SOP Management & Workflow Documentation3 min readUpdated September 2026

Preparing Your SOPs for a CMMC-Style Assessment Sample

Procedures have to be controlled, versioned, and demonstrably followed, because an assessor will sample them and ask for evidence. Document control and execution records decide how that review goes, not which tool is pleasant to write in.

Here is what that sampling actually looks like in practice, walked through as it would play out during a review, and where Process Street and SweetProcess each hold up or fall short.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

The assessor asks for the current version of an access control procedure

This is where document control gets tested first. SweetProcess's version history answers this cleanly: the current version, when it was last revised, and who approved the revision, all visible without digging through email threads or shared drive folders with filenames like final-v3-updated. A procedure library without built-in version control turns this simple request into a scramble to confirm which copy is actually current. Practice this specific request internally before an actual assessment: pick a procedure at random and time how long it takes to produce the current version with its approval history. If that takes more than a couple of minutes, the document control system needs work before an assessor tests it for you.

The assessor asks to see evidence the procedure was actually followed last month

This is where a checklist earns its place. A Process Street run of the access review, with timestamps, who completed each step, and what was found, is the evidence that closes this request. A written policy with no execution record answers the first question well and fails this one completely, since a policy that exists on paper without proof of execution reads to an assessor as a gap, not a control. Build the checklist so the evidence generates itself as a byproduct of doing the work, rather than as a separate logging step people have to remember to do after the fact, since the second version is the one that quietly stops happening once the initial rollout excitement fades.

The assessor asks who approved a specific exception to the standard process

Exceptions happen even in a controlled environment, a delayed access revocation during a system migration, for instance, but an undocumented exception is functionally the same as a violation from an assessor's point of view. Build an exception path into the checklist itself, requiring an approver and a reason before the exception can be logged, so this question has a clean answer instead of an uncomfortable pause. Even a short delay, a day or two while a migration completes, deserves the same documented treatment as a longer one, since an assessor testing your control is checking whether the exception process exists and gets used, not measuring the exception's actual duration.

The assessor asks how a procedure update actually reaches the people who execute it

A revised procedure that sits in SweetProcess but never triggers anything for the team running the related Process Street checklist is a gap an assessor is specifically trained to find. Link the checklist step to the current procedure version directly, so a revision automatically changes what the person running the checklist sees, rather than depending on someone remembering to update both systems separately. Test this the same way you tested document control: revise a procedure, then check how long it takes for that change to visibly reach the checklist someone runs against it. A delay measured in weeks instead of the same day is the gap an assessor is specifically trained to probe.

The assessor asks about the last time the process itself was reviewed for effectiveness, not just followed

Following a process correctly and the process itself still being the right one are different questions, and an assessor increasingly asks both. Schedule a periodic review of each critical procedure, not triggered only by an incident or an upcoming assessment, and log that the review happened even when the conclusion was no change needed, since an unreviewed procedure with a five-year-old revision date raises its own questions regardless of how well it has been followed. Rotate which procedures get this deeper review each quarter rather than trying to revisit all of them at once, so the effort is sustainable and the review dates spread naturally across the year instead of clustering right before an assessment.

What this costs to run and who should own it

Median pay for an operations manager, often the role responsible for this kind of compliance system, runs $105,770 a year nationally1, worth budgeting against whether this sits inside an existing quality or security role or justifies a dedicated compliance hire as your contract base grows and assessment scope expands with it. Whichever path you choose, put the ownership in writing the same way you would any other critical procedure, since an assessor asking who owns document control and getting an uncertain answer is its own kind of finding.

Before an assessment, rehearse these requests internally:

  • Produce the current version of a randomly chosen procedure, with its last revision date and approver, in a couple of minutes.
  • Show a timestamped checklist run proving the access review was completed last month, including who finished each step and what was found.
  • Name the approver and the reason for any exception to the standard process.
  • Show how a procedure revision reaches the people running the related checklist, without relying on someone to remember to tell them.
  • Show a logged periodic review of each critical procedure, even where the conclusion was no change needed.
Executive Capability Standard

What Good Looks Like

A well-run contractor can produce the current version of any procedure, evidence it was followed in the last review period, and a record of any approved exception, on request during an assessment.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Pick one critical procedure and trace whether you could currently answer all five assessor-style questions about it.
2. Do Manually:Write down the current version of your highest-risk procedures and start manually logging execution evidence.
3. Delegate:Assign a compliance or quality lead to own document control and confirm execution records are complete.
4. Automate:Move policy content into a version-controlled library and execution steps into a checklist tool linked to the current version.
5. Buy:Run document control, execution evidence, and exception tracking under one governed system ready for the next assessment.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Does one tool cover both document control and execution evidence, or do you need two?

Most defense contractors use two tools rather than one, because the requirements differ. A procedure library holds version-controlled policy content and needs revision history. A checklist tool holds execution evidence and needs timestamped completion records tied to a specific instance of the work.

How far back should execution records be retained for an assessment?

Match whatever retention period your specific contract or assessment framework requires, and default to keeping longer rather than shorter when a requirement is ambiguous, since retrieving a deleted record is much harder than storing one you end up not needing.

Should exception approvals require the same signoff level regardless of the procedure's risk level?

No. Set a higher approval level for exceptions on higher-risk procedures, such as access control or data handling, and a lighter approval path for lower-risk administrative procedures, so the approval burden actually tracks the risk instead of treating every exception identically.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Annual wage, General and Operations Managers (SOC 11-1021), US all industries. BLS OEWS May 2025, 2025.

Related Guides