FeaturesCompliance Reports

CMMC Level 2 Evidence Report

Generate CMMC Level 2 / NIST SP 800-171 compliance evidence for your C3PAO assessment — covering change management, CODEOWNERS enforcement, risk identification, and review quality.

Overview

The Cybersecurity Maturity Model Certification (CMMC) is a DoD requirement for contractors in the Defense Industrial Base (DIB). Level 2 maps to NIST SP 800-171 and is required for any contractor handling Controlled Unclassified Information (CUI).

Koalr's CMMC report generates an evidence package suitable for review by a certified Third-Party Assessment Organization (C3PAO) during your formal assessment. It covers four practices directly addressable by engineering change management data.

Practices covered

CM.L2-3.4.9 — Control and Monitor User-Installed Software

Control language: Control and monitor user-installed software.

Koalr evidence: All code changes are peer-reviewed and risk-scored before merging into protected branches. Every merged pull request in the reporting period is captured with author, reviewer, approval state, and merge timestamp.

CA.L2-3.12.3 — Monitor Security Controls

Control language: Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Koalr evidence: CODEOWNERS rules are enforced on every pull request. Violations are logged and must be resolved before merge. The report surfaces the full list of CODEOWNERS-compliant vs non-compliant merges.

SI.L2-3.14.1 — Identify and Correct Information System Flaws

Control language: Identify, report, and correct information and information system flaws in a timely manner.

Koalr evidence: Deploy risk scoring identifies high-risk changes (DDL migrations, coverage drops, blast radius) before they are merged. Every change gets a 0–100 risk score with signal breakdown.

CA.L2-3.12.1 — Periodically Assess Security Controls

Control language: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

Koalr evidence: Review quality is continuously monitored. Rubber-stamp approvals (under 2 minutes, zero comments) and missing required reviewers are flagged as evidence of control effectiveness issues.

Report output

The CMMC report produces two artifacts:

PDF evidence package

A fully formatted PDF with:

  • Dark navy cover page with Koalr branding, practice coverage badges, and metadata block prepared for C3PAO review
  • Executive summary page with six KPI tiles (total merged PRs, approved before merge, no reviewer activity, high/critical risk, CODEOWNERS violations, DDL migrations)
  • Per-practice detail pages with evidence count, status badge, and a full table of in-scope pull requests
  • Change management table (CM.L2-3.4.9) listing all merged PRs with approval evidence
  • CODEOWNERS table (CA.L2-3.12.3) listing compliant and non-compliant merges
  • Risk / flaw table (SI.L2-3.14.1) listing risk-scored PRs with top signals and DDL flag
  • Review quality table (CA.L2-3.12.1) listing approval counts, review comments, and rubber-stamp flags
  • Page number footer with CONFIDENTIAL marking on every page

CSV export

A flat CSV with every merged PR in the period and all evidence fields: PR #, Title, Repository, Author, Merged At, Approvals, Reviewers, CODEOWNERS OK, Risk Score, Risk Level, DDL Migration, Changed Files, Additions, Deletions

Generating a report

  1. Navigate to Compliance in the Koalr sidebar
  2. Click CMMC Level 2
  3. Select a reporting period (default: last 90 days)
  4. Choose either all practices (combined report) or a single practice filter
  5. Click Download Evidence Package (PDF) or Export CSV

Integration requirements

To generate a CMMC report, Koalr must be connected to:

  • GitHub (required) — provides PRs, reviews, CODEOWNERS files, commit history
  • Optional enhancements: CI integration for test coverage signals, PagerDuty/OpsGenie for incident correlation

C3PAO review notes

When handing the report to your C3PAO:

  • The PDF cover page explicitly names "CMMC Third-Party Assessment Organization (C3PAO)" in the Prepared For field
  • Every page is marked CONFIDENTIAL in the footer
  • Evidence is generated point-in-time from live data — re-running the report for the same period produces identical output as long as the underlying data has not changed
  • Koalr does not modify or summarize PR titles, reviewer logins, or timestamps — the evidence table is a direct projection of your GitHub activity
  • For controls requiring additional non-technical evidence (e.g., personnel security, physical access), use Koalr's PDF alongside your broader compliance documentation

Disclaimer

This report is designed to support CMMC evidence collection. It does not constitute a formal assessment. Engage a certified C3PAO for official CMMC Level 2 certification.