Interactive guide to understanding evidence types, documentation requirements, and assessment methods for DoD CMMC program audits. Click on any evidence type to learn more about its importance and usage.
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (specifications, mechanisms, activities). Used to review documents, policies, configurations, and artifacts that demonstrate compliance.
Conducting discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. Interviews must be with personnel who implement, perform, or support the practices.
The process of exercising assessment objects under specified conditions to compare actual with expected behavior. Includes live demonstrations, penetration tests, and system validations.
Policies, procedures, standards, and governance documents
Firewall configs, penetration tests, and system validations
Audit logs, error reports, and continuous monitoring evidence
Interview summaries, training records, and personnel documentation
User management, authentication, and authorization documentation
Physical access controls, environmental protections, and facility security