Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Which matters more for CMMC Level 2, policies…
Governance, Ownership & Risk

Which matters more for CMMC Level 2, policies or operational proof?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Operational proof matters more, because assessors must validate that controls are implemented correctly and functioning in practice. Policies establish intent, but CMMC Level 2 is about evidence that the environment actually behaves as the policy claims. The organisations that struggle most are usually the ones with documentation but little repeatable proof of control operation.

Why CMMC Level 2 Favors Evidence Over Policy Language

CMMC Level 2 is not won by having polished policy documents alone. Assessors are looking for proof that controls are operating as described, consistently and in the real environment. A policy may show intent, but operational evidence shows whether the control is actually working, whether staff follow it, and whether exceptions are handled in a repeatable way.

That distinction matters because documentation can be clean while execution is weak. A policy can say access is reviewed, logs are retained, or configurations are hardened, yet the stronger signal is whether those activities produce artefacts that can be traced, sampled, and validated during assessment.

What Counts as Operational Proof in Practice

Operational proof is the collection of records, system outputs, tickets, logs, screenshots, reports, and change history that demonstrate a control exists and functions over time. For CMMC Level 2, the question is usually not “do you have the policy?” but “can you show the control being applied, not just described?” That means evidence should connect policy statements to actual events, configuration states, and human actions.

Good proof is usually repeatable and attributable. For example, access reviews should leave behind dated review records, remediations should show closure, logging controls should produce visible log entries, and configuration standards should be reflected in current system state. The assessor is testing both design and operation, so the evidence needs to be current enough to prove continuity rather than a one-time success.

Operational proof is stronger when it comes from the control itself, not from a manual explanation of the control. A recurring export from the system, a workflow record, or a management report is more credible than a narrative assertion that “we always do this.”

How to Read the Difference Between a Control and Its Evidence

The practical test is whether the artefact demonstrates behaviour. Policies define expected behaviour; evidence shows observed behaviour. If the artefact only repeats the rule, it is still policy. If it shows the control in action, it becomes proof. That is why CMMC assessments often hinge on whether organisations can produce both the governing statement and the operational trail behind it.

This also changes how teams should prepare. A document set without supporting operational records can create false confidence. By contrast, a smaller set of controls with clean, repeatable evidence often performs better than a larger set of controls that cannot be demonstrated consistently. The assessment risk is usually not the absence of intent, it is the absence of verifiable execution.

For teams mapping their control environment to formal baselines, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful because it reinforces the difference between policy-like control statements and evidence that supports assessment of control operation. For operational resilience and repeated validation expectations, EU Digital Operational Resilience Act (DORA) illustrates the same principle: controls matter most when they can be shown to work under scrutiny, not merely when they are documented.

Risk and Threat Considerations

The main risk is assessment failure caused by a gap between declared control and actual operation. That gap can hide weak access reviews, stale configurations, unexecuted logging, or unmanaged exceptions, all of which create real security exposure even when the policy set looks complete. In practice, documentation can mask a control failure until someone asks for proof.

Failure mechanism: Teams rely on written policy as evidence, but the assessor needs artefacts showing the control was performed, observed, and repeated. Where logs, tickets, review records, or system outputs are missing or inconsistent, the control cannot be demonstrated even if the policy is well written.

Impact: The organisation may fail the assessment, but the larger consequence is operational blind spots that persist after the audit. If the control is not producing evidence, it often is not producing protection either.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingCMMC evidence hinges on proving controls operate through logs and review outputs.
CA-2 — Control AssessmentsCMMC Level 2 assessment logic depends on verified control operation, not policy text alone.
CM-6 — Configuration SettingsOperational proof often comes from system configuration state matching documented baselines.
Recommendation — Produce recurring audit evidence showing logs are reviewed and anomalies are acted on. Collect assessment-ready evidence that each control is implemented and functioning. Verify live configurations match approved secure settings and retain supporting records.
CIS Controls v8CIS-4 — Secure Configuration of Enterprise Assets and SoftwareDemonstrates the need for visible, repeatable configuration evidence over written intent.
Recommendation — Validate secure baselines with observable system evidence and exception records.
NIST CSF 2.0GV.OV-01 — Oversight of cybersecurity risk management strategyCMMC readiness needs governance that can prove controls are monitored and validated.
Recommendation — Establish oversight that requires operational evidence for control validation.

Practitioner Guidance

What to prioritise: Build evidence around the controls most likely to be sampled, especially access reviews, logging, configuration management, and remediation tracking. If a control cannot produce recurring artefacts with timestamps and ownership, treat it as immature.

What to verify: Check that every policy statement has a matching operational trace. The best test is simple: if an assessor asked for proof today, could you show not just the rule, but the last few instances where the rule was executed and closed out?

Common mistake: Treating annual policy review as equivalent to operational control. A current policy with no repeatable evidence usually scores as intent, not assurance.

Practitioner takeaway: For CMMC Level 2, policy is necessary, but proof is what earns confidence, so prepare the environment to demonstrate control behaviour, not just control intention.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org