---
title: Understanding Adequacy and Sufficiency in CMMC Evidence
description: Learn what adequacy and sufficiency mean for CMMC assessment evidence. Get checklists and examples to ensure your evidence passes — complete guide.
---

[Skip to content](https://support.futurefeed.co/knowledge-base/hc/en-us/articles/38793819646740-understanding-adequacy-and-sufficiency-in-cmmc-evidence#main-content)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=400&height=99&name=FutureFeed-White-Green-SupportCenter.png)](https://support.futurefeed.co/?hsLang=en)

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

Open main navigation

Close main navigation

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

 FutureFeed's Knowledge Base

- There are no suggestions because the search field is empty.

1. [FutureFeed Support](https://support.futurefeed.co/knowledge-base?hsLang=en)
2. [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en)
3. [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#cmmc-program-regulation-guidance)

# Understanding Adequacy and Sufficiency in CMMC Evidence

When preparing for a CMMC assessment, its critical to understand what **adequacy** and **sufficiency** mean in the context of your evidence. These terms guide assessors in determining whether your submitted evidence appropriately and completely supports that you meet the security requirements and assessment objectives.

 

#### TL;DR (Too Long; Didnt Read)

This is your quick summary of what matters most.

- **Adequacy means youre showing the right thing.** Your evidence must align with the security requirement it is being provided for.
- **Sufficiency means youre showing enough.** You must provide enough proof that the requirement is fully implemented across all applicable in-scope assets and that it is operationalnot just documented.
- **You need both adequacy and sufficiency to pass.**
- Quick Self-Test: 
    - **Adequate?** Is this the right evidence? Does this evidence directly align with the control and the requirement it is being provided for?
    - **Sufficient?** Does this evidence fully prove the control/requirement is properly implemented across all in-scope assets and is working as intended?

If youre short on time, this is the **bottom line up front (BLUF)**but keep reading for detailed examples, common pitfalls, and best practices for reviewing your CMMC evidence.

 

---

 

**Understanding Controls, Requirements, and Evidence**

 

![Screenshot 2025-07-01 at 12.41.27 PM](https://support.futurefeed.co/hs-fs/hubfs/Screenshot%202025-07-01%20at%2012.41.27%20PM.png?width=478&height=201&name=Screenshot%202025-07-01%20at%2012.41.27%20PM.png)

 

Before we dive into adequacy and sufficiency, its important to understand the difference between **controls** and **requirements.**

- **Requirement:** What you are required to do.
- **Control:** The system, process, or combination of both that you put in place to meet the requirement.

 

#### **Example:**

Your company requires **limiting system access to only authorized users.**  
To meet this requirement, you:

- Deploy access control software.
- Implement system settings that require username, password, and multi-factor authentication.
- Establish administrative processes to: 
    - Request, review, approve, and document authorized access.
    - Create and deactivate user accounts.
    - Periodically review active accounts to ensure no stale or unauthorized access exists.

Together, these processes and tools make up the **control.**

 

### **What is Evidence?**

**Evidence** is the proof that your controls are implemented and working. It demonstrates that you are meeting the requirementnot just in documentation, but in actual operations.

Evidence typically comes from:

- **Documents:** Policies, procedures, screenshots, system logs, configurations, completed forms.
- **Interviews:** Conversations with staff who perform the security activities.
- **Demonstrations:** Showing the control in action (e.g., logging in, system settings, security scans).

