Compare the request with your record
Find the request source. Identify the work, information, systems, and time period involved. Record any difference from the scope your evidence covers.
If the terms are unclear, ask the requesting party to clarify. Keep that question separate from an implementation gap. Your team cannot plan the work until it understands the condition it must meet.
Test the fit
Check the requirement
Does the material address the actual requirement and requested form of response? A policy or prior answer may support context without satisfying this request.
Check the scope
Does it cover the work, information, and systems in this customer relationship? Scope determines whether a result can travel with the method.
Check the current implementation
Does the material describe what your team operates today? A document may remain accurate while a system or practice has changed.
Check time and change
Is the material current for this request? Establish whether a relevant change occurred after collection or review.
Check the sharing route
Are you allowed to provide the material through the route the customer requested? Handle evidence according to the terms and approved process.
Check customer acceptance
Does the recipient accept this evidence, or require a different assessment or record? The customer and governing terms decide that question.
Keep a reason with every reuse decision. If evidence needs a scope update, assign the work and record the next action. Match what you share to the customer’s request. Retain the detailed evidence that supports your answer.
A practical example
Suppose you have evidence about access reviews for one system. A new customer asks about another environment used for its work. The existing procedure can help your team plan. The old review results do not show that the other environment received the same review.
Record the additional scope, perform the needed work, and retain the resulting evidence. Reusing a method and reusing a result are different decisions.
Keep the demonstration route distinct
Customer evidence requests, self-assessments, affirmations, and certification have different purposes. Select the route required by the governing terms and current implementation direction.
The published CMMC clause distinguishes assessment statuses and links required status to systems used for covered contract information. An evidence folder does not establish that status. DFARS 252.204-7021.
Maintain the work behind the response
Record what you sent, the scope it covered, when you checked it, and who approved the response. When a relevant system, process, person, or requirement changes, review the affected work and evidence before reusing the answer.
Deep Fathom helps your team maintain the work behind customer responses. It connects requirements, assigned work, and evidence with the scope they support. It does not share evidence across customers or decide whether a customer accepts it.
Describe one repeated customer request and the work behind it to evaluate the platform for your requirements.
See how primes can make requests clearer or return to the hub.
In Deep Fathom
Keep the evidence and its context together.
Collection details, owner roles, and review timing help explain an evidence record. This demo record is marked stale, so it needs review before reuse.
Expand product view +