You must maintain evidence for all implemented controls including account management records, system inventories, policies, training records, and technical configurations.
Maintaining appropriate evidence is crucial both for demonstrating compliance during the self-assessment process and for substantiating your certification if questions arise.
Understanding documentation requirements helps organizations establish sustainable processes rather than scrambling to recreate evidence when needed.
For Level 1, you must keep evidence for the duration of your attestation cycle, or at least one year, whichever is longer.
Since Level 1 requires annual renewal, this means maintaining at least 12 months of documentation at any given time.
For Level 2 (when it becomes available), longer retention periods will likely apply given the tri-annual external assessment cycle.
From a practical perspective, many organizations maintain evidence for longer periods to demonstrate security posture trends over time and for potential audit or incident investigation purposes.
Maintain current lists of all user accounts showing names, roles, system access permissions, account creation dates, account modification dates, and current status (active, disabled, deleted).
Document quarterly account reviews showing who reviewed accounts, when reviews occurred, and what actions were taken.
Keep records of access requests, approvals, and justifications for privileged access. This documentation proves you're actively managing accounts rather than letting permissions accumulate unchecked.
A spreadsheet or database works well, especially if integrated with HR systems to trigger updates automatically when employment status changes.
Maintain an inventory of systems approved for handling Specified Information, including system names, purposes, owners, and security features.
Document device inventories listing all corporate laptops, mobile devices, and external drives with asset numbers, assigned users, and approval dates.
Keep vendor security assessments for cloud services showing evaluation of data location, encryption, MFA capabilities, and other security features.
This documentation proves you've thoughtfully evaluated and approved systems rather than allowing employees to use whatever tools they prefer without oversight.
Maintain current copies of all security policies. These should include the following types of policies:
Include version control and approval documentation showing policies are periodically reviewed and updated.
Policies should be dated and signed by appropriate authorities (typically IT leadership and executive management).
Document security training provided to employees, including attendance records, training materials, dates conducted, and content covered.
Maintain records showing employees understand what Specified Information looks like and how to prevent public disclosure.
Keep checklists or approval records for reviewing public-facing content before publication.
This demonstrates your organization isn't just hoping employees intuitively understand security requirements but actively training them on their responsibilities.
Maintain configuration documentation showing security settings for systems, networks, and applications.
Keep logs of security updates and patches applied, including what was updated, when, and by whom.
Maintain antivirus scan logs showing regular scanning is occurring and how detected threats were addressed.
Document firewall rules and network segmentation showing separation between public and internal systems.
Generate MFA enrollment records showing which accounts have multifactor authentication enabled.
This technical evidence proves controls are genuinely implemented in your technology environment, not just described in policies.
Maintain current lists of who has physical access to areas containing Specified Information, including key and badge assignments, access codes, and approval dates.
Keep visitor logs (paper or electronic) documenting all visitors to sensitive areas, escort procedures, and visit purposes.
Document physical access reviews showing periodic verification that only authorized personnel have access.
This creates accountability for physical security and demonstrates you're managing access as carefully for physical entry as for network access.
Maintain detailed logs of all media destruction activities. Your logs should capture the following information:
Include certification of complete destruction for items that contained Specified Information.
This documentation proves you haven't simply thrown old equipment in the trash where someone could retrieve data from it.
If security incidents occur, maintain detailed records. Your incident documentation should include the following elements:
Even if no incidents occur, document your incident response testing and training activities.
This demonstrates you have functional processes for responding to security events, not just theoretical plans.
Establish a systematic approach to organizing evidence. Consider implementing the following practices:
The evidence you maintain for CPCSC compliance is itself often sensitive and should be treated with appropriate security.
The most successful approach to evidence maintenance is building documentation into normal business processes rather than treating it as a separate compliance exercise.
For example, when your IT team applies security updates, they should routinely log what was updated as part of that workflow.
When HR offboards an employee, they should follow a checklist that includes documenting account deactivation.
When your communications team publishes content, their approval process should document the security review.
This "built-in" approach is more sustainable and reliable than trying to reconstruct evidence periodically.
For additional information, consult the following resource:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)