Old screenshots, stale policies, and inactive accounts can weaken an otherwise sound CMMC program. When preparing for an assessment, I treat CMMC assessment evidence as proof of how your environment operates now, not a folder of documents created for a past milestone.
Many defense contractors search for a fixed number of days. However, CMMC evidence does not follow one universal 30, 60, or 90-day rule. Its acceptable age depends on the control, the assessment period, and whether the artifact still reflects your actual systems and practices.
Key Takeaways
- CMMC does not impose one universal freshness window for every evidence item.
- Evidence must be final, approved, traceable, and relevant to the environment under assessment.
- Recurring controls need records that show consistent operation over a meaningful period.
- Major changes to systems, users, cloud services, or boundaries can make older evidence unreliable.
- Assessment artifacts require long-term retention, while operational proof must remain current.
What the CMMC Program Rule Requires
The CMMC Program rule in 32 CFR Part 170 establishes the assessment and affirmation structure, but it does not assign one expiration date to every screenshot, policy, log, or configuration report.
That distinction matters. A policy approved 10 months ago may still be valid if leadership reviewed it, the policy matches current practice, and the supporting procedures are active. In contrast, a privileged-access review completed 10 months ago would rarely prove that access is controlled today.
For CMMC Level 2, organizations must reaffirm compliance annually in the Supplier Performance Risk System, or SPRS. A Level 2 certification assessment has a three-year validity period. Yet certification validity does not make evidence permanently current. Your operating environment can change long before the next assessment.
The rule also requires assessment artifacts to be retained for at least six years from the assessment date. Retention is different from evidence currency. You keep the historical record to support the completed assessment, while you maintain newer operational proof for ongoing compliance.
A document can meet the retention requirement and still be too old to prove that a recurring security control operates today.
I recommend separating these two tasks. Archive the evidence package used for an assessment. Then continue collecting current evidence through normal security operations, reviews, and change management.
How Recent Must CMMC Evidence Be Before an Assessment?
The practical answer is that CMMC evidence must be recent enough to demonstrate the control is implemented and operating during the relevant assessment period. The right date depends on what the requirement asks your organization to do.
The DoD’s CMMC Level 2 Assessment Guide calls for objective evidence that demonstrates fulfillment of each assessment objective. It also makes an important point: draft documents are not acceptable evidence. Policies, procedures, plans, diagrams, and similar artifacts must be final forms.
I advise clients to look at every artifact through two questions:
- Does this prove the control exists in the current assessment scope?
- Does the date match the control’s operating frequency?
This approach avoids a false sense of security from a well-organized evidence library. A polished file name means little if the system name changed, the device inventory is outdated, or the staff member shown in a training record left months ago.
The table below offers practical recommendations, not regulatory deadlines.
| Evidence type | What assessors need to see | Practical currency recommendation |
|---|---|---|
| Policies and procedures | Approved, applicable documents that match current practice | Review after material changes and on your documented review schedule |
| System security plan | Accurate system boundary, assets, users, data flows, and control descriptions | Update whenever the CMMC scope or implementation changes |
| Access reviews | Proof that authorized access is reviewed and adjusted | Match the frequency stated in your policy or procedure |
| Security awareness training | Completion records for in-scope personnel | Include current personnel and the most recent training cycle |
| Vulnerability management | Scans, remediation records, and risk decisions | Show recent activity that follows your defined cadence |
| Backups and recovery tests | Backup status and recovery validation | Present the latest test and evidence of routine backup operation |
| Endpoint configurations | Device settings, encryption, antivirus, and account controls | Pull fresh reports close to the assessment when possible |
The key point is simple. A monthly activity needs evidence from recent monthly cycles. An annual review needs the latest completed annual record. A standing configuration should be verified against the live environment shortly before the assessment.
Recurring Controls Need a Usable History
Assessors do not only look for a single successful event. They need reasonable confidence that your organization performs recurring tasks as written. I have found that a consistent record is more persuasive than a last-minute report created days before the assessment.
For example, if your procedure requires monthly vulnerability scanning, preserve several consecutive scan reports, remediation tickets, exception approvals, and management review records. If the same unresolved critical finding appears repeatedly, document the risk decision and corrective action. Silence creates doubt.
Similarly, access control evidence should connect the user list, job roles, approval process, and removal of terminated users. A single export from Microsoft 365 or an identity platform is useful, but it does not prove a review process without supporting records.
