidence addresses both digital and physical media handling.
Key evidence to collect:
Media protection policy defining how media is marked, stored, transported, and destroyed. Evidence of CUI marking on physical media such as labeled drives or disks.
Access controls limiting who can access media containing CUI. Secure storage documentation showing how media is physically protected—photos of locked cabinets or secure rooms may be appropriate.
Sanitization procedures explaining how media is cleared, purged, or destroyed before disposal or reuse. Sanitization records documenting when media was sanitized and what method was used. For destruction, certificates of destruction or documented destruction procedures with witness signatures.
Encryption evidence showing that CUI is protected on portable media. Transport procedures for moving media outside controlled areas.
Personnel Security (3.9) – 2 Requirements
Personnel security controls address the human element of your security program. Evidence focuses on screening and termination processes.
Key evidence to collect:
Personnel screening policy describing background check requirements for individuals accessing CUI. Evidence that screening occurs before granting access—this might include a log of completed background checks without revealing personal information.
Termination procedures ensuring access is revoked when employment ends. Evidence showing timely access revocation, such as account termination timestamps correlated with employment end dates. Documentation of exit procedures including return of equipment, badges, and other organizational assets.
Physical Protection (3.10) – 6 Requirements
Physical protection controls secure the physical environment where CUI is processed and stored. Evidence combines documentation with physical verification.
Key evidence to collect:
Physical security policy defining controlled areas and access requirements. Access authorization lists specifying who can enter controlled areas.
Physical access logs documenting entries to controlled areas. Access control mechanism documentation such as badge reader configurations, visitor sign-in procedures, or key management records.
Evidence of visitor controls including escort procedures, visitor badges, and visitor logs. Physical boundary protections such as photos of secured areas, fence lines, or locked doors—ensure photos don’t reveal sensitive security details.
Monitoring mechanisms like security camera documentation or guard schedules. For areas where CUI is displayed, evidence of screen positioning or other protections against unauthorized viewing.
Risk Assessment (3.11) – 3 Requirements
Risk assessment controls ensure you understand and manage risks to your organization. Evidence focuses on assessment processes and results.
Key evidence to collect:
Risk assessment policy describing your methodology, frequency, and scope. Completed risk assessment documentation showing identified threats, vulnerabilities, and resulting risks.
Vulnerability scanning reports demonstrating regular scanning of systems for weaknesses. Remediation tracking showing how identified vulnerabilities are addressed.
Risk assessment updates demonstrating that assessments are refreshed when significant changes occur or at defined intervals.
Security Assessment (3.12) – 4 Requirements
Security assessment controls address ongoing evaluation of your security program. Evidence demonstrates continuous monitoring and improvement.
Key evidence to collect:
Security assessment plan describing how you evaluate control effectiveness. Assessment results documenting findings from internal assessments or external evaluations.
Plan of Action and Milestones (POA&M) tracking identified deficiencies and remediation plans. POA&M updates showing progress toward closing gaps.
System security plan (SSP) describing your security control implementations. Evidence that the SSP is reviewed and updated regularly.
System and Communications Protection (3.13) – 16 Requirements
This family addresses network security and communications protection. Evidence is heavily technical, focusing on configurations and architecture.
Key evidence to collect:
Network architecture diagrams showing system boundaries, segmentation, and data flows. Boundary protection device configurations for firewalls, routers, and other network security appliances.
Encryption implementation evidence for data in transit, including Transport Layer Security (TLS) configurations and certificate documentation. For CUI at rest, encryption configurations on storage systems and endpoints.
Network segmentation documentation showing how CUI systems are separated from general-purpose systems. Domain Name System (DNS) filtering or web proxy configurations restricting external connections.
Session authenticity protections such as session token handling configurations. Evidence of denial-of-service protections and network monitoring capabilities.
System and Information Integrity (3.14) – 7 Requirements
The final family addresses system integrity and flaw remediation. Evidence combines operational records with technical configurations.
Key evidence to collect:
Vulnerability management policy and procedures. Patch management records showing that security updates are identified and applied timely. Evidence of prioritization—critical patches should be applied faster than routine updates.
Malware protection configurations demonstrating endpoint protection deployment and update settings. Malware scan logs or detection reports.
Security alert monitoring evidence showing how you receive and respond to threat intelligence and vendor security advisories. System monitoring configurations and alert records demonstrating detection capabilities.
Spam protection configurations for email systems. Input validation documentation for web applications processing CUI.
Practical Tips for Evidence Collection
Start collecting evidence now, not when an assessment approaches. Many controls require evidence of ongoing activities that can’t be recreated retroactively.
Automate evidence collection where possible. Security tools often generate reports that serve as excellent evidence, and automated collection ensures nothing is missed.
Date your evidence clearly. Assessors need to verify that evidence reflects current practice, not historical configurations.
Maintain evidence quality. Blurry screenshots, truncated logs, and undated documents create problems during assessments. Take the time to collect clean, complete evidence.
Map evidence to specific requirement numbers. When an assessor asks about requirement 3.5.3, you should be able to locate relevant evidence immediately.
Need Help With Your CMMC Compliance Journey?
Navigating CMMC requirements can feel overwhelming, especially when you’re trying to run your business at the same time. At Greypike, a veteran-owned company, we understand the challenges defense contractors face because we’ve been in your shoes. Whether you have questions about evidence requirements for specific controls, need guidance on meeting NIST SP 800-171 requirements, or want hands-on support getting your organization assessment-ready, we’re here to help. Reach out to the Greypike team—we’d be happy to talk through your situation and point you in the right direction.
Sources
- CMMC Program Final Rule – Department of Defense CMMC program requirements and assessment procedures
https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-A/part-170 - NIST Special Publication 800-171 Revision 2 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final - NIST Special Publication 800-171A – Assessing Security Requirements for Controlled Unclassified Information
https://csrc.nist.gov/publications/detail/sp/800-171a/final - CMMC Model Overview – Cybersecurity Maturity Model Certification official documentation
https://dodcio.defense.gov/CMMC/ - NIST Special Publication 800-53 Revision 5 – Security and Privacy Controls for Information Systems and Organizations
https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final - DFARS Clause 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting
https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting