Evidence
What counts as evidence?
Last updated July 2026 · 5 min read
Evidence is the documentation that proves your controls exist and are operating. Without evidence, an auditor cannot verify your claims — no matter how good your processes actually are.
Types of evidence
- Policies and procedures — Written documents describing how you do something. Example: Access Control Policy, Incident Response Plan, Password Policy.
- Screenshots — Visual proof that a technical control is configured. Example: Screenshot of MFA enabled in your identity provider, screenshot of your firewall rules.
- Logs and reports — System-generated records showing activity. Example: Access review logs, security monitoring reports, vulnerability scan results.
- Training records — Evidence that employees received security training. Example: Training completion report, signed acknowledgment forms.
- Agreements and contracts — Signed documents. Example: Vendor agreements with security clauses, employee NDAs.
- Test results — Results from security testing. Example: Penetration test report, disaster recovery test results.
What makes good evidence?
Auditor rule of thumb: Good evidence is specific, dated, and shows the control actually operating — not just that it exists on paper.
Good evidence:
- Has a clear date or date range
- Is specific to your company (not a generic template)
- Shows the control working, not just being described
- Is signed or approved by an appropriate person where relevant
Weak evidence:
- Undated policies that could be written after the fact
- Generic templates without your company's name
- Screenshots without dates or company context
Evidence by control type
- Access control (CC6.1–CC6.3) — Access control policy, user access list, screenshots of your identity provider settings, access review records.
- Incident response (CC7.2) — Incident response plan, record of any incidents and how they were handled.
- Monitoring (CC7.1) — Screenshots of monitoring tools configured, alerting rules, sample alert notifications.
- Risk assessment (CC3.1–CC3.2) — Written risk assessment document, risk register.
- Disaster recovery (A1.3) — Disaster recovery plan, results of a DR test.
- Privacy notice (P1.0) — Link to or copy of your published privacy policy.