A folder full of screenshots can still leave a supplier unable to explain how its security controls work. The missing detail is often ordinary: which system the image came from, who checked it, whether it covers the contract’s information, and what happened after the picture was taken.

For suppliers subject to Canadian Program for Cyber Security Certification requirements, Level 1 evidence should make those connections easy to follow. Public Services and Procurement Canada’s guidance describes a self-assessment against 13 cyber-hygiene controls and gives examples of records suppliers can keep.

Draw the boundary before collecting records

Start with the solicitation and contract. Identify the specified information, then trace where it is received, stored, processed, and shared. Include the people, endpoints, cloud services, and physical locations that can reach it. A security setting on a system outside that boundary tells you little about the information the contract requires you to protect.

The official guidance ties applicability and timing to contracting activity. Confirm the requirement with the contracting authority rather than treating a general program announcement as the schedule for a particular bid. If relying on recognition of a U.S. CMMC certification, obtain confirmation for the relevant scope; recognition should not be assumed.

What an explainable record looks like

Examples of evidence, not a complete control mapping
PracticeUseful recordContext to retain
Access managementAccount list and access-review resultSystem, reviewer, removals and review date
Device managementCurrent device inventoryScope, owner and update process
Security awarenessTraining completion recordAudience, material and completion date
System protectionFirewall or MFA configurationRelevant service, scope and capture date
Recurring maintenanceUpdate or sanitization logWhat was done, by whom and when

A record can be simple. An access review might identify the account population, the manager who examined it, the exceptions found, and the date those exceptions were resolved. That tells a more useful story than a screenshot of the user-administration screen alone.

Avoid copying sensitive operational records into an unnecessarily broad evidence folder. Keep the evidence accessible to the people responsible for the assessment while preserving the access restrictions appropriate to its contents. A reference to a controlled source can be easier to maintain than several copies.

The attestation begins a maintenance cycle

Save the completed assessment, result and expiry information. PSPC’s guidance says evidence should be retained for the duration of the attestation cycle or at least one year. Assign responsibility for maintaining it through personnel changes, device replacement, and changes to service providers.

Set review dates according to how quickly a record can become wrong. An account list may change much faster than an approved policy. When a control is incomplete, record the gap and resolve it through the applicable assessment process; an attractive evidence pack cannot substitute for implementation.

A useful final check is to ask someone who did not assemble the folder to follow one control. Can they identify the requirement, the systems covered, the evidence of operation, and the owner who can answer a question? If they can, the file is much more likely to remain useful after the assessment is submitted.

Selected primary sources

Open the primary-source pages used to verify the claims summarized here.