CMMC Level 2 Evidence Report
Generate CMMC Level 2 / NIST SP 800-171 compliance evidence for your C3PAO assessment — covering change management, CODEOWNERS enforcement, risk identification, and review quality.
Overview
The Cybersecurity Maturity Model Certification (CMMC) is a DoD requirement for contractors in the Defense Industrial Base (DIB). Level 2 maps to NIST SP 800-171 and is required for any contractor handling Controlled Unclassified Information (CUI).
Koalr's CMMC report generates an evidence package suitable for review by a certified Third-Party Assessment Organization (C3PAO) during your formal assessment. It covers four practices directly addressable by engineering change management data.
Practices covered
CM.L2-3.4.9 — Control and Monitor User-Installed Software
Control language: Control and monitor user-installed software.
Koalr evidence: All code changes are peer-reviewed and risk-scored before merging into protected branches. Every merged pull request in the reporting period is captured with author, reviewer, approval state, and merge timestamp.
CA.L2-3.12.3 — Monitor Security Controls
Control language: Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
Koalr evidence: CODEOWNERS rules are enforced on every pull request. Violations are logged and must be resolved before merge. The report surfaces the full list of CODEOWNERS-compliant vs non-compliant merges.
SI.L2-3.14.1 — Identify and Correct Information System Flaws
Control language: Identify, report, and correct information and information system flaws in a timely manner.
Koalr evidence: Deploy risk scoring identifies high-risk changes (DDL migrations, coverage drops, blast radius) before they are merged. Every change gets a 0–100 risk score with signal breakdown.
CA.L2-3.12.1 — Periodically Assess Security Controls
Control language: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
Koalr evidence: Review quality is continuously monitored. Rubber-stamp approvals (under 2 minutes, zero comments) and missing required reviewers are flagged as evidence of control effectiveness issues.
Report output
The CMMC report produces two artifacts:
PDF evidence package
A fully formatted PDF with:
- Dark navy cover page with Koalr branding, practice coverage badges, and metadata block prepared for C3PAO review
- Executive summary page with six KPI tiles (total merged PRs, approved before merge, no reviewer activity, high/critical risk, CODEOWNERS violations, DDL migrations)
- Per-practice detail pages with evidence count, status badge, and a full table of in-scope pull requests
- Change management table (CM.L2-3.4.9) listing all merged PRs with approval evidence
- CODEOWNERS table (CA.L2-3.12.3) listing compliant and non-compliant merges
- Risk / flaw table (SI.L2-3.14.1) listing risk-scored PRs with top signals and DDL flag
- Review quality table (CA.L2-3.12.1) listing approval counts, review comments, and rubber-stamp flags
- Page number footer with CONFIDENTIAL marking on every page
CSV export
A flat CSV with every merged PR in the period and all evidence fields:
PR #, Title, Repository, Author, Merged At, Approvals, Reviewers, CODEOWNERS OK, Risk Score, Risk Level, DDL Migration, Changed Files, Additions, Deletions
Generating a report
- Navigate to Compliance in the Koalr sidebar
- Click CMMC Level 2
- Select a reporting period (default: last 90 days)
- Choose either all practices (combined report) or a single practice filter
- Click Download Evidence Package (PDF) or Export CSV
Integration requirements
To generate a CMMC report, Koalr must be connected to:
- GitHub (required) — provides PRs, reviews, CODEOWNERS files, commit history
- Optional enhancements: CI integration for test coverage signals, PagerDuty/OpsGenie for incident correlation
C3PAO review notes
When handing the report to your C3PAO:
- The PDF cover page explicitly names "CMMC Third-Party Assessment Organization (C3PAO)" in the Prepared For field
- Every page is marked CONFIDENTIAL in the footer
- Evidence is generated point-in-time from live data — re-running the report for the same period produces identical output as long as the underlying data has not changed
- Koalr does not modify or summarize PR titles, reviewer logins, or timestamps — the evidence table is a direct projection of your GitHub activity
- For controls requiring additional non-technical evidence (e.g., personnel security, physical access), use Koalr's PDF alongside your broader compliance documentation
Disclaimer
This report is designed to support CMMC evidence collection. It does not constitute a formal assessment. Engage a certified C3PAO for official CMMC Level 2 certification.
Compliance Reports Overview
Audit-ready evidence packages for engineering change management across CMMC, SOC 2, ISO 27001, PCI-DSS, ITIL CAB, and FedRAMP.
SOC 2 Type II Evidence Report
Automate SOC 2 Type II change management evidence collection. Maps PR review records, deployment controls, and risk scoring to Trust Services Criteria CC8.1, CC6.1, and CC9.2.