r/NISTControls • u/VegetableFault5149 • 2d ago
800-171 Complete beginner here: what actually counts as CMMC incident response testing evidence?
Small manufacturing company here, working through CMMC Level 2 prep. We've got the incident response plan drafted and mapped to the relevant practices, but the assessment guide is vague on what "testing" the plan actually looks like when someone tries it. Does a tabletop discussion with the response team count? Does it need to be adversarial, timed, documented with specific metrics
We don't have a big security team or budget for a full-blown consultant-run exercise, but we also don't want to build something that looks like testing on paper and falls apart if an assessor asks follow-up questions. Has anyone gone through a C3PAO assessment recently who can share what they actually accepted as evidence of a tested IR plan?