Guide
What evidence do I need for CMMC Level 1?
Short Answer
There is no official evidence checklist. A requirement is MET when adequate evidence shows the objectives are implemented. For most FCI-only suppliers that means a short set of policies, a few configuration screenshots or exports, an inventory of external systems, and a simple boundary diagram, all in final form and retained for six years.
What tends to be enough
A practical Level 1 package usually includes an inventory of external and cloud systems, a brief policy or two, configuration evidence such as firewall or account settings, a simple network or boundary diagram, and records of reviews. You do not need a fifty-page policy binder.
Rules that matter
Evidence should be complete, dated, tied to the specific objective, and in final form rather than draft. Nothing is uploaded to SPRS. You keep the evidence, and it must be retained for six years, so it needs to survive staff turnover and reorganized drives.
Where AssessrLog fits
AssessrLog is the system of record for this. It stores each artifact, versioned and content-hashed, next to the objective and the determination it supports, so the record stays traceable and defensible. The determination itself is always yours to make.
Related Requirements
Related Definitions
Related Questions
Primary Sources
Build the Record Behind This
AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.
