
CMMC Requirements: Why Assessors Require Evidence, Not Just Policies
Having a policy in place is not the same as having a control in place. For many defense contractors, this is where CMMC compliance efforts break down, and where formal assessments expose gaps that internal reviews never surfaced.
Under the CMMC final rule, assessors aren't evaluating whether your organization has documented its intentions. They're evaluating whether those intentions are operational, consistent, and backed by evidence. That requires more than paperwork.
What Do CMMC Assessors Look for During an Assessment?
When a C3PAO assessor evaluates your environment, they're working through each applicable practice using the CMMC Assessment Process (CAP). For every practice, the question isn't "do you have a policy that addresses this?" It's "can you show me that this is happening?"
That distinction matters because policies are easy to produce and hard to validate on their own. Evidence is what closes the gap. It tells an assessor that a control isn't just described. It's implemented, it's operating, and it's been functioning consistently enough to leave a traceable record.
Which CMMC Practices Have the Most Evidence Gaps?
Several CMMC practices consistently surface documentation gaps during assessments. What makes them notable isn't their complexity. It's that organizations often assume they're covered until an assessor asks for proof.
Access Control (AC)
Organizations frequently have access control policies but lack the logs or configuration records to demonstrate enforcement. Assessors expect to see evidence of least privilege implementation, role-based access assignments, and reviews of user access rights. A policy that describes how access should be managed isn't sufficient without system-generated records showing it's being managed that way.
Audit and Accountability (AU)
Log management is one of the most commonly underdeveloped areas in CMMC readiness. Assessors look for evidence that audit logs are being generated, protected, reviewed, and retained. Many organizations have logging enabled but can't demonstrate that logs are reviewed on a defined schedule or that anomalies are acted on.
Incident Response (IR)
A documented incident response plan is a starting point, not a finish line. Assessors want to see evidence that the plan has been tested, that personnel know their roles, and that prior incidents or exercises have been documented. Tabletop exercises with no written record leave assessors with nothing to validate against.
Configuration Management (CM)
Baseline configurations are required, but assessors also look for evidence that those baselines are enforced and that changes go through an approval process. Change logs, configuration records, and deviation documentation are all fair game during an assessment.
Identification and Authentication (IA)
Multi-factor authentication requirements under CUI 3.5.3 are well known, but assessors frequently find gaps in coverage. Systems or access points where MFA isn't enforced, or where enforcement can't be demonstrated through system settings or access records, are common findings.
Why Does Documented Compliance Often Fail Under CMMC Scrutiny?
Most organizations approaching CMMC for the first time have spent their preparation time building policies and completing self-assessments. Both are necessary steps, but they don't tell you whether your evidence will hold up under scrutiny.
Evidence collection isn't a one-time task. Assessors aren't looking for a snapshot of where you are the week before your assessment. They're looking for indicators that controls have been operating over time. Logs that only go back 30 days, training records completed in a single afternoon, or incident response documentation with no history of use all signal that a control was stood up for the assessment rather than embedded in day-to-day operations.
With only an estimated 1% of defense contractors currently holding CMMC certification, the gap between documented compliance and demonstrable compliance is widespread. For prime contractors, that affects competitiveness directly. For subcontractors, it can mean being excluded from opportunities before a bid is even submitted.
How Do You Build a CMMC Compliance Program That Satisfies Assessors?
Closing the gap between policy and evidence requires a deliberate approach. Controls need owners who are responsible not just for maintaining documentation but for ensuring that operational activity generates the records an assessor will expect to see. System Security Plans (SSPs) need to reflect how controls are implemented, not how they're intended to be implemented.
Regular internal reviews against the CMMC Assessment Process, not just against a checklist, give organizations a realistic picture of where their evidence stands before an assessor does. That preparation is what separates organizations that pass on the first attempt from those that don't.
If you're unsure whether your current compliance program would hold up under assessor scrutiny, Clark Schaefer Consulting can help you evaluate your evidence posture and identify gaps before they become findings. Contact our team to get started.






