Home / Article

How Often Should We Refresh Our CMMC Evidence?

September 30, 2026 · cmmc, evidence, nist-800-171, dfars

Your CMMC evidence was solid in January, but your cloud settings have changed since then.

What the rules actually require

Start with CMMC itself. CMMC is the Cybersecurity Maturity Model Certification. The program rule is 32 CFR Part 170. It ties CMMC Level 2 to the NIST SP 800-171 security requirements. NIST SP 800-171 is the federal checklist for protecting CUI. CUI is Controlled Unclassified Information. (32 CFR Part 170)

The rule does not set a refresh calendar for each evidence type. What it does set is currency for your assessment. DFARS 252.204-7019 requires a current assessment to be considered for award. Current means not more than 3 years old, unless the solicitation says less. You verify this by posting summary scores in SPRS. SPRS is the Supplier Performance Risk System. (DFARS 252.204-7019)

Then there is how assessors work. NIST SP 800-171A is the assessment guide for CUI requirements. It tells assessors to use three methods: examine, interview, and test. Potential objects include system configuration settings and audit logs. The test method compares actual behavior with expected behavior. Stale screenshots fail that comparison. Only evidence that matches the live system passes. (CMMC Assessment Guide, Level 1)

A refresh schedule by evidence type

The rules above do not name a calendar. This schedule fills the gap. It is practical guidance, not a regulation. Treat it as the minimum that keeps you assessment ready.

Continuous monitoring data covers vulnerability scans, audit logs, and access reviews. Collect these continuously, or at least monthly. A gap of months reads as an unmonitored control.

Point-in-time configurations include firewall rules, encryption settings, and access control settings. Refresh these at least quarterly. Refresh them again right after any change.

Annual artifacts include policies, training records, and the incident response plan. Review policies each year. Record training when it happens and keep yearly proof on file.

Your SPRS score is the DFARS assessment score. Refresh it before it turns 3 years old. An expired score can block an award. (DFARS 252.204-7019)

The Phase 2 pause changed none of this

In July 2026, DoD suspended CMMC Phase 2. Phase 2 would have expanded third-party certification as a condition of award. The suspension pauses the audit expansion. It does not pause the rules. (CMMC Level 2 requirements status)

DFARS 252.204-7012 still requires you to safeguard covered defense information with NIST SP 800-171. The 7019 and 7020 assessment and SPRS duties remain in the current clause text. Letting evidence go stale during the pause is the fastest way to fail the next self-assessment. (DFARS 252.204-7012)

Your prime can still demand proof. Primes flow these clauses down to subcontractors. A stale evidence folder is your problem at the next bid, pause or no pause.

What to do this week

Pull one fresh export of your cloud configuration. Compare it with your last evidence set. Note every difference.

List every artifact older than 90 days. Give each one an owner and a refresh date.

Check your SPRS score date. Set a reminder 6 months before it turns 3 years old.

Schedule one monthly collection run. Put it on someone's calendar, not in a chat message.

Sources

  • 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
  • DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements: https://www.acquisition.gov/dfars/252.204-7019-notice-nist-sp-800-171-dod-assessment-requirements.?searchTerms=DFARS+Provision+252.204-7019%3A+Notice+of+NIST+SP+800-171+DoD+Assessment+Requirements
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
  • NIST SP 800-171A assessment methods (examine, interview, test), via the DoD CMMC Assessment Guide, Level 1: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL1.pdf
  • CMMC Phase 2 suspension status: https://corsicatech.com/blog/cmmc-level-2-requirements/

Next step

Collect your evidence from the live system instead of chasing screenshots. PolicyCortex uses 33 collectors that read live Azure configuration. It builds SSP, SAR, and POA&M output from the evidence it collects. See how it works.