 

**Key Principle:**

If you tell an assessor youre doing something, **you need to prove it.**

 

#### **Example: Linking Evidence to Controls and Requirements**

 

| **Requirement:** |  |
| --- | --- |
| Limit logical access to an information system to only authorized users. |  |
| **Control:** |  |
| To meet the above requirement, your organization chooses to **restrict logical access** to the information system to only authorized users of that system (**Ref #1**). To enforce this, you implement **access control software** (**Ref #2**) and deploy **security configuration settings** (**Ref #3**) that require users to authenticate using an account, username, password, and multi-factor authentication. You also establish several **administrative processes** to manage access: - A process for using a form to **request, review, approve, and document authorized access** (**Ref #4**). - A process for **creating information system accounts** (**Ref #5**) for new users who need access. - A process to **deactivate accounts** (**Ref #6**) when access is no longer required. - A process to **audit account creation and deactivation** by regularly reviewing all active accounts on a defined schedule (**Ref #7**) to ensure there are no stale or unauthorized accounts remaining in the system. |  |
| **Ref #** | **Evidence - Proof That You Have:** |
| #1 | Successfully restricted logical access to that information system to only authorized users of that information system. Potential evidence: - Documentation or ability to identifying all authorized users (user lists) - System report of all current active accounts - Approved access request forms |
| #2 | Access Control Software - implemented and working as intended. Potential evidence: - Screen share showing tool use - Software license documentation - Interview with personnel responsible for managing the access control software |
| #3 | Deployed security configuration settings. Potential evidence: - Screenshots of configuration settings - Configuration reports - Configuration compliance scans - Interview with personnel responsible for administering the access control software |
| #4 | A process of using a form to request, review, approve, and document authorized access, a process for granting access and that you are using and following that process. Potential evidence: - Documentation defining the process - Completed access request forms - Interview with personnel responsible for requesting, reviewing, approving and authorizing access |
| #5 | A process for creating the information system accounts. Potential evidence: - Documentation defining the process - Interview with person responsible for creating information system accounts and following the defined process - Interview with personnel responsible for creating information system accounts. |
| #6 | A process to deactivate accounts and that you are using and following that process. Potential evidence: - Documentation defining the process - Data and time audit logs showing account deactivation activity is in alignment with employee's last day - Interview with personnel responsible for deactivating information system accounts. |
| #7 | A process to audit the account creation and deactivation processes by reviewing all active accounts on a defined frequency and that you are using and following that process. Potential evidence: - Documentation defining the process - Activity logs showing review activity history - Review outcome reports - Interview with personnel responsible for auditing active information system account |

---

 

**Adequacy and Sufficiency Explained**

 

![ChatGPT Image Jul 1, 2025, 12\_47\_42 PM](https://support.futurefeed.co/hs-fs/hubfs/ChatGPT%20Image%20Jul%201%2c%202025%2c%2012_47_42%20PM.png?width=248&height=165&name=ChatGPT%20Image%20Jul%201%2c%202025%2c%2012_47_42%20PM.png)

 

### **Adequacy**

**Adequacy means you are showing the right thing.**  
The evidence you provide must directly relate to the requirement and the control you have implemented.

- Does the evidence directly support the requirement?
- Does it prove the control that you say is in place?

 

### **Sufficiency**

**Sufficiency means you are showing enough.**  
The evidence must fully demonstrate that the control is fully implemented across all in-scope assets and is operational.

- Does the evidence cover all applicable system types, locations, and assets?
- Does it show the control is consistently enforcednot just documented?

---

 

### **Easy-to-Understand Examples**

### Example #1: Security Configuration Enforcement (CM-3.4.2)

**Requirement:** Establish and enforce security configuration settings for information technology products employed in organizational systems.

 

#### Adequate Evidence:

A current and approved baseline configuration document that:

- Covers all system types in scope for the CMMC assessment (e.g., Windows servers, Linux servers, network devices).
- Specifies security configuration settings for each system type.

This document demonstrates that your organization has formally defined baseline configurations and baseline security configuration settingsso its **adequate.**

 

#### Sufficient Evidence:

To be sufficient, you need to show the baseline configurations are actually applied and maintained across **all system types in scope:**

- System screenshots or configuration exports from both Windows and Linux servers showing the baseline settings are implemented.
- Change control records showing that baseline deviations were formally reviewed and approved.
- Configuration audit logs or system inventory scans demonstrating that baseline configurations are enforced across the environment.

