CMMC LEVEL 2 · NIST SP 800-171

CMMC Audit Logging & Evidence, Without the Cloud or Splunk

The Audit & Accountability controls are where most small defense contractors stall. Here's what CMMC actually requires — and how to satisfy it inside your own network.

The clock is real

Phase 2 of the CMMC rollout begins November 10, 2026, when third-party (C3PAO) assessments become the standard for many CUI contracts. If your logging and evidence aren't in place before your assessment, you don't get certified — and you can't win the work.

Audit & Accountability is one of the most common places small contractors lose points, because it's the one control family you can't fake with a policy document: assessors want to see the logs and the evidence.

What CMMC actually asks for in audit logging

In plain English, the Audit & Accountability (AU) family — and the related System & Information Integrity monitoring requirements — ask you to:

  • Create audit logs of the events that matter — logins, privilege changes, access to CUI, and security-relevant system events.
  • Protect those logs from tampering and unauthorized access.
  • Retain them long enough to support an investigation and an assessment.
  • Review them — someone actually has to look, not just collect.
  • Produce evidence on demand that all of the above is happening.

CMMC doesn't literally say "buy a SIEM." But satisfying AU.L2 and the related System & Information Integrity controls without SIEM-like tooling is very hard — which is why most contractors end up needing dedicated tooling.

The three options most small contractors consider

Every DIB SMB we talk to has looked at some version of these three paths. Each falls short for a different reason.

Enterprise SIEM

Splunk, LogRhythm, and friends

Powerful and battle-tested — but expensive, complex, and far more than a small contractor needs. Realistic all-in cost is six figures plus a full-time engineer to keep it healthy.

Overkill for most DIB SMBs

Cloud SIEM

Blumira, Huntress, and similar

Affordable and easy to stand up — but your logs, which reference CUI, leave your enclave and go to a third-party cloud. That reintroduces the exact data-boundary problem CMMC is trying to solve.

Expands your CUI boundary

Manual / do-nothing

Spreadsheets and hope

Screenshots on assessment week, ticket exports, and a prayer. This is the single most common way small contractors lose points on Audit & Accountability.

#1 way to fail AU

See how Attestor compares to SIEM and GRC tools.

What "good" looks like

A CMMC-ready audit logging program for a small contractor should meet four tests:

Logging inside your enclave

So CUI — and everything that references it — never leaves your environment.

Automatic control mapping

Events tagged to the specific 800-171 / CMMC controls they evidence, at ingest.

Assessor-ready evidence

Something you can hand a C3PAO — not a pile of raw logs to interpret.

Runnable by a small team

Simple enough that you don't need a dedicated SOC engineer to keep it healthy.

How Attestor does it

Attestor is a self-hosted compliance SIEM built for CMMC Level 2 and NIST SP 800-171 Rev 2. It's designed to satisfy the audit logging, continuous monitoring, and evidence requirements without pulling CUI into someone else's cloud.

Stays in your enclave

Attestor is self-hosted — deploy with Docker in your own environment. It never sends your data to Phaethon: no telemetry, no analytics, no licence check-in. The only outbound connections are the alert webhooks and SMTP destinations you configure.

Maps events to controls automatically

As events are ingested, Attestor tags each to the NIST 800-171 / CMMC control it evidences — Access Control, Audit & Accountability, and Identification & Authentication — so your coverage builds itself.

Signed, assessor-ready evidence

Generate cryptographically signed evidence bundles for a chosen framework and date range. Independently verifiable, and built for a C3PAO to review.

Honest scope note: Attestor focuses on the audit logging, monitoring, and evidence side of CMMC — pair it with your other controls (and, if you use one, your GRC tool) for full coverage.

Where your data goes

A fair way to evaluate any compliance tool is to look at where the data physically travels. Here is Attestor's full outbound surface — nothing else leaves your environment.

DataDestinationWho controls it
Raw log events & CUI-referencing telemetryStays inside your Attestor deploymentYou
Signed evidence bundlesDownloaded by you; shared with your assessor at your discretionYou
Licence verificationVerified locally against a signed licence file — no phone-homeYou (offline)
Product telemetry / analyticsNone. Attestor does not send usage data to Phaethon.N/A
Alert notificationsOnly to the webhook URLs you configure (e.g. Slack, Teams, PagerDuty)You
Email notificationsOnly via the SMTP server you configureYou

In short: Attestor never sends your data to Phaethon. The only outbound connections it makes are the alert webhooks and SMTP destinations you configure — and you choose whether to configure them, and where they point.

Serving multiple clients? (For MSPs)

MSPs and MSSPs building CMMC managed offerings can deploy Attestor per client, keep each client's data in that client's enclave, and hand over signed evidence at assessment time — no shared multi-tenant SaaS to explain in an SSP.

Explore partner options

Frequently asked questions

See your own events mapped to CMMC controls in minutes.

Self-hosted. 14-day evaluation. Your logs never leave your enclave.