Home / Article
What Do Assessors Prefer: Screenshots or System Exports?
You are collecting proof for your CMMC assessment and wondering which format assessors trust.
Short answer: they accept screenshots, but they give more weight to exports from the live system.
How assessors judge your evidence
CMMC is the Cybersecurity Maturity Model Certification. Level 2 requirements come from NIST SP 800-171. NIST SP 800-171 is the federal checklist for protecting CUI. CUI is Controlled Unclassified Information. (32 CFR Part 170)
Assessors check each requirement with three methods: examine, interview, and test. NIST SP 800-171A is the assessment guide for CUI requirements. Examine means reviewing, inspecting, or analyzing what you hand them. Interview means asking your people questions about the control. Test means exercising the control and comparing actual behavior with expected behavior. (NIST SP 800-171A)
A screenshot only supports the examine method. The assessor can read it but cannot run it. A system export can support both examine and test. The assessor can read it and check it against the running system.
Why test beats examine on technical controls
Test is the stronger method for anything the system enforces. A firewall screenshot shows one moment in time. It cannot prove the rule still exists, and it can be edited. An export from the live firewall can be matched against what runs now.
The assessment guide lists "system configuration settings" as an examine object. For the same type of control, it lists the enforcement mechanism as the test object. Give the assessor both: the document and the live proof behind it. (NIST SP 800-171A)
When a screenshot is fine
Screenshots fit one-time events and signed documents. Examples: a signed policy, a training certificate, a completed access review. These record something that already happened. They cannot drift, so a picture of the record is enough.
When you need a system export
Use exports for anything that can change after you capture it. Examples: firewall rules, user access lists, multi-factor authentication (MFA) settings, and backup settings. Collect the export as close to assessment day as you can. Put the requirement number and the date in each file name. If the setting changed, collect a fresh export and keep the old one.
What to hand the assessor for each control
For each technical control, give one examine object and one test object. For access control, that means the access policy plus a current user list export. For least privilege, it means the policy plus the privileged account list from the system. The assessment guide names configuration settings and enforcement mechanisms as objects for this control. (NIST SP 800-171A)
For process controls like training, the examine object is enough. The training record plus a staff member who can explain it covers examine and interview.
What to do this week
Pick your five most technical controls. Pull a fresh system export for each one today. Put the requirement number and the date in each file name. Keep the older exports as a trail of past states. Write down who can explain each control to an assessor.
Sources
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- NIST SP 800-171A Rev. 3, Assessing Security Requirements for Controlled Unclassified Information: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171Ar3.pdf
- DoD CMMC Assessment Guide, Level 1, Version 2.13, September 2024: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL1.pdf
Next step
Your assessor wants proof they can test, not pictures they can only read. PolicyCortex reads live Azure configuration with 33 collectors. That evidence becomes your System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M). See how it works.