Uniqcli

CMMC control families

CMMC Audit & Accountability (3.3 AU): 9 requirements and where the logs actually live

Nine requirements about creating audit records, tying them to individual users, protecting them and reviewing them. The correlation and the review cadence are your platform's job and your team's. The capacity the retention window implies, the log-forwarding subscriptions on the gear that produces the records, and the integration work that gets them to your collector are ours.

Family
3.3 — Audit & Accountability
Requirements
9 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

Records have to exist, name a person, survive, and be reviewable

Audit and accountability carries nine requirements. You create and retain audit records sufficient to monitor, analyze, investigate and report unlawful or unauthorized activity (3.3.1); every logged action has to be traceable to an individual user (3.3.2); the logging process itself has to alert you when it fails (3.3.4); clocks have to run against an authoritative time source (3.3.7); the audit records have to be protected from unauthorized access, modification and deletion (3.3.8); and management of the audit function is limited to a privileged subset of users (3.3.9). Almost all of that is configuration and review discipline. What a supplier puts behind it is capacity — somewhere the records live for as long as you said they would — the console plumbing that gets them off the equipment in the first place, the log-forwarding and reporting subscriptions on the boundary and endpoint platforms producing the records, and the deployment work that points every log source at the collector you have chosen.

Levels

What each level asks of this family

Nothing in this family is scored at Level 1, which surprises contractors who assume logging is table stakes. Audit and accountability is a Level 2 family — the 15 FAR 52.204-21 requirements behind a Level 1 self-assessment do not reach 3.3 at all.

At Level 2 all nine apply, from record creation and content at 3.3.1 and 3.3.2 through review and reporting, failure alerting at 3.3.4, time synchronization at 3.3.7, and protection of the audit records themselves at 3.3.8 and 3.3.9. The last two are the pair that turns a logging design into a storage design: records that a local administrator can quietly delete are not protected records.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Somewhere the records live (3.3.1)

Retention is a number you choose and then have to hold. NAS and storage arrays sized to that window are quoted against it rather than against a level — Buffalo is the best-stocked NAS line we carry, QNAP is deep on catalog but thin on the shelf, and Nexsan is priced across a thousand rows without stock, so it is a lead-time line. The quote states which is which before you commit.

Capacity by the tray

Where the array already exists, the requirement usually turns into disks. Axiom is by a distance the deepest in-stock drive line on the hub, with Seagate, Western Digital and Rocstor behind it. Enterprise drives are quoted with the caddies, rails and warranty terms the platform needs, and availability is confirmed per line rather than assumed.

Getting records off the box (3.3.8)

Protecting audit information usually means it does not stay only on the device that produced it, and out-of-band console access is how infrastructure without a management NIC gets reached at all. Serial console and device servers from Lantronix, Perle, Opengear, Digi and Vertiv's Avocent line are quoted with the cabling and PDU the rack layout needs.

Getting records into your platform

The devices producing the records are usually where the forwarding is licensed. WatchGuard's SIEM-integration lines, Proofpoint's and SonicWall's syslog and reporting subscriptions, and the equivalent reporting terms on the other boundary families we carry are all priced in our licensing catalog and quoted against your renewal date. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Pointing the sources at the collector

A retention design only works once every log source is actually reporting into it. Deployment and configuration work — standing up the array, baselining the appliances, configuring the forwarding and recording what was changed — is scoped alongside the order rather than left as an exercise for whoever unboxes it.

Limits

What stays yours to run

We do not sell SIEM or log-management platforms, and we are not going to pretend otherwise — that category is not in our catalog, and correlation, alerting, retention policy and review cadence are your platform and your people either way. Selecting the event types under 3.3.1, tying actions to individuals under 3.3.2 and restricting audit management under 3.3.9 are decisions no invoice reaches.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Audit and accountability questions

How long must CMMC audit logs be retained?

NIST SP 800-171 does not name a number. 3.3.1 requires you to create and retain audit records to the extent needed to enable monitoring, analysis, investigation and reporting — the period is yours to define in the SSP and then defend. Sizing follows from that decision, which is why we quote capacity against your retention window rather than against a level. If your contract carries DFARS 252.204-7012, check its own preservation expectations for incident-related data separately, because they are set by that clause and not by 3.3.

Does CMMC require a SIEM?

No. The family requires audit records, traceability to individual users, protection of those records and a review and reporting process — it names no product category. Plenty of small contractors meet 3.3 with native logging, a collection target and a documented review. We do not sell SIEM platforms; we quote the storage and console hardware the design underneath one depends on.

What events have to be logged under NIST 800-171 3.3?

The ones you define. 3.3.1 asks for audit records sufficient to monitor, analyze, investigate and report unlawful or unauthorized system activity, and 3.3.2 requires the logged actions to be traceable to individual users, so the event set has to cover the activity your risk assessment cares about. The event list belongs in the SSP, where an assessor can compare it against what the systems actually emit.

Is audit and accountability required at CMMC Level 1?

Not at Level 1. Audit and accountability is one of the eight Level 2-only families, so an annual Level 1 self-assessment never looks at logging at all. Contractors handling CUI carry 3.3 through DFARS 252.204-7012 regardless of what level a solicitation names.

Get a CMMC estimate — CMMC Audit & Accountability (3.3 AU)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Audit & Accountability (3.3 AU)

Talk to us about log retention capacity

Tell us the retention window you wrote into the SSP and the platform that has to hold it. A Uniqcli specialist replies with an estimate for the array, the disks, the console hardware, the forwarding subscriptions and any staging work the build needs — availability stated per line, TAA and §889 screening performed before it goes out.