Evidence

What counts as evidence?

Evidence is the documentation that proves your controls exist and are operating. Without evidence, an auditor cannot verify your claims — no matter how good your processes actually are.

Types of evidence

  • Policies and procedures — Written documents describing how you do something. Example: Access Control Policy, Incident Response Plan, Password Policy.
  • Screenshots — Visual proof that a technical control is configured. Example: Screenshot of MFA enabled in your identity provider, screenshot of your firewall rules.
  • Logs and reports — System-generated records showing activity. Example: Access review logs, security monitoring reports, vulnerability scan results.
  • Training records — Evidence that employees received security training. Example: Training completion report, signed acknowledgment forms.
  • Agreements and contracts — Signed documents. Example: Vendor agreements with security clauses, employee NDAs.
  • Test results — Results from security testing. Example: Penetration test report, disaster recovery test results.

What makes good evidence?

Auditor rule of thumb: Good evidence is specific, dated, and shows the control actually operating — not just that it exists on paper.

Good evidence:

  • Has a clear date or date range
  • Is specific to your company (not a generic template)
  • Shows the control working, not just being described
  • Is signed or approved by an appropriate person where relevant

Weak evidence:

  • Undated policies that could be written after the fact
  • Generic templates without your company's name
  • Screenshots without dates or company context

Evidence by control type

  • Access control (CC6.1–CC6.3) — Access control policy, user access list, screenshots of your identity provider settings, access review records.
  • Incident response (CC7.2) — Incident response plan, record of any incidents and how they were handled.
  • Monitoring (CC7.1) — Screenshots of monitoring tools configured, alerting rules, sample alert notifications.
  • Risk assessment (CC3.1–CC3.2) — Written risk assessment document, risk register.
  • Disaster recovery (A1.3) — Disaster recovery plan, results of a DR test.
  • Privacy notice (P1.0) — Link to or copy of your published privacy policy.