Confidential — Internal Use Only
Customer Kickoff Guide + Evidence Repo Strategy
Domains
6
Practice families
Practices
17
All must be MET
Cadence
Annual
Self-assessment cycle
Submission
SPRS
+ Senior Official Affirmation
The DoD doesn't mandate a specific tool — but they DO require evidence to be secure, controlled-access, and retrievable for the annual affirmation cycle. Here's the tiered approach by maturity:
🏆 Recommended — GCC High SharePoint / OneDrive
Microsoft 365 GCC High or GCC (M365 Business Premium minimum)
Folder structure below ↓
Strong Alternative — Google Workspace (Gov edition) or AWS GovCloud S3
If customer is already on Google or AWS ecosystem
Dedicated GRC Platform — Vanta, Drata, or Scrut.io
Best if customer plans to grow to Level 2 or has multiple frameworks (SOC 2, HIPAA)
Avoid — Personal Dropbox, non-GCC OneDrive, or local shared drive
Consumer-grade storage is not appropriate for FCI evidence. Fails the access control and audit log requirements.
Recommended Folder Structure (SharePoint / GCC)
📁 CMMC-L1-Evidence/
📁 00_Governance/
→ System Security Plan (SSP), Scope Statement, Asset Inventory
📁 01_Access-Control (AC)/
→ AD/Entra screenshots, MFA policy, user account list
📁 02_Identification-Authentication (IA)/
→ Password policy, MFA enrollment proof
📁 03_Media-Protection (MP)/
→ Sanitization policy, disposal records
📁 04_Physical-Protection (PE)/
→ Access logs, facility control documentation
📁 05_System-Comms-Protection (SC)/
→ Firewall rules, network diagram, encryption configs
📁 06_System-Info-Integrity (SI)/
→ AV/EDR proof, patch management records, update logs
📁 07_Annual-Assessment-Records/
→ Signed checklist, SPRS submission screenshot, affirmation record
Access Control (AC) — 4 practices
Identification & Authentication (IA) — 2 practices
Media Protection (MP) — 1 practice
Physical Protection (PE) — 4 practices
System & Comms Protection (SC) — 2 practices
System & Info Integrity (SI) — 4 practices
Pre-Meeting Preparation
Meeting Agenda (90 min suggested)
Welcome + Context Setting
Walk the 17 Practices — High Level
Assign Owners + Set Status (Live Tracker Walk)
Evidence Repo Setup + Document Roles
Project Plan + Timeline
SPRS + Affirmation — Explain the End State
Based on CMMC 2.0 Final Rule · DoD Assessment Guide Level 1 v2.0 · Phase 1 enforcement Nov 10 2025