This is where CMMC assessment evidence often breaks down. Teams collect technical screenshots but omit the management action behind them. A privileged account list shows who has access. A dated review with an approver shows that someone evaluated whether that access remains justified.
I recommend keeping a rolling evidence calendar tied to control frequency. Monthly tasks, quarterly reviews, annual training, and event-driven updates should each have an owner and repository. That cadence reduces the scramble before an assessment and exposes missed activities earlier.
Changes Can Make Evidence Stale Overnight
Evidence does not become unreliable only because time passes. A major change can invalidate it immediately.
A new tenant configuration, domain controller, firewall, cloud application, or managed service provider can change how a control works. The same is true when you add remote workers, open a new location, move workloads, or begin handling CUI in a different system.
For example, an Office 365 Migration can change identity controls, retention settings, audit logging, sharing restrictions, and mobile device management. If you move regulated workloads into Microsoft 365 GCC High, your system security plan, data-flow diagrams, asset inventory, and evidence collection method may all need revision.
Likewise, a change in Cloud Infrastructure needs more than a new architecture diagram. You need current proof of account configuration, least-privilege access, logging, backup coverage, and shared-responsibility assignments. A Secure Cloud Architecture is only credible when its live settings match the design.
I recommend a formal evidence refresh after any material scope or technology change. Connect that step to your change-management process. When the change closes, update affected procedures and collect new proof while the implementation details are still clear.
Build an Evidence Package That Shows Real Operations
Strong evidence is organized, but it should never look manufactured. Assessors need to trace an artifact to a control, an in-scope system, and a defined period of operation.
My preferred approach is to map each practice to a small evidence set: the governing policy or procedure, a technical record, and proof that people followed the process. Keep filenames understandable. Include dates, system names, responsible owners, and version information.
For many small contractors, the strongest evidence sources include:
- Current system security plans, network diagrams, data-flow diagrams, and asset inventories.
- Microsoft 365 audit logs, endpoint reports, multifactor authentication settings, vulnerability scans, backup records, and ticket history.
- Training rosters, access review approvals, incident records, risk register entries, and management meeting minutes.
- Live demonstrations that confirm the current configuration matches the written evidence.
Technical evidence should also be consistent across sources. If your asset inventory lists 42 endpoints, your endpoint platform, patch dashboard, and encryption report should reconcile with that count or explain the difference.
Endpoint Security and Device Hardening often produce a large volume of data. Avoid sending unfiltered exports without context. Provide a short index that identifies which report supports each control and what date range it covers. That saves time and makes gaps easier to address before an assessor finds them.
Technology Scope Still Determines Evidence Quality
Small contractors often operate mixed environments. A company may need Small Business IT, Cybersecurity Services, and Cloud Management while also running specialized business systems. The CMMC boundary must reflect where Federal Contract Information or CUI exists, travels, or receives protection.
That scope question applies to Data Center Technology, mobile devices, managed endpoints, line-of-business applications, and outsourced support. It can also affect firms that offer Restaurant POS Support or Kitchen Technology Solutions alongside defense-related work. Separate commercial systems do not automatically belong in CMMC scope, but a shared identity service, network, administrator account, or backup platform may bring them into the evidence discussion.
A capable Business Technology Partner should connect compliance needs to day-to-day operations. That includes Technology Consulting, Infrastructure Optimization, and an IT Strategy for SMBs that does not treat CMMC as a once-every-three-years project.
Services described as Innovative IT Solutions, Tailored Technology Services, Managed IT for Small Business, or Digital Transformation should still produce audit-ready records. Ask providers for change tickets, configuration baselines, incident escalation procedures, administrative access lists, and service reports. Those records support Business Continuity & Security and make evidence easier to validate.
Confirm Expectations Before the Assessment
The assessment guide and rule provide the governing framework, but your scope, contract language, and selected assessment method affect what evidence is appropriate. I recommend confirming evidence expectations early with your assessor, legal counsel, and compliance advisors.
Do not wait until the assessment date to discover that a control owner lacks records or that a diagram omits a critical service. A pre-assessment review can test whether your artifacts are final, current, and tied to the actual environment.
Final Thoughts
The age of CMMC evidence matters because proof must reflect the way you protect information today. Retained assessment artifacts preserve history, while current records demonstrate continuing compliance.
The strongest preparation combines CMMC assessment evidence that is final, dated, traceable, and refreshed after meaningful change. That discipline turns an assessment from a document hunt into a credible demonstration of your security program.
Discover more from Guide to Technology
Subscribe to get the latest posts sent to your email.
