Case Study 05 - Defense Supplier Preparing for C3PAO Assessment

Building audit-ready evidence architecture for a C3PAO assessment.

Documentation gaps are the single most common reason CMMC assessments fail. Templates and policy files are not enough. What survives a C3PAO assessment is a controlled evidence chain - a system where every NIST 800-171A assessment objective is tied to dated, verifiable artifacts that demonstrate the control is not just documented, but actually operating.

Industry: Aerospace and defense supplier on a defined assessment timeline Geography: Southern California CMMC scope: Level 2
Industry context

A defense supplier on an assessment timeline - with controls in place and almost no evidence to prove it.

The organization at the center of this case study is a Southern California defense supplier with established controls, a documented policy package (built through earlier engagements summarized in the other case studies in this series), and a scheduled C3PAO assessment on the horizon. The work in this engagement was not to build security controls - those existed. It was to build the evidence architecture that proves the controls are operating, on the cadence the framework expects, and in a form that an assessor can verify.

The evidence problem in CMMC is not unique to this organization. Greenberg Traurig's October 2025 GT Alert on CMMC audit preparation makes the point directly: a System Security Plan that does not reflect the current environment, or that references controls without supporting evidence of operation, will not survive a C3PAO assessment. The Alert is explicit that "the absence of an updated SSP at the time of an assessment will result in a finding that an assessment could not be completed." Bass Berry & Sims, in its analysis of the Final Rule, reinforces the same conclusion from a contractual liability angle: documentation has become a condition of contract eligibility, and the affirming official's annual certification puts personal weight behind it.

The NIST SP 800-171A assessment methodology spells out exactly what assessors look for. Every one of the 110 NIST 800-171 Rev 2 controls is broken into specific assessment objectives - 320 in total. Assessors verify each objective using one or more of three methods: Examine (review of documentation), Interview (conversation with personnel responsible for the control), and Test (demonstration that the control actually operates as documented). The evidence architecture has to support all three methods, for every objective, for every applicable control. That is the standard. Anything less is a gap.

The challenge

Evidence collected in a pre-assessment scramble does not look like evidence collected through normal operations. Assessors can tell.

Industry data captured by The Cyber AB and analyzed independently by Secureframe in March 2026 indicates that approximately 1,000 organizations have achieved CMMC Level 2 certification, against a Defense Industrial Base estimated at 80,000 contractors needing certification. That is roughly one percent. The bottleneck, as Secureframe's analysis notes, is not C3PAO assessor capacity - it is contractor readiness. Within contractor readiness, the dominant gap is evidence.

Evidence collected in a pre-assessment scramble looks different from evidence collected through normal operations. Pre-assessment scramble evidence has gaps in dates, missing approvals, inconsistent owners, and structural patterns that signal compression. Normal-operations evidence has continuous cadence, documented ownership, and chains of custody. Greenberg Traurig's October 2025 GT Alert reinforces this directly: "Assessors will be looking for any disconnect between what the documentation says and the company's actual practice." A scramble produces those disconnects almost by definition.

The 320 NIST 800-171A objectives are numerous, granular, and easy to lose track of. Some objectives are satisfied by a single artifact. Others require multiple artifacts of different types - a policy document, a procedure document, a configuration export, an audit log sample, training records. An organization that does not have a central inventory mapping each objective to its supporting artifacts will find itself unable to demonstrate coverage even when the underlying controls are operating correctly.

Evidence has to be defensible across time. A C3PAO assessor reviewing an environment may request a sample from a window earlier in the year. Logs that were retained for a week, then rotated and lost, do not satisfy an assessor's request to review last quarter's audit log review activity. Evidence retention policies, log retention configurations, and the discipline to actually retain artifacts for the required windows are part of the architecture - not afterthoughts.

Hash verification and forensic defensibility matter. If an evidence artifact is contested - for example, if an assessor asks whether a policy document was actually in place on a particular date, or whether a configuration setting was actually applied at a claimed point in time - the contractor needs to be able to demonstrate the artifact has not been retroactively created or modified. Hash-stamped artifacts stored in immutable or strongly version-controlled locations satisfy this. Word documents in a shared folder do not.

