Document artifact names, hashes, algorithms, versions, and source locations
A synthetic CMMC artifact hash-manifest example for preserving evidence identity and provenance during an approved assessment handoff.
One immutable fingerprint per exported artifact version
Source, owner, version, and collection context retained
Algorithm and generation timestamp recorded
Manifest linked back to objective and artifact indexes
Hashing protects identity, not meaning
A hash can show that a file has not changed since the fingerprint was generated. It cannot show that the file is approved, current, correctly scoped, or sufficient for an assessment objective. Those fields still need evidence operations and assessment judgment.
Preserve enough context to reproduce the handoff
The manifest should make it possible to identify the exact artifact version and where the original came from without exposing unnecessary sensitive content in the index.
- Artifact identifier and file name
- Source repository and approved export path
- Version, collection date, and evidence owner
- Hash algorithm, hash value, and generation time
- Linked assessment objectives or pack section
- Replacement or superseded-version relationship
Follow the authorized assessment procedure
DoD publishes dedicated hashing guidance and assessment processes may impose specific handling steps. The manifest template must be adapted to the current official guidance and the assessment team’s instructions.
What the working artifact can contain
| Artifact ID | File | Version | Algorithm | Hash | Source |
|---|---|---|---|---|---|
| EV-0048 | access-review-q2.xlsx | 2.1 | SHA-256 | 4e3b…9af1 | Client SharePoint |
| EV-0073 | network-diagram.pdf | 5.0 | SHA-256 | 91c7…02be | Client SSP folder |
| EV-0112 | training-completion.csv | 2026-Q2 | SHA-256 | 2a81…bc44 | Client LMS export |
Synthetic hash rows — values are shortened and fictional.
Concrete, client-owned operating records
Facts, not verdicts
This illustrative manifest is not a substitute for the DoD CMMC Hashing Guide, the CMMC Assessment Process, or assessment-team instructions.
Frequently asked questions
Does hashing prove the evidence is valid?
No. Hashing helps preserve file identity. Approval, relevance, currency, scope, implementation, and sufficiency are separate questions.
Should CUI appear in the manifest?
The manifest should minimize sensitive content. File names and metadata can themselves be sensitive, so the final structure and storage location require client approval.
Source context
Bring the evidence state you actually have.
Gridex will map the operating work, the human judgment boundary, and the safest next step.