Skip to content
← Back to documentation

Collecting evidence

Evidence is what turns a written policy into something an auditor can verify. The Evidence Library stores your supporting documents, links each one to the control it proves, and timestamps everything so you can show your work.

What counts as evidence

Evidence is any artifact that demonstrates a control is actually in place — a signed policy, a screenshot of a configured setting, an access-review export, a training completion record, a vendor DPA. If a control says you do something, the evidence proves you do it.

Upload a document

  • Open the Evidence Library from the dashboard sidebar.
  • Choose "Upload" and select the file (PDF, image, or document).
  • Add a short description so the artifact is easy to find later.
  • Link it to one or more controls so it shows up against the right requirement.

CMMC evidence

For CMMC, you can upload evidence straight from the CMMC Evidence vault and link it to specific NIST SP 800-171 controls. Each control then shows the evidence that backs it, which is exactly what a C3PAO assessor walks through.

Timestamps and audit trail

Every upload is timestamped and recorded in your audit trail. Evidence is private to your organization and is never shared with anyone outside it.

Export

You can export your evidence and its manifest at any time — useful for handing a package to an assessor or keeping an offline copy. See the data export guide for details.

Collecting evidence — Aegis Firma Docs