Access Control in CMMC: Why Quarterly Reviews Aren’t Enough

Access control failures are the most common reason contractors fail CMMC assessments. Learn exactly what C3PAO assessors examine and what documentation proves operating effectiveness.

Understanding CMMC access control audit evidence requirements is the highest-leverage preparation work a defense contractor can do — because access control is where most assessments fail. Here’s a pattern I’ve seen over and over in readiness work with contractors who failed a prior assessment: the company had excellent policy documentation, good incident response, solid change management. And they failed anyway, because when the assessor asked for proof that access was reviewed, revoked, and monitored on a schedule, the evidence simply wasn’t there. This article breaks down exactly what assessors examine and what documentation actually proves operating effectiveness — a bar the July 2026 suspension of third-party assessments didn’t lower, because it’s the same evidence a defensible self-assessment and a prime’s supplier review stand on.

Why Access Control Sinks More Assessments Than Any Other Domain

The access control family in NIST SP 800-171 contains 22 practices — the largest of the 14 domains. More practices mean more evidence obligations, and more places for a well-intentioned program to leak. But volume isn’t the real reason contractors fail here.

The real reason is that access control is a living system. Firewall rules can sit unchanged for a year and still be correct. Access can’t. People join, change roles, leave, and accumulate permissions. A contractor’s access picture from six months ago is always wrong today — which is exactly why CMMC treats the review cycle, not the policy, as the control. A policy describes intent. The recurring review is the mechanism that keeps intent and reality aligned, and it’s the mechanism assessors test.

The Five Artifacts Assessors Ask For

When a C3PAO assessor works through the access control practices, the requests are predictable. Five artifacts come up in virtually every assessment:

  • Dated access reviews. Not a policy that says reviews happen — the actual review records, with dates, the reviewer’s signature, the accounts examined, and the exceptions found.
  • A role-based access matrix. Which roles exist, what each can reach, and the business justification. If your matrix says “engineer” and your directory shows an engineer with domain admin rights, expect a finding.
  • Termination checklists. Completed ones, showing account disablement within your stated window, credential recovery, and badge collection — for real departures, with dates.
  • Access logs. Records showing who accessed CUI systems and when, plus proof that someone actually reviews those logs on a schedule.
  • Exception documentation. Every deviation — the contractor who kept access past the end date, the shared account you can’t eliminate yet — documented with justification, approval, and an expiry.

Most Tier 2 and Tier 3 contractors I work with have some of this. Very few have all of it — and CMMC requires all of it.

CMMC access control audit evidence requirements six-month timeline infographic
Six months of access control evidence: the cycle a C3PAO assessor expects to see

Why One Quarterly Review Isn’t Enough

Here’s the trap in the title of this article. Contractors hear “quarterly access reviews” and conclude that running one review before the assessment checks the box. It doesn’t — for the same reason a single gym visit doesn’t constitute a fitness habit. A single review proves the control can exist. A repeated cycle proves it does exist. Assessors are trained to ask for the review before the most recent one, precisely because that’s what distinguishes a functioning program from assessment theater.

Operating effectiveness has a time dimension you cannot compress. If your assessment is six months out, you have time to produce two full review cycles — but only if you start the first one now. This is also the logic behind the evidence-collection phase of my 90-day CMMC readiness roadmap: the calendar, not the effort, is the limiting resource.

The same time logic applies to your multi-factor authentication rollout. MFA on CUI systems is non-negotiable under NIST SP 800-171, but assessors don’t just verify it’s enabled today — they look at enrollment records and authentication logs to confirm it’s been enforced, for everyone, without undocumented bypasses.

Building CMMC Access Control Audit Evidence Requirements Into Routine

The fix is not complicated, and that’s what makes access control failures so frustrating to watch. Here’s the minimal machinery that passes assessments:

  1. A documented access control policy that states review frequency, roles, and responsibilities — one page of substance beats twelve pages of boilerplate.
  2. A quarterly review process with a named owner. Calendar it. The owner pulls the account list, compares it to the role matrix, flags deviations, gets sign-off.
  3. A log of who was reviewed, with signatures. A spreadsheet with dates and initials is fine. Perfection isn’t the standard — consistency is.
  4. Change records for every access grant and revocation. Ticket, approval, timestamp. If your helpdesk tool does this automatically, you already have the evidence — you just need to be able to retrieve it.

That’s it. Three months of documented access reviews and you eliminate one of the most common failure points in CMMC assessments. The cost is a few hours per quarter. The alternative is failing a $15K–$30K assessment over a missing spreadsheet.

A 90-Day Priority Plan

If your assessment is roughly 90 days out, here’s how I’d sequence access control specifically. Days 1–15: build or update the role-based access matrix and reconcile it against reality — every account, every system in the CUI boundary. Days 16–30: run your first full documented review; expect it to be painful and to surface orphaned accounts. Days 31–60: fix what the review found, process the exceptions formally, and verify MFA coverage is total. Days 61–90: run the second review cycle — this one should be fast and boring, which is exactly what you want an assessor to see.

Two boring, well-documented review cycles are worth more at assessment time than any amount of policy prose. Boring is what operating effectiveness looks like.

Start With the Control That Fails First

Meeting the CMMC access control audit evidence requirements comes down to converting good intentions into dated artifacts on a schedule. If access control is where most assessments fail, it’s also where preparation pays off first — and it’s the domain I check first in every readiness engagement, because it predicts how the rest of the program looks.

If you’re 90 days from an assessment — or you’re not sure whether your review cycles would survive an assessor’s scrutiny — let’s find out before it costs you. Schedule a discovery call and we’ll walk through your access control evidence together.