Retention is only half the requirement
The Audit & Accountability area isn't just "keep logs." To satisfy the requirements, you have to do all four of the following — and be able to show it:
Create the right logs
Log the events that matter — logins, privilege changes, access to CUI, security-relevant system events.
Protect them
Guard audit records against tampering and unauthorized access — integrity is part of the requirement, not a nice-to-have.
Retain them
Keep logs long enough to support investigations and your assessment — a period you define and follow.
Review them
Someone (or something) has to actually look at the logs — and you have to be able to show that they do.
So how long is "long enough"?
NIST SP 800-171 does not set a universal number of days. It expects you to define a retention period that supports investigations and your assessment, document it in your SSP, and actually follow it.
Separately, DFARS 252.204-7012 requires that, in the event of a cyber incident, you preserve and protect relevant monitoring and packet-capture data for at least 90 days from the incident. That's an incident-preservation obligation — it is not a cap on routine audit-log retention.
Many contractors choose to retain routine audit logs well beyond 90 days — a year or more is common — and record their chosen period in their SSP. Bottom line: pick a defensible period, document it, and confirm it with your assessor.
Anyone quoting a single "the CMMC log retention rule is X days" is oversimplifying. The 90-day figure is about incident preservation under DFARS 7012, not routine audit log retention under 800-171.
Protecting logs from tampering
Retention only counts if the logs are trustworthy. Audit records need to be protected from unauthorized access and modification.
Append-only storage and integrity protection matter here — an assessor needs confidence that the records they're looking at weren't altered after the fact.
Reviewing logs (the step people skip)
The controls expect logs to be reviewed, not just collected. You need a process — and evidence of that process — showing that someone (or something) is actually monitoring for the events that matter. A retention period without review is a storage bill, not a control.
Documenting it in your SSP
Your System Security Plan is where retention becomes a control an assessor can evaluate. At minimum, document:
- Define your retention period and the rationale behind it.
- Describe how logs are protected from tampering and unauthorized access.
- Describe how and how often logs are reviewed — and who's responsible.
- Describe how you'd produce logs for an investigation or assessment.
How Attestor helps
Attestor is built around exactly this. It retains your security events inside your own enclave, stores audit records with integrity protection so they're tamper-evident, runs detection rules with alerts so review isn't purely manual, and produces signed evidence bundles that show the logging and monitoring controls are working.
You still set and document your retention policy — Attestor makes it enforceable and demonstrable.
See it on your own logs — start a free 14-day evaluation.
Related reading: the CMMC audit logging guide · what evidence a C3PAO asks for.
Frequently asked questions
This guide is general education, not compliance or legal advice — confirm specifics with your C3PAO or RPO.