Before you begin
- Select the correct Active client and Active program. Have the exact file to review and know its applicable requirement and period.
- Use an account authorized to upload and review evidence. A reviewer must assess the file itself; a hash check is not a sufficiency decision.
1. Upload a file into Evidence
- Open Evidence or Evidence Vault, depending on the active navigation view. Confirm the client/program at the top.
- Choose the Framework requirement, enter a descriptive Evidence title and record context in Notes. Example: “Privileged account review — October 2026”; include the actual owner and review period in your notes.
- Click Upload Manual Evidence and select the file. Wait for the upload to finish, then locate its row in the evidence list.
- Select the retained version and click Open Selected Version. Confirm that the content is the intended file. Click Verify SHA-256 to verify its retained bytes.
- When replacing evidence later, select the evidence record and use Upload New Version. Review and link the intended new version explicitly; do not assume every prior requirement link now refers to it.
Check before continuingThe evidence list contains the intended retained version, with the expected title/file and an integrity result.
2. Link the exact version to a requirement
- Open the active program’s requirements workspace and select the requirement row. The page name follows the framework, such as CMMC Requirements Workspace.
- Under Link evidence version, select the desired item in Evidence version to link. Use Preview selected evidence to confirm its content.
- Click Link selected version. Alternatively, Upload & link evidence uploads and links a new file directly from this workspace.
- Select the resulting entry in the linked-evidence list. Use Review linked evidence to record sufficiency; do not treat the Evidence sufficiency display as a substitute for the review dialog.
Check before continuingThe requirement lists the intended version. The link still needs a recorded review before it can be treated as sufficient.
3. Save a sufficiency decision
- In Review linked evidence, check the displayed requirement and file/version identity. Open or preview that exact version before choosing a decision.
- Enter Reviewer name. In Decision, choose Mark Sufficient, Request Changes or Reject.
- In Reason, write 20–4000 characters explaining the basis. For example: “Reviewed the October access-review export for all 12 in-scope administrators; the reviewer sign-off and two resolved exceptions are included.” Use facts from your actual review, not this example.
- Select I reviewed this exact version and its relevance, scope and freshness. Click Save review.
- Return to the requirement and confirm the linked evidence reflects the saved decision. Complete the remaining workpaper, sampling, independent approval and findings checks separately.
Check before continuingThe evidence link has a reviewer, decision and rationale tied to the reviewed version; unresolved workpaper gates remain visible.
If something goes wrong
Save review is refused
Check Reviewer name, a real decision, the 20-character minimum Reason and the review-confirmation checkbox.
The requirement still is not ready
Evidence sufficiency and requirement readiness are different. Review the other linked evidence, scope, workpaper and independent approval requirements.
The preview is unavailable
Use the supported Open Selected Version workflow to inspect the actual file. Do not mark it sufficient based only on its filename.