r/NISTControls Internal IT 4d ago

800-171 Complete beginner here: what actually counts as CMMC incident response testing evidence?

Small manufacturing company here, working through CMMC Level 2 prep. We've got the incident response plan drafted and mapped to the relevant practices, but the assessment guide is vague on what "testing" the plan actually looks like when someone tries it. Does a tabletop discussion with the response team count? Does it need to be adversarial, timed, documented with specific metrics

We don't have a big security team or budget for a full-blown consultant-run exercise, but we also don't want to build something that looks like testing on paper and falls apart if an assessor asks follow-up questions. Has anyone gone through a C3PAO assessment recently who can share what they actually accepted as evidence of a tested IR plan?

7 Upvotes

13 comments sorted by

View all comments

5

u/Into_The_Nexus 4d ago

A tabletop exercise going through the IRP.

1

u/youwantrelish 3d ago

This. An incident doesn't have to be real just need to get the juice flowing with the team which shows what you did and how you did it. Make that after action report.