Exercise

Perform a Mock Evidence Review

Play the assessor: decide whether sample artifacts actually prove the control claimed.

Intended audience
Program owners preparing for review
Difficulty
Intermediate
Estimated time
20 minutes
Access
Free
CMMC
SOC 2
NIST SP 800-171
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Evaluate sample compliance artifacts the way an assessor would, deciding accept, accept with note, or reject.
  • Identify the specific defect (missing date, missing approval, incompleteness) that would cause an artifact to be rejected.
  • Propose the single fix that would make a rejected artifact acceptable.
  • Apply the same rigor to the reader's own evidence as to the sample artifacts.
  • Understand why an artifact must prove not just that a control exists, but that it existed as of a specific point in time.

Artifacts to judge

  • A screenshot of an MFA settings page with no date visible.
  • A policy document with no approval or version.
  • A backup success email from fourteen months ago.
  • A training spreadsheet listing three of nine employees.
  • An access review with a reviewer name and date, but no decisions recorded.

Key takeaways

  • Evidence must prove what a control does and when, so undated screenshots and documents are rarely acceptable on their own.
  • A policy document without approval or version control cannot demonstrate that it reflects a current, authorized state.
  • Evidence that is technically true but stale, such as a fourteen-month-old backup confirmation, does not prove a control is operating now.
  • Partial evidence, like a training list covering only some employees, should be flagged as incomplete rather than accepted outright.
  • The most useful review habit is being at least as critical of one's own evidence as of unfamiliar sample artifacts.

Practice workspace

  1. Hint: Ask what the artifact proves, and as of when.

  2. Hint: Usually a date, an approval, or completeness.

  3. Hint: Be as harsh with yours as with the samples.

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 1
Knowledge check

80% required to pass. Answers are graded on our servers.

1. A screenshot of an MFA settings page with no visible date should generally be treated as:

2. What is the primary defect in a policy document with no approval or version noted?

3. Why is a backup success email from fourteen months ago problematic as evidence?

4. A training spreadsheet listing three of nine employees is best judged as:

5. An access review with a reviewer name and date but no recorded decisions is missing what?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Matched on shared frameworks, topics, and program packs.

Checklist

Evidence Collection Checklist

Turn what you already do into evidence: what to capture, how to label it, and how long to keep it.

Intermediate
25 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Quick reference

Evidence Collection Tips — One Page

A pocket guide to capturing artifacts that will still make sense in six months.

Beginner
4 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Guide

How to Collect Compliance Evidence

What counts as evidence, how to capture it without slowing the business, and how to keep it usable.

Intermediate
11 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Guide

Preparing for a Security Assessment

The six weeks before an assessment, sequenced: documentation, evidence, owner rehearsal, and gap honesty.

Advanced
15 min
Premium
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.