Verification framework

How a C3PAO assessor verifies a Level 2 objective

The three verification methods in a C3PAO assessment A diagram showing the three verification methods (Examine, Interview, Test) used by C3PAO assessors per NIST SP 800-171A, with the Master Evidence Tracker mapping all 320 assessment objectives to dated, hash-verified artifacts. 14 CONTROL FAMILIES 110 SECURITY REQUIREMENTS 320 ASSESSMENT OBJECTIVES 3 VERIFICATION METHODS Every objective is verified using one or more of three methods defined by NIST SP 800-171A Examine METHOD 1 OF 3 Documentation review The assessor inspects written artifacts to confirm the control is defined and authorized. TYPICAL ARTIFACTS - System Security Plan entry - Policy & procedure text - Configuration export - Training records Interview METHOD 2 OF 3 Conversation with personnel The assessor speaks with the people responsible for operating the control. Mismatches with the documentation become findings. TYPICAL ROLES - Control owner / process lead - IT administrator - End users and operators Test METHOD 3 OF 3 Operational demonstration The assessor verifies the control actually operates as documented, in production, with real evidence. TYPICAL EVIDENCE - Live configuration check - Vulnerability scan output - Audit log samples - Access attempt traces MASTER EVIDENCE TRACKER Maps all 320 assessment objectives to dated, hash-verified artifacts that support each verification method.

Reading this diagram: every assessment objective is verified using one or more of three methods defined by NIST SP 800-171A. The Master Evidence Tracker ties every objective to dated, hash-verified artifacts that support each method. Sources: NIST SP 800-171A, Greenberg Traurig GT Alert (October 2025), Redspin 2025 Momentum report.

How we approached this

Build the evidence architecture as a system that produces audit-ready artifacts during normal operations.

We treat evidence collection as a continuous-compliance discipline, not a one-time pre-assessment project. The architecture is designed so that the artifacts a C3PAO assessor will examine are produced as a natural byproduct of the controls themselves - collected on cadence, stamped with dates and hash values, and stored in a controlled location that can be walked end to end.

Build the Master Evidence Tracker - every NIST 800-171A objective mapped to its supporting artifacts

The foundational document of the evidence architecture is the Master Evidence Tracker. It lists every NIST 800-171A assessment objective in a structured row, identifies which artifacts satisfy that objective, and locates each artifact in the controlled evidence library. The tracker also records the owner responsible for keeping the artifact current, the cadence at which the artifact is refreshed, and the last verified date. Where multiple artifacts contribute to a single objective, the tracker records all of them. Where an objective is satisfied by an external service provider's controls, the tracker references the Shared Responsibility Matrix for that provider. This document is the single most important artifact the C3PAO assessor will use to navigate the assessment scope.

Catalog and classify every existing evidence artifact

Before any new evidence gets created, every existing artifact gets cataloged. Policy documents, procedure documents, training records, configuration exports, audit log samples, vendor authorization documentation, vulnerability scan reports, change management records, incident response test records, physical access logs - every artifact in the environment gets identified, classified, and added to the evidence library. Each artifact gets a row in the Master Evidence Tracker with a unique identifier, a hash value computed at the time of cataloging, a date of last update, and an owner. This step alone closes a substantial portion of the apparent evidence gap, because most organizations have more evidence than they think - it is just not organized into a system.

Identify the genuine gaps and build the artifacts they require

After the cataloging pass, the remaining gaps become visible. Some are policy gaps - a NIST objective that requires a documented procedure for which no procedure exists. Some are operational gaps - a procedure that exists on paper but is not being executed on cadence, with no log of execution. Some are evidence-of-evidence gaps - a control that is operating, but the evidence of its operation is not being retained. Each gap gets a remediation plan: author the missing artifact, institute the missing cadence, configure the missing log retention. The Plan of Action and Milestones (POA&M), where appropriate, formally tracks these in the form the framework expects.

Establish weekly evidence collection cadence

Evidence does not get collected once. It gets collected on a recurring schedule that produces an unbroken chain of artifacts. We established a weekly evidence collection cycle: a defined set of artifacts gets refreshed every week (audit log review samples, change management approval records, new-hire onboarding records, visitor logs, security event triage records). A separate monthly cycle covers slower-rotation evidence (vulnerability scan reports, configuration review records, training completion summaries). The cadence is documented in the Operations Security Procedures Manual, executed by named owners, and the execution itself produces evidence - the existence of the weekly collection log demonstrates the collection is happening.

Hash-stamp and version-control critical artifacts

Policy documents, procedure documents, the System Security Plan, the Shared Responsibility Matrices, and the Master Evidence Tracker itself all receive hash values when they are issued and again on each revision. The hash value is recorded in the document control header and in the Master Evidence Tracker. The artifacts are stored in a version-controlled location with retention configured to satisfy the longest applicable retention window. If an assessor asks whether a particular version of a document was in place on a specific date, the chain of hashes and revision dates supports the answer. This forensic discipline is what separates assessment-defensible documentation from documentation that an assessor can challenge.

Run a mock C3PAO assessment against the evidence architecture

Before the actual assessment, we ran a mock assessment using the NIST 800-171A methodology - Examine, Interview, Test, every applicable objective. The mock identified two classes of issues: artifacts that existed but were hard to find within the evidence library (resolved by improving the Master Evidence Tracker navigation), and personnel who could explain their roles in conversation but whose explanations did not match the documented procedures word-for-word (resolved through additional targeted training). The mock surfaces issues that are correctable. Surfacing them during the actual assessment is far more expensive.

