Evidence, Artifacts, and “Show Me, Don’t Tell Me”: What Assessors Look For in a CMMC Assessment
For many business owners, the most frustrating part of preparing for a CMMC Level 2 assessment isn’t the controls themselves. It’s understanding what an assessor will accept as proof that those controls are in place.
Policies get written. Tools get purchased. Screenshots get collected. And yet, when the assessment starts, uncertainty creeps in. What exactly counts as evidence? Why isn’t a policy enough? Why does an assessor keep asking to “see it” instead of just reading what’s been documented?
The short answer is this: CMMC assessments are not about what you say you do. They’re about what you can demonstrate in practice.
What Assessors Mean by “Evidence”
In a CMMC Level 2 assessment, evidence is simply objective proof that a required control is operating the way your organization claims it is.
That proof usually needs to show three things: the control is defined, it’s implemented, and it’s being used on a regular basis. Documentation addresses intent. Technical artifacts show configuration. Operational records and conversations show that the process is real.
Assessors don’t expect a single document to check every box. What they look for is alignment. When documentation, systems, and people all tell the same story, controls are usually straightforward to validate. When they don’t, that’s when questions start.
Why Policies Alone Don’t Carry Much Weight
Most organizations come into an assessment with solid policies. That’s a good thing. But policies, by themselves, rarely prove anything.
A policy might state that access reviews are performed monthly. From an assessor’s perspective, that’s a claim, not evidence. The natural follow-up is to ask how that review happens, who performs it, and what proof exists that it’s been done over time.
This is often where organizations feel surprised. From the business side, the policy represents the rule. From the assessment side, it represents the starting point for validation.
The Role of Technical Artifacts
Technical artifacts tend to feel more tangible. System settings, access lists, logs, and configuration screenshots all play an important role in assessments.
But even here, context matters. A screenshot shows how something looks at a single moment in time. It doesn’t explain whether the setting is enforced consistently, whether it’s reviewed, or whether staff understand how it fits into a broader process.
That’s why assessors often ask follow-up questions even when a configuration looks correct. They’re not questioning the tool. They’re validating the control around it.
Why “Show Me” Is a Core Part of the Process
When assessors ask to see something demonstrated, it’s not an attempt to make the process harder. It’s how CMMC distinguishes real operational controls from theoretical ones.
A live walkthrough of how a user is provisioned, how logs are reviewed, or how incidents are handled often provides more clarity than any document ever could. These demonstrations show not only that the control exists, but that it’s understood and repeatable.
For business owners, this is an important distinction. Assessments are designed to evaluate how your organization operates, not how it’s supposed to operate on paper.
Interviews Are About Alignment, Not Interrogation
Interviews tend to worry people, especially leadership. In practice, they’re one of the most effective validation tools assessors have.
Assessors are listening for consistency. Does the way your team describes a process match what’s written down? Does it match what the systems show? Are responsibilities clearly understood?
When answers vary widely between roles or conflict with documentation, assessors have to dig deeper. That doesn’t automatically mean a failure, but it does introduce uncertainty. Organizations that prepare staff to explain what they do in plain terms generally find interviews to be far less stressful than expected.
More Evidence Is Not Better Evidence
One of the most common mistakes we see is over-collection. Faced with uncertainty, organizations upload everything they can think of, hoping something in the pile will stick.
From an assessment perspective, this often has the opposite effect. Important artifacts get lost in the noise, review time increases, and inconsistencies become easier to spot.
Assessors are looking for clear, relevant evidence that directly supports a control. A smaller, well-organized set of artifacts almost always leads to a smoother assessment than a large, unfocused one.
Consistency Is the Quiet Indicator of Maturity
If there’s one trait that separates smoother assessments from difficult ones, it’s consistency.
When your system security plan reflects how your environment actually works, when staff describe processes the same way, and when artifacts support both, the assessment naturally moves faster. Inconsistencies don’t necessarily mean poor security, but they do signal that a program may not be fully controlled or understood.
From a business perspective, this is less about compliance and more about operational discipline.
What Assessors Are Actually Trying to Do
It’s worth addressing a concern many business owners have but rarely say out loud. Assessors are not looking for reasons to fail organizations.
CMMC assessments are structured evaluations with defined criteria. Assessors are required to document how conclusions are reached and apply the same standards consistently. The objective isn’t perfection. It’s verifiable, repeatable implementation of required controls.
When organizations understand that, the dynamic of the assessment tends to shift from defensive to collaborative.
Preparing the Right Way
The organizations that fare best in CMMC Level 2 assessments don’t try to out-document the process. They focus on making sure what’s written matches reality and that reality can be demonstrated.
That preparation usually looks like internal walkthroughs, light evidence testing, and honest conversations about where controls rely on vendors or inherited services. It’s less about creating new material and more about validating what already exists.
Final Thought
At the end of the day, a CMMC Level 2 assessment is a “show me, don’t tell me” exercise. If your organization can clearly explain how it operates, demonstrate that those processes are in use, and show that they’re applied consistently, the assessment becomes far less intimidating. Evidence stops feeling like a hurdle and starts reflecting the way your business runs. That’s the goal.
Continue Reading
July 29, 2026
Five Takeaways from This Week’s CyberAB Town Hall
July 14, 2026
