Skip to content

Evidence request lists

CMMC 2.0 Level 1

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

AC.L1-3.1.1
Authorized Access Control

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.1: Authorized Access Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(i) (3.1.1).

Artefacts an auditor will ask for
  • Account inventory limiting system access to authorized users, processes and devices
  • Access authorization records
Where this commonly fails
  • Shared/unauthorized accounts with FCI access
AC.L1-3.1.2
Transaction and Function Control

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.2: Transaction and Function Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ii) (3.1.2).

Artefacts an auditor will ask for
  • Role/permission matrix limiting access to permitted transactions and functions
Where this commonly fails
  • Users able to execute functions beyond their role
AC.L1-3.1.20
External Connections

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.20: External Connections - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iii) (3.1.20).

Artefacts an auditor will ask for
  • Inventory + authorization of external system connections
  • Controls verifying/limiting use of external systems
Where this commonly fails
  • Unverified external connections to FCI systems
AC.L1-3.1.22
Control Public Information

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.22: Control Public Information - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iv) (3.1.22).

Artefacts an auditor will ask for
  • Review/approval process for information posted to publicly accessible systems
Where this commonly fails
  • FCI inadvertently posted publicly

Identification and Authentication

IA.L1-3.5.1
Identification

CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.1: Identification - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(v) (3.5.1).

Artefacts an auditor will ask for
  • Unique identifiers for users, processes and devices
Where this commonly fails
  • Shared or generic accounts
IA.L1-3.5.2
Authentication

CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.2: Authentication - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vi) (3.5.2).

Artefacts an auditor will ask for
  • Authentication mechanism verifying identities before access
  • Authenticator management
Where this commonly fails
  • Identities not authenticated before granting FCI access

Media Protection

MP.L1-3.8.3
Media Disposal

CMMC 2.0 Level 1 (Foundational) practice MP.L1-3.8.3: Media Disposal - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vii) (3.8.3).

Artefacts an auditor will ask for
  • Media sanitization/destruction procedure for FCI media before disposal or reuse
  • Sanitization records
Where this commonly fails
  • FCI media disposed without sanitization

Physical Protection

PE.L1-3.10.1
Limit Physical Access

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.1: Limit Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(viii) (3.10.1).

Artefacts an auditor will ask for
  • Physical access authorization limiting access to systems/equipment/operating environments
Where this commonly fails
  • Uncontrolled physical access to FCI systems
PE.L1-3.10.3
Escort Visitors

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.3: Escort Visitors - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.3).

Artefacts an auditor will ask for
  • Visitor escort and activity-monitoring procedure
Where this commonly fails
  • Unescorted visitors in FCI areas
PE.L1-3.10.4
Physical Access Logs

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.4: Physical Access Logs - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.4).

Artefacts an auditor will ask for
  • Audit logs of physical access maintained
Where this commonly fails
  • No physical access logging
PE.L1-3.10.5
Manage Physical Access

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.5: Manage Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.5).

Artefacts an auditor will ask for
  • Control and management of physical access devices (keys, badges, locks)
Where this commonly fails
  • Physical access devices not tracked/recovered

System and Communications Protection

SC.L1-3.13.1
Boundary Protection

CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.1: Boundary Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(x) (3.13.1).

Artefacts an auditor will ask for
  • Boundary protection monitoring/controlling communications at external/key internal boundaries
Where this commonly fails
  • No boundary protection around FCI systems
SC.L1-3.13.5
Public-Access System Separation

CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.5: Public-Access System Separation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xi) (3.13.5).

Artefacts an auditor will ask for
  • Subnetworks for publicly accessible components separated from internal networks (DMZ)
Where this commonly fails
  • Public-facing components on the internal FCI network

System and Information Integrity

SI.L1-3.14.1
Flaw Remediation

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.1: Flaw Remediation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xii) (3.14.1).

Artefacts an auditor will ask for
  • Flaw identification/reporting/remediation (patch management) records
Where this commonly fails
  • Known flaws unpatched
SI.L1-3.14.2
Malicious Code Protection

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.2: Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiii) (3.14.2).

Artefacts an auditor will ask for
  • Malicious-code protection deployed at appropriate locations
Where this commonly fails
  • No anti-malware on FCI systems
SI.L1-3.14.4
Update Malicious Code Protection

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.4: Update Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiv) (3.14.4).

Artefacts an auditor will ask for
  • Anti-malware signature/engine update process
Where this commonly fails
  • Outdated malware definitions
SI.L1-3.14.5
System and File Scanning

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.5: System and File Scanning - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xv) (3.14.5).

Artefacts an auditor will ask for
  • Periodic system scans + real-time scanning of external-source files
Where this commonly fails
  • No periodic or real-time scanning
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CMMC 2.0 Level 1 framework page.