October 09, 2026
What Evidence Satisfies Audit Requirement 3.3.1?
You know assessors will ask for your audit logs, but you are not sure which records actually count.
Requirement 3.3.1 of NIST (National Institute of Standards and Technology) SP 800-171 Rev 2 answers that question directly. It protects CUI (Controlled Unclassified Information) in nonfederal systems.
The full requirement text appears in NIST SP 800-171 Rev 2. In plain words: create and keep system audit logs that support monitoring, analysis, investigation, and reporting of unauthorized system activity.
This article shows exactly what to prepare, mapped to how assessors examine, interview, and test.
Why do assessors start with 3.3.1 in every audit?
Logs are the memory of your environment. Without them, no incident can be reconstructed and no claim can be checked. Assessors test later requirements against the records created here. If 3.3.1 fails, review and analysis requirements have nothing to work with. Get this control right and the rest of the audit family gets easier.
What does "to the extent needed" mean?
"To the extent needed" means you scope logging to what your systems can use in an investigation. You do not need to log every file access on every machine by default. You log the events that matter for detecting misuse of your CUI systems. NIST gives an example: record every file access only for specific cases, not all the time. NIST SP 800-171 Rev 2
What counts as an audit record in your systems?
An audit record is any log entry the system creates about a security-relevant event. That includes operating system logs, application logs, firewall logs, and cloud audit trails. Azure Activity Log and Microsoft Entra audit logs are common examples in Azure. Assessors care about the full chain, from the event to the stored record. The record must be detailed enough to support monitoring, analysis, investigation, and reporting.
What must each audit record contain?
Assessors first check that you specified which events to log. NIST SP 800-171A Rev 2 Examples from NIST include password changes, failed logons, admin privilege use, and third-party credential use. Then they check that the record content is defined. Each record should establish what happened, when, where, the source, the outcome, and who was involved. In Azure, Microsoft Entra sign-in logs and the activity log already carry most of these fields. You still must document which fields your assessment boundary keeps.
How long must you keep audit records?
The standard does not name a number of days or months. It requires your organization to define the retention period in writing. NIST SP 800-171A Rev 2 Then you must retain the records for that period. Evidence is two things: the written period and the oldest record still on file. Assessors commonly flag a defined period that the systems never actually meet. Check the oldest timestamp in each repository before the assessment, not during it.
What does an assessor examine, interview, and test?
Under CMMC (Cybersecurity Maturity Model Certification) Level 2, all six objectives must be satisfied for the practice to pass. CMMC assessment objectives reference The six objectives are simple. Events to log are specified. Record content is defined. Records are actually created. Records contain the defined content. Retention requirements are defined. Records are retained as defined. NIST SP 800-171A Rev 2
NIST SP 800-171A Rev 2 lists the evidence objects for each method. NIST SP 800-171A Rev 2
Examine
- Audit and accountability policy
- Procedures addressing auditable events
- SSP (System Security Plan) describing the audit design
- System design documentation and configuration settings
- Procedures addressing audit record generation and control of audit records
- Actual audit logs and records, auditable events, and incident reports
Interview
- Personnel with audit and accountability responsibilities
- Personnel with information security responsibilities
- Personnel with audit review, analysis, and reporting responsibilities
- System or network administrators
Test
- Mechanisms implementing system audit logging
What does a practical checklist look like for a small team?
Work through these steps in order before an assessment.
- Write an audit and accountability policy that names the event types to log.
- List the required fields for each record: who, what, when, where, source, and outcome.
- Write down the retention period and set every system to meet it.
- Describe the audit design in the SSP.
- Assign someone to review the logs on a set schedule.
- Forward logs to a central store so no single server holds the only copy.
- A SIEM (Security Information and Event Management) tool can simplify central storage and review.
- Spot check the oldest records each quarter against the written period.
How do cloud teams meet 3.3.1 without extra agents?
In Azure, diagnostic settings forward resource logs to a Log Analytics workspace. Microsoft Entra keeps sign-in and audit logs by default. Set a retention period on the workspace that matches your written policy. Export copies to immutable storage so records survive accidental deletion. Document these settings in the SSP so the assessor sees the full design.
What should you show an assessor on day one?
Prepare one folder per requirement before the assessment starts. For 3.3.1, the folder should hold these items.
- The audit and accountability policy with event types and retention period
- The SSP section describing audit record generation
- Configuration exports showing logging enabled on in-scope systems
- Sample audit records with all required fields present
- A screenshot of the oldest retained record in each repository
What if you use a managed service provider?
Many small teams outsource log storage to a managed provider. That is acceptable, but you still own the requirement. Keep the contract language that names retention and access controls. The assessor will still examine your policy and interview your staff.
What common gaps do assessors flag?
Watch for these gaps.
- Retention gaps: the written period is longer than the oldest record on file. Fix it by raising the rollover threshold or extending retention.
- Unprotected logs: anyone can edit or delete records, which also fails requirement 3.3.8. Fix it by restricting write access to the log store.
- No review procedure: logs exist, but nobody looks at them on a schedule. Fix it by naming a reviewer and a review frequency in writing.
- Missing event types: admin actions and failed logons never reach the log store. Fix it by adding those events to the logging configuration.
- SSP silence: the System Security Plan never mentions audit logging. Fix it by adding one page that describes what is logged, where it goes, and how long it stays.
Sources
- NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-171r2
- NIST SP 800-171A Rev 2, Assessing Security Requirements for Controlled Unclassified Information. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=926380
- NIST CSRC page for SP 800-171 Rev 2. https://csrc.nist.gov/pubs/sp/800/171/r2/final
Next step
Collecting audit evidence by hand wastes time your team does not have.
See how PolicyCortex collects audit evidence from live Azure configuration.