If your assessment scope includes **multiple system types (e.g., Windows, Linux, Cisco routers),** evidence must exist for each. Providing evidence from only one system type is **insufficient.**

 

#### Incomplete (Insufficient) Example:

- If you provide the baseline configuration document but no operational proof, the evidence is **adequate but insufficient.**
- If you provide screenshots only from Windows systems but your environment also includes Linux servers, the evidence is **insufficient.**
- If you provide an outdated baseline document that no longer matches your current systems, the evidence is **inadequate and insufficient.**

 

 

### Example #2: Physical Access Control (PE-3.10.1)

**Requirement:** Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.

#### Adequate Evidence:

A current physical security policy that:

- Requires all employees and visitors to use badge access to enter the facility.
- States that visitors must sign in and be escorted at all times.

This is the **right type of evidence** because it directly supports the requirement and describes the control you've put in place to protect physical access.

 

#### Sufficient Evidence:

- Badge access logs showing who entered the building over the past 30 days.
- A completed visitor log showing escorted visitor activity.
- Photos or video demonstrating that badge readers are installed and in use.
- An interview with the security officer explaining how badge access is managed and how visitor escort requirements are enforced.

This shows the control is **actively enforced, operating across the entire facility, and consistently followed.**

 

### Insufficient Example:

Providing only the written security policy: Adequate but not sufficient. (It shows what you say you do but not that you actually do it.)

Providing outdated security procedures that no longer match your current badge system: Not adequate and Not sufficient.

 

---

 

 Best Practices for Evidence Review

 

When gathering evidence, ask yourself:

 

#### ✔️ Adequacy Checklist  "Am I showing the right thing?"

For each piece of evidence:

- Does the evidence directly map to the specific CMMC security requirement and its assessment objectives?
- Is the evidence current (reflects the present process, system configuration, or activity)?
- Is the evidence specific to the systems and processes in the assessment scope or compliance boundary?
- Does the evidence demonstrate the correct policy, process, procedure, configuration, or activity required by the control?
- If its a policy or procedure, is it approved, version-controlled, and assigned to the appropriate owner?
- If screenshots, logs, or system exports are provided, do they correctly identify the systems in scope?
- Is the evidence free of unrelated information that could cause confusion or misalignment?

 

#### ✔️ Sufficiency Checklist  "Am I showing enough to fully prove its real and working?"

For each requirement:

- Do I have operational evidence (not just policies or procedures) showing the control is actively in place?
- Is there evidence showing the control is implemented across **all applicable system types in scope?**  
  *(Example: If you have Windows, Linux, and Cisco devices, evidence must exist for each.)*
- Does the evidence include multiple proof points (e.g., screenshots, logs, records, system settings) as appropriate?
- Does the evidence cover the full timeframe being assessed?  
  *(For example: account reviews or system scans must reflect recurring or recent activities, not just one-time events.)*
- Are there records of enforcement and maintenance, such as approvals, reviews, or audit trails?
- If there are processes that apply to people, are there completed forms, approvals, or training records showing the process was followed?
- Have I reviewed the entire assessment scope and compliance boundary to ensure no system, location, or asset was missed?

 

#### ✔️ Final Self-Test

- Adequate? ✔️ Does this evidence correctly match the control and assessment objective?
- Sufficient? ✔️ Does this evidence fully prove the control is in place, working, and covers all in-scope systems?

 

---

 

#### Takeaway

 

You need both **adequate** and **sufficient** evidence to pass a CMMC assessment. Adequate evidence shows youre presenting the right information that directly maps to the control. Sufficient evidence shows that the control is fully implemented, enforced, and proven across the assessment scope.

By focusing on both elements, you will build a **strong, defensible body of evidence** that stands up to assessor scrutiny.

