Assessment & Evidence

Evidence. Engineered.

Upload an artifact once and link it to every assessment objective it supports. When a C3PAO examines a practice, the evidence is already attached and indexed, not hunted down across four systems on assessment day.

110 CMMC L2 practices supported
320+ Assessment objectives linkable
On premises No external artifact storage
Capability

How Evidence Linking Works

When you upload a file, you link it to one or more assessment objectives at the moment of upload. The link is permanent and indexed, so any time an assessor or your own team opens that practice in the Requirements Browser, the attached evidence is already there. No folder browsing, no searching.

A single artifact can support many objectives. A network diagram supports boundary protection in SC, access control in AC, and configuration management in CM at the same time. Upload it once, link it everywhere it applies. Every file stays on the 1TEN appliance and every upload is logged with timestamp, user, file name, and linked objectives.

Dashboard Requirements Evidence POA&M Reports
1TEN Evidence Repository showing uploaded artifacts, expiration status, and the objectives each one is linked to
Assessment

What C3PAO Assessors Actually Verify

C3PAO assessors use three methods for each practice: examine, interview, and test. The examine method is the most common, and it is satisfied by evidence. When an assessor examines a practice, they look at the artifacts you have attached, not your implementation notes, not a verbal explanation, not the fact that you marked it Met. The artifact is the evidence.

For practices assessed by interview, the evidence still matters. Assessors ask personnel to describe a control, then verify the description matches what is documented. A policy that says one thing while the uploaded configuration screenshot shows another is a finding even if both are present. Keeping them in one place surfaces the discrepancy before the assessment, not during it.

Inside the Module

What You See Inside

Any file type
PDF, DOCX, PNG, JPG, XLSX, log files, and configuration exports are all accepted at upload.
Link at upload
Tag each artifact to one or more of the 320+ assessment objectives it supports, at the moment you upload it.
Evidence panel per practice
Every practice in the Requirements Browser shows the artifacts linked to it. No hunting across systems.
Evidence gap flagging
Assessment Summary flags any practice marked Met with no evidence attached, before an assessor finds it.
Versioned and attributed
Upload date, uploading user, file version, and a full-text description tracked for every artifact.
On-premises storage
Files live on the 1TEN appliance. No cloud storage dependency, no external transmission of CUI.
The problem this solves

Most contractors have the evidence. It is the organization that fails them. Policy documents live in SharePoint, configuration screenshots sit in someone's Downloads folder, training records are in the HR system, audit logs are on the SIEM. When an assessor asks for evidence supporting AC.L2-3.1.3, finding it should not take twenty minutes across four systems. No more SharePoint folders disconnected from the requirements, no more spreadsheets mapping filenames to practice numbers, no more cloud storage of CUI artifacts.

Reference

Common Evidence Types by Domain

Access Control (AC)
Active Directory group policy exports, role assignment screenshots, access request records, account provisioning procedures.
Audit & Accountability (AU)
SIEM configuration screenshots, log retention policy, sample audit log exports, log review records.
Configuration Management (CM)
Baseline configuration documents, change request records, software inventory exports, vulnerability scan results.
Identification & Authentication (IA)
MFA enrollment screenshots, password policy exports, privileged account list, authenticator management procedures.
Incident Response (IR)
Incident response plan, tabletop exercise records, incident log, reporting procedure documentation.
Maintenance (MA)
Maintenance log records, remote access session logs, vendor access approvals, maintenance personnel screening records.
Media Protection (MP)
Media sanitization records, portable media inventory, encryption configuration screenshots, disposal logs.
Physical Protection (PE)
Visitor logs, badge access reports, facility access list, physical security assessment records.
System & Comms Protection (SC)
Network architecture diagrams, firewall rule exports, encryption configuration, boundary protection evidence.
Awareness & Training (AT)
Training completion certificates, course completion records, training content screenshots, attendance rosters.
Practices

Practices Satisfied

Practice IDDescription
CA.L2-3.12.1 Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
All Domains Evidence linkage supports the examine assessment method across all 110 CMMC Level 2 practices and 320+ assessment objectives.
Connected Modules

Related Modules

Your SPRS score, live.

1TEN maps your documented controls to all 110 NIST SP 800-171 requirements and scores your posture in real time.

Request a Demo