The CMMC Assessment Process (CAP) requires that sufficient evidence must:
Cover the sampled organization,
Cover the defined model scope of the assessment (Target CMMC Level), and
Correspond to the evidence collection approach.
Evidence is always required, even if the organization holds other certifications such as ISO. External certifications cannot replace CMMC evidence requirements. Thus, the statement that “Evidence is not required if the practice is ISO certified” is not valid.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit