# P86-Assess Sample Evidence Checklist

Use this as a simple example of what the client sees during evidence collection.

## Upload These First

| Priority | Evidence | What Good Looks Like |
| --- | --- | --- |
| High | Vulnerability remediation SLA tracker | Severity, owner, due date, remediation date, closure evidence |
| High | MFA policy and platform export | Policy statement plus actual enforcement coverage from the named identity/VPN tools |
| Medium | Incident response tabletop tracker | Actions, owners, status, due dates, completion proof |
| Medium | Information security policy | Approved version, owner, review date, scope |

## Evidence Quality Rules

- Upload current evidence, not screenshots with missing dates.
- Include owner and approval context where possible.
- Evidence should prove operation, not only policy intent.
- If a questionnaire answer names software such as Entra ID, Okta, FortiGate, or GlobalProtect, request exports or configuration proof from that named platform.
- If evidence is rejected, upload a corrected version against the same request.

## Assessor Review Signals

| Signal | Meaning |
| --- | --- |
| Accepted | Evidence is sufficient for the current assessment purpose |
| Under review | Assessor or AI-assisted review is still in progress |
| Rejected | Evidence is missing, stale, incomplete, or does not support the claim |
| Requested | Evidence has not been uploaded yet |

## Why This Matters

The assessment is only as defensible as the evidence behind it. P86-Assess keeps the evidence request, uploaded file, hash, review decision, finding, and report output connected.
