KB-041

Evidence folder setup in SharePoint or OneDrive

Applies to
All plans
Last reviewed
October 7, 2026
Version
1.0

For companies that use Microsoft 365 KB-041 | Applies to: All plans | Last reviewed: October 7, 2026

If your company uses Microsoft 365 for email, you already have SharePoint and OneDrive. This guide shows how to set up your evidence folder there and how to copy links for AffirmReady. If an IT provider manages your Microsoft 365, they may prefer to set up the folder for you. See KB-021: What if my IT provider manages my Microsoft 365?

SharePoint or OneDrive: which should I use?

We recommend a SharePoint site. Files in a SharePoint site belong to the company, so nothing is lost if someone leaves. OneDrive is tied to one person's account. It works fine for a one-person shop, but if more than one person will help, use SharePoint.

Step 1: Pick or create a site

  1. Sign in at office.com with your work account and open SharePoint.
  2. If you already have a site your leadership or office team uses, open it. Otherwise choose Create site, pick Team site, and give it a name such as Compliance.
  3. Add only the people who need access, such as the owner, office manager, and IT provider.

Step 2: Upload the folder kit

  1. Download and unzip the AffirmReady folder kit (see KB-040).
  2. In your site, open Documents.
  3. Drag the CMMC L1 Evidence folder from your computer into the browser window, or choose Upload, then Folder.
  4. Wait for the upload to finish and open the folder to confirm the subfolders are there.

Using OneDrive instead? The steps are the same. Open OneDrive at office.com and upload the folder into My files.

Step 3: Copy a link for AffirmReady

  1. Find the file or folder you want to record. Hover over it and select the three dots (More actions).
  2. Choose Copy link.
  3. Before you copy, check who the link works for. Select the link settings and choose People with existing access. This creates a link that only works for people who can already open the file, so it does not share anything new.
  4. Copy the link and paste it into the evidence entry in AffirmReady.

Avoid link settings that say Anyone. Those links work for anyone who gets them, including people outside your company.

Helpful tips

  • Linking to a subfolder, such as 06 Passwords and sign-in, is often easier than linking to each file. Anyone reviewing can open the folder and see everything for that requirement.
  • If you move or rename a file, SharePoint links usually keep working, but it is worth clicking the link in AffirmReady once to check.
  • You can sync the folder to your computer with the Sync button so you can save screenshots straight into it from File Explorer.

If your screen looks different

Menus change from time to time. If a button or setting name does not match what you see, the goal is the same: a folder only your team can open, and a link that only works for people who already have access. Microsoft's own instructions for sharing and link settings: support.microsoft.com, search for Share SharePoint files or folders.

Still need help?

Email support@affirmready.com and include your company name and the email address on your AffirmReady account. Our team is available Monday through Friday, 8:00 AM to 5:00 PM Eastern, and replies within one business day.

For CMMC Level 1 readiness purposes only. Not legal advice. Your company is responsible for the accuracy of its self-assessment and affirmation.

Did the steps match what you see?

Microsoft and other software change their screens often. If something here looks different on your screen, let us know and we'll update this article.

Please don't include passwords or sensitive company information.
Cloudflare verification

Loading verification…