Home / Article

How Do I Map Evidence to Each CMMC Practice?

October 05, 2026 · cmmc, evidence, assessment

You have 110 security practices and a pile of proof that does not name any of them. That pile is the problem this article fixes. Mapping evidence means linking each practice to the exact proof that satisfies it.

What a map actually is

CMMC is the Cybersecurity Maturity Model Certification. Level 2 holds 110 practices across 14 families. These practices are identical to the requirements in NIST SP 800-171 Rev 2 (32 CFR Part 170). A C3PAO is a CMMC Third-Party Assessment Organization. Its assessors check each practice one by one. Your map tells the assessor where to look for each practice.

How an assessor judges your evidence

NIST SP 800-171A is the assessment guide for these requirements (NIST SP 800-171A). It gives each requirement a set of determination statements. Each statement starts with the word determine. The assessor marks each statement satisfied or not.

Three methods support every determination: examine, interview, and test. Examine means reviewing, inspecting, or analyzing what you hand over. Interview means discussing the control with your people. Test means exercising the control and comparing actual behavior to expected behavior.

Assessment objects fall into four kinds: specifications, mechanisms, activities, and individuals. Specifications are documents like policies and plans. Mechanisms are the hardware, software, or firmware doing the work. Activities are the protection steps your people perform. Individuals are the staff who apply them.

The five step mapping process

Step 1: list the practices. Start with the 110 practices in NIST SP 800-171 Rev 2, chapter 3 (NIST SP 800-171 Rev 2). Copy each practice ID and its short statement into a table. The 14 families give you natural groups: access control, incident response, and twelve more.

Step 2: read the assessment objectives. Open NIST SP 800-171A for each practice (NIST SP 800-171A). Break each practice into its lettered determination statements. These statements are your real checklist, not the practice text alone.

Step 3: assign one owner per practice. One named person owns each practice row. The owner finds the proof and keeps it current. Small firms can assign one owner per family instead of per practice.

Step 4: attach proof to each statement. Give every determination statement at least one piece of proof. Aim to cover examine and test for technical controls. Interviews happen live, so note who can speak to each control.

Step 5: date everything and schedule refreshes. Put a date on every file and every table row. Set a refresh date for each item so nothing goes stale before the assessment. Stale proof is a common assessment failure.

What the table should contain

Each row covers one practice. It holds eight columns: practice ID, short statement, owner, evidence files, methods covered, last refreshed, status, and SSP section.

Example row: practice ID AC.L2-3.1.1, short statement "Limit system access to authorized users," owner J. Rivera, evidence files 3.1.1-access-control-policy.pdf and 3.1.1-access-review-2026-09.xlsx, methods covered Examine and Interview, last refreshed 2026-09-30, status Met, SSP section 3.1.

SSP is a System Security Plan. The last column ties each table row to the section of the SSP where the practice is described.

How to name files so an assessor finds them

Start every file name with the practice number. Example file names: 3.1.1-access-control-policy.pdf and 3.6.1-incident-log.xlsx. A practice with several files gets a subfolder named for the practice number. Do not use names like final-v2. Names should let a stranger find the file in ten seconds.

Worked example: an access control practice

Practice AC.L2-3.1.1 says to limit system access. It covers authorized users, their processes, and devices. Map it like this.

Examine: the access control policy PDF and a conditional access export from your identity system. Interview: your IT admin explains who approves new accounts. Test: the assessor attempts a login without MFA and is blocked. Store all three under 3.1.1 in your table. Cite the NIST SP 800-171A determination statements you used (NIST SP 800-171A).

Worked example: an incident response practice

Practice IR.L2-3.6.1 says to build an incident-handling capability. It covers preparation, detection, analysis, containment, recovery, and user support. Map it like this.

Examine: the incident response plan and the incident log for the past year. Interview: the person named in the plan describes the last tabletop exercise. Test: the assessor reviews how a past incident moved through the ticket system. Paper plans alone never pass. You need records showing the plan was used.

How the map feeds your SSP

Your SSP describes how you meet each practice. Add an evidence column to your SSP practice narrative. List the exact file names from your table. When the SSP and the table point to the same files, the assessor trusts both.

What to do this week

Build the table with all 110 practice IDs first. Fill one family completely as your pilot. Access control is a good first family. Then repeat the pattern across the rest.

PolicyCortex reads live Azure configuration and ties each reading to its matching 800-171 requirement. This fills the test column of your table without manual exports. See how it works.

Sources

  • NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: https://doi.org/10.6028/NIST.SP.800-171r2
  • NIST SP 800-171A, Assessing CUI Requirements: https://csrc.nist.gov/publications/detail/sp/800-171a/final
  • CMMC Program Rule, 32 CFR Part 170: https://www.ecfr.gov/current/title-32/part-170