Outcomes

An evidence chain that walks cleanly through Examine, Interview, and Test.

The organization's evidence architecture is now navigable, dated, version-controlled, and tied to every applicable NIST 800-171A assessment objective. The Master Evidence Tracker functions as the entry point - both for the internal team running the program and for the C3PAO assessor when the assessment begins. From any control objective, the tracker points to the artifacts that satisfy it. From any artifact, the tracker points back to the objectives it supports. Each entry has a date, an owner, a hash value, and a cadence.

Evidence is now produced as a continuous byproduct of operations rather than as a pre-assessment scramble. The weekly and monthly collection cycles run on schedule. When a sample is needed from an earlier time window, it is available because retention was configured to support the request. Personnel responsible for each evidence stream understand their role and can speak to it under interview.

The forensic integrity of the artifacts is established. Hash values recorded at issuance and at each revision allow the organization to demonstrate that policies and procedures were in place at the dates claimed, not retroactively authored to satisfy an assessor's question. This level of discipline goes beyond what most CMMC programs achieve, and it is the difference between a program that survives an aggressive assessment line of questioning and a program that does not.

From the assessor's perspective, the assessment is now navigable. The Examine phase has a clear entry point and complete artifacts. The Interview phase has personnel who can explain the controls they own. The Test phase has demonstrable controls with evidence chains supporting each demonstration. Greenberg Traurig's central point - that "assessors will be looking for any disconnect between what the documentation says and the company's actual practice" - is the test this organization is now positioned to pass.

Standards and controls touched

The published controls and authorities behind this work.

Every Consilien engagement maps to specific, citeable controls and publications. This is the regulatory and standards footprint of the work described above.

Standard / Control
Why it applies here
CA.L2-3.12.1 / 3.12.2 / 3.12.3 / 3.12.4
Security Assessment family - periodic assessment, POA&M, monitoring, and the System Security Plan itself. The evidence architecture is the substrate this family relies on.
AU.L2-3.3.1 through 3.3.9
Audit and Accountability - log collection, retention, protection, review, and reporting. Evidence retention is a core element of this family.
CM.L2-3.4.1 through 3.4.9
Configuration Management - baseline configuration, change control, configuration review. Each requires retained evidence of operation.
IR.L2-3.6.1 / 3.6.2 / 3.6.3
Incident Response - including documented testing of the IR plan, which itself requires evidence retention to demonstrate.
MA.L2-3.7.1 through 3.7.6
Maintenance - maintenance tools, personnel, and records, all of which require evidence trails.
RA.L2-3.11.1 / 3.11.2 / 3.11.3
Risk Assessment - periodic risk assessment, vulnerability scanning, and remediation. Multiple scan cycles and remediation records are typically required as evidence.
NIST SP 800-171A
Assessment methodology - the authoritative source for what evidence assessors actually examine.
DFARS 252.204-7012(c)
Cyber incident reporting - the operational evidence trail for incident response capability is required to demonstrate compliance with the 72-hour reporting obligation.
Why this matters for similar manufacturers

If your evidence is generated in the weeks before assessment, your assessor will notice.

The single largest determinant of whether a CMMC assessment goes well is the quality of the evidence architecture. Controls that are operating in practice but are not evidenced will be marked as not implemented. Controls that are documented in policy but not demonstrated in practice will be flagged as disconnects. The framework is unambiguous on this - NIST 800-171A specifies the assessment methodology in detail - and the assessor population has been trained to apply it consistently.

Three diagnostic questions will tell you whether your own evidence architecture is ready. First, can you, right now, name the artifact that satisfies a specific NIST 800-171A objective - pick one at random from the assessment guide - and produce that artifact within ten minutes? Second, for that artifact, can you produce evidence that it has been refreshed or reviewed on the cadence the framework expects? Third, for that cadence, can you produce a sample from at least one month ago and at least three months ago, dated and verifiable? If any of those answers is no, your evidence architecture has work to do.

The economic argument for getting this right is simple. The Redspin 2025 survey found that 31 percent of contractors have already spent more than $250,000 preparing for CMMC, with another 26 percent in the $100,000-$250,000 range. A meaningful portion of those expenditures goes to remediation after a failed first attempt - re-engagements with consultancies, re-scheduled C3PAO visits (against a one-year-plus waitlist at most authorized firms), and the workforce-disruption cost of running the program a second time. An evidence architecture built correctly the first time is, in retrospect, the cheapest line item in the entire program.

Sources and references

Sources & references

Is your evidence architecture ready for a C3PAO assessment?

If your controls are in place but your evidence is scattered, undated, or generated in pre-assessment cycles, we can audit your evidence architecture against the NIST 800-171A methodology in a focused engagement.