CMMC Level 2 Assessment Objectives — Overview¶
This set of pages lists every CMMC Level 2 Assessment Objective (AO) mapped to its parent practice/requirement, the expected collection approach, potential evidence examples, and (where available) the related Assessment Guide discussion questions.
Column definitions (from the source workbook):
- Identifier — the CMMC Assessment Objective ID, e.g.
AC.L2-3.1.1[a]. The portion before the brackets (AC.L2-3.1.1) is the parent practice/requirement; the bracketed letter identifies the specific objective within that requirement. - Assessment Objective — the specific condition that must be satisfied for the requirement.
- Collection Approach — how an assessor is expected to gather evidence: Document, Artifact, Screen Share, or Physical Review.
- Potential Evidence Examples — illustrative evidence that could satisfy the objective.
- Assessment Guide Further Discussion — related question(s) from the CMMC Assessment Guide, where published guidance exists (not every objective has one).
Each section shows how an assessor will typically verify that each CMMC assessment objective is actually being met — not just documented on paper. For every assessment objective, the table indicates the type of proof an assessor will likely ask for.
These are starting-point expectations, not fixed rules. An experienced assessor can and will adjust the approach in real time — for example, asking for a live demonstration instead of a policy document — based on what your organization has already provided, how strong that evidence is, or where gaps remain. In other words: this table tells you what to prepare for, but flexibility is part of the process.
Assessors rely on four basic categories of proof. Understanding these now will help your team prepare the right kind of evidence for each requirement, rather than scrambling during the assessment window:
- Documents — Your written policies, procedures, and plans. This is the "what we say we do" layer: the rules and intentions your organization has put in writing.
- Artifacts — The system-generated records that prove your policies are actually being followed — think log files, configuration reports, tickets, or scan results. This is the "what actually happened" layer.
- Screen Share — A live, real-time demonstration where someone on your team shows the assessor a system or process in action, screen-to-screen. This lets the assessor see a control working, not just read about it.
- Physical Review — An in-person, on-site observation — for example, checking that a server room door locks properly or that visitor logs are being kept at the front desk.
In short: documents show intent, artifacts show proof of execution, and screen shares and physical reviews let the assessor directly observe your controls in action. Most requirements will call for a combination of these — so the earlier your team can map out where each type of evidence lives, the smoother the assessment will go.