CMMC Level 2 Encryption Evidence Checklist
Encryption can be active across your environment and still fail an assessment if you cannot prove where it protects CUI, which module provides it, and how your team manages it.…
Encryption can be active across your environment and still fail an assessment if you cannot prove where it protects CUI, which module provides it, and how your team manages it.…
A CMMC Level 2 assessment can show strong controls on paper, yet an unsupported annual affirmation can still create contract risk. For senior officials, the CMMC annual affirmation is a…
A locked office door is not enough to prove CMMC Level 2 compliance. I regularly see small contractors protect their space reasonably well, yet struggle to show who had access,…
A CAD file can carry Controlled Unclassified Information long after it leaves the engineering workstation. A drawing may sit in a PDM vault, move through Microsoft 365, appear in a…
Weak passwords still break strong environments. When I help a team prepare for Entra ID password protection in a CMMC Level 2 context, I start with one plain fact: Microsoft…
A stolen password should not open the door to Controlled Unclassified Information. When I help teams build CMMC conditional access controls, I want identity, device health, and audit evidence to…
Most CUI doesn’t leak through a dramatic breach. It leaves through ordinary user actions on an endpoint, a USB copy, a browser upload, a print job, or a quick paste…
A device can look healthy in Intune and still leave you short on audit evidence. I see that gap often with Intune Secure Boot and TPM evidence, because admins trust…
One Teams recording can turn a normal project call into a CUI handling event. I see that happen most often when a meeting starts as routine collaboration and ends with…
Microsoft 365 rarely fails because a control was missing on paper. It fails because the control drifted, nobody checked it, or the evidence never got saved. I use an SSP…