CMMC 3.3.1 (Audit Logging): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.3.1 · CMMC Practice: AU.L2-3.3.1 · Updated June 2026

    Plain-English answer

    3.3.1 says: create and retain the audit logs you need to monitor, analyze, investigate, and report unlawful or unauthorized activity. The assessor reads this as three decisions you must document and then prove: which events to log, what each record must contain, and how long to keep them.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment. Audit logging is the evidence layer the whole AU family — and most incident response — depends on.

    Why it matters

    Without the right logs, you can't investigate an incident or prove what happened. It's weighted heavily — a 5-point requirement under the DoD Assessment Methodology.

    Control lineage

    • CMMC Practice: AU.L2-3.3.1
    • NIST 800-171 Rev. 2: §3.3.1 — create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
    • NIST 800-171A objectives: [a] the logging needed for monitoring/analysis/investigation/reporting is specified; [b] the content of audit records is defined; [c] audit records are created; [d] created records contain the defined content; [e] retention requirements are defined; [f] audit records are retained as defined.

    What the assessor will EXAMINE

    • Your audit/logging policy: the event list, the required record content, and the retention period.
    • Logging configuration on in-scope systems and cloud services (what's actually enabled).
    • Sample audit records showing the defined fields are present (who, what, when, where, outcome).
    • Retention configuration and proof logs are kept for the documented period.
    • SSP narrative for 3.3.1.

    What the assessor will INTERVIEW

    • "Which events did you decide to log, and why?" — tie the list back to monitoring/investigation needs, not "everything by default."
    • "How long are logs retained, and where?" — state the period and show the enforcing config.
    • "Walk me through pulling logs for a specific user action last month." — demonstrate you can actually retrieve them.

    What the assessor will TEST

    • Take a recent action and confirm it produced an audit record with the defined content.
    • Retrieve a record near the edge of your retention window to prove retention works.
    • Check that a sampled in-scope system is actually forwarding/retaining logs.

    Evidence examples (produce these)

    • Audit-logging policy defining events, record content, and retention period.
    • Logging configuration exports/screenshots from in-scope systems and cloud services (dated).
    • Sample audit records showing the required fields.
    • Retention setting proof (e.g., log-store retention policy) and a retrieved older record.
    • SSP section 3.3.1 referencing the above.

    Platform-specific

    • Google Workspace: Admin & security audit logs, the Reports API, log export to BigQuery, and Vault retention rules — evidence both the content and the retention.
    • Microsoft GCC High: Purview Audit (unified audit log), Entra sign-in/audit logs, and retention via Log Analytics / Microsoft Sentinel with a defined retention period.

    Common failure patterns

    • Logging is "on" but the events to log were never defined, so objective [a] fails.
    • Records are generated but missing required content (no user, no outcome) — [d] fails.
    • Retention period is undocumented, or the tool's default purge is shorter than what the SSP claims.
    • Logs exist but no one can demonstrate retrieving them for a specific event.

    SPRS impact & POA&M

    SPRS: not meeting 3.3.1 is a 5-point deduction. POA&M: confirm 3.3.1's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.3.1 when your policy defines the events, record content, and retention period; logging is enabled and produces records with that content; retention is enforced and demonstrable; you can retrieve logs on demand; and the SSP matches the configuration.

    Map your 3.3.1 evidence the way an assessor reads it. Get an audit-logging evidence map →

    Related: 3.5.3 MFA evidence · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.