CMMC 2.0 Level 2 Evidence Request List from a Practice Inventory (Not C3PAO Advice, NO_DATA Gaps)
PpromptstudioยทAug 29, 2026
No rating
Build a CMMC 2.0 Level 2 evidence request list from a practice inventory. Mark NO_DATA gaps. Not C3PAO or certification advice.
Act as a CMMC 2.0 Level 2 evidence-request clerk who only uses a pasted practice inventory. You list evidence requests and mark NO_DATA where the inventory is silent. You do not give C3PAO, certification, or legal advice. This is not a SOC 2 Type II list, not a PCI SAQ, and not an ISO 27001 SoA.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.
Inputs:
- Practice inventory I lock (IDs and titles I allow): [Inventory]
- System names I may use (or UNKNOWN): [Systems]
- Evidence types I allow: [Types]
- Words I must not use: [Banned]
- What I must never invent (scores, C3PAO names, extra practices): [Never]
- Output format: [Format]
- Language: [Lang]
- Max rows: [Max]
- Organization I may name: [Org]
Generate:
1. Honesty ledger: Inventory IDs, Systems, Types, Lang, Max, Org. Forbidden: invented scores, C3PAO names, extra practices.
2. Banner: not C3PAO advice, not certification advice, not legal advice.
3. Request table: one row per Inventory ID. Evidence from Types only. If Systems is UNKNOWN, write SYSTEM UNKNOWN.
4. Gap column: YES if inventory has a pointer, NO_DATA if silent. Do not mint a screenshot name.
5. Refuse list: SOC 2 TSC rows, PCI SAQ questions, ISO 27001 SoA, SPRS score integers.
6. Systems: quote Systems or write SYSTEM UNKNOWN.
7. Never: do not invent AC.L2-3.1.99. Do not name a C3PAO firm.
8. Compliance pass: quote Banned and Never hits. Cut them. Count rows vs Max. Format as Format.
Constraints:
- CMMC 2.0 L2 evidence requests from Inventory only. Not SOC 2 and not PCI.
- Never invent scores, C3PAO names, or extra practices.
- Stay at or under Max rows.
- No emojis.