 

---

 

### **Need Further Assistance?**

 

📌 **Join Our Weekly Group Meeting**

If you need additional assistance, register for our **weekly group meeting**, where we address all FutureFeed and compliance related questions:

👉 [Register here](https://events.zoom.us/ev/AmLDLOd8zqhYjYcXChkYTHKczlJ3wQe2R3LI4V_tUvtbxJZDfQVV~AqP4ybcYayu_TF8iRvMNhLSsIog38wDE73T_GV55LaGpTO0WhXOj7B63ZA)

 

- [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#main-content)

    - [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#cmmc-program)
- [Product Information](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#main-content)

    - [Basic Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#basic-pricing)
    - [Advanced and Volume Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#advanced-and-volume-pricing)
    - [Features](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#features)
    - [Additional Details](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#additional-details)
    - [CMMC Express Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#cmmc-express-pricing)
- [How-to's](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#main-content)

    - [How-to... Build and Manage Projects in "Your FutureFeed"](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-build-and-manage-projects-in-your-futurefeed)
    - [How-to... Deliverables](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-deliverables)
    - [Other Features](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#other-features)
    - [How-to... Manage Tools, Services, and Documentation](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-tools-services-and-documentation)
    - [How To... Onboarding Rocket](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-onboarding-rocket)
    - [How-to... Big Picture](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-big-picture)
    - [How to... Work in the Assess Subway Stop](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-work-in-the-assess-subway-stop)
    - [How-to.... Manage People and Users](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-people-and-users)
    - [How To... Complete the SSP](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-complete-the-ssp)
    - [How to ... Manage a Marketplace Listing](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-a-marketplace-listing)
    - [How To.... Recurring Tasks](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-recurring-tasks)
- [Terminology](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#main-content)

    - [Glossary](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#glossary)
- [Getting started](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#main-content)

    - [Navigation](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#navigation)
    - [Subscription Management](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#subscription-management)
    - [Platform Access](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#platform-access)
    - [Compliance Standards - Background Information](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#compliance-standards-background-information)
- [Manage Compliantly](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#main-content)

    - [Technology Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#technology-subway-stop)
    - [Company Profile](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#company-profile)
    - [Deliverables Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#deliverables-subway-stop)
    - [Your FutureFeed Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#your-futurefeed-subway-stop)
    - [SSP Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#ssp-subway-stop)
- [Webinars and Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#main-content)

    - [NIST SP 800-171 R3](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#nist-sp-800-171-r3)
    - [2023 User Webinars](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#2023-user-webinars)
    - [Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#features)
- [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#main-content)

    - [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#cmmc-program-regulation-guidance)
- [FutureFeed Support](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#main-content)

    - [Product Information](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#product-information)
- [Frameworks](https://support.futurefeed.co/knowledge-base/frameworks?hsLang=en)
- [Tools and Services](https://support.futurefeed.co/knowledge-base/tools-and-services?hsLang=en)
- [Hawk AI](https://support.futurefeed.co/knowledge-base/hawk-ai?hsLang=en)
- [CMMC Fundamentals](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#main-content)

    - [SPRS & Compliance Reporting](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#sprs-compliance-reporting)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=300&height=74&name=FutureFeed-White-Green-SupportCenter.png "FutureFeed-White-Green-SupportCenter")](https://support.futurefeed.co/?hsLang=en)

FutureFeed Footer – Newest

## Footer

[1-844-725-8252](tel:14105605602) [support@futurefeed.co](mailto:support@futurefeed.co)

- [Facebook](http://facebook.com/FutureFeedCompliance/)
- [X (Twitter)](https://x.com/futurefeedco/)
- [LinkedIn](https://www.linkedin.com/company/futurefeed/)

Attain. Maintain. Prove It Anytime.

### Resources

- [15-Min with FutureFeed](https://zoom.us/meeting/register/WKkYTumjR6OOUjNRwZi91A#/registration)
- [User - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Partner - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Download the Everything Book](https://futurefeed.co/cmmc_guide/)

### Legal

- [Terms of service](https://futurefeed.co/terms/)
- [Privacy policy](https://futurefeed.co/privacy/)
- [Security](https://futurefeed.co/security/)
- [Legal](https://futurefeed.co/legal/)

©  FutureFeed.co. All rights reserved.

Disclaimer: The appearance of U.S. Department of Defense (DoD) visual information does not imply or constitute DoD endorsement.