CMMC20X
Blueprint appendix · evidence

Worked example:
one MFA claim.

An identity export reports MFA for 24 accounts. A local emergency account sits outside that export. Until someone verifies factor enforcement for that access path, the system may contain a way around MFA. That is a cybersecurity gap, not a paperwork defect.

The Blueprint defines CMMC 20X. This appendix shows how one security claim can remain connected to its sources, conflicts, software analysis, and human judgment.

The chain

What the record shows.

The software preserves each layer instead of turning a machine output into a decision. Follow the claim from assertion to authority.

Security claim · claim-ia-3.5.3-01uncertain

3.5.3 · Multifactor authentication

Multifactor authentication is enforced for synthetic privileged and network access paths in scope.

Observed population
24 / 24 visible accounts
Source system
synthetic identity provider
Collected
2026-08-10T12:00:00Z
Review state
returned
  1. 01

    Claim

    Multifactor authentication is enforced for synthetic privileged and network access paths in scope.

  2. 02

    Source

    24 of 24 accounts visible to the identity provider are covered. The export cannot see local emergency accounts.

  3. 03

    Conflict

    The identity-provider export reports complete coverage for its visible population while the exception register identifies a local emergency-account path outside that export. Collect source evidence for local emergency-account factor enforcement or narrow and re-review the claim.

  4. 04

    Rule + AI analysis

    The rule-based check returns pass with limitation. The AI analysis says: The structured export supports factor coverage for observed paths; the local emergency-account conflict requires human examination.

  5. 05

    Human finding

    return for additional evidence: The local emergency-account path is inside the stated boundary but not covered by evidence of factor enforcement.

  6. 06

    Authorized decision

    not issued. Legal or program effect: none.

What software cannot decide

A valid record is not proof that MFA works.

The validator can confirm required fields, references, dates, and file integrity. Those checks make the record testable; they do not establish that the emergency account requires a second factor. Evidence sufficiency, CMMC findings, and decisions remain with qualified people and authorized organizations.

For implementers

Technical files.

Inspect the record structure, validate an implementation, or map it to OSCAL. These discussion-draft files use synthetic data and carry no assessment or program effect.