3.3.6Be able to search and report on logs in Rev. 3
Reworded: 03.03.06 Audit Record Reduction and Report Generation.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.3.6 Reduction & Reporting
Assessment objectives · 800-171A
- [a] an audit record reduction capability that supports on-demand analysis is provided
- [b] a report generation capability that supports on-demand analysis is provided
- [c] an audit record reduction capability that supports on-demand reporting is provided
- [d] a report generation capability that supports on-demand reporting is provided
Rev. 3 · not adopted 03.03.06 Audit Record Reduction and Report Generation
a. Implement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after-the-fact investigations of incidents.
b. Preserve the original content and time ordering of audit records.
Determination statements · 800-171A Rev. 3
- 03.03.06.a[01] an audit record reduction and report generation capability that supports audit record review is implemented.
- 03.03.06.a[02] an audit record reduction and report generation capability that supports audit record analysis is implemented.
- 03.03.06.a[03] an audit record reduction and report generation capability that supports audit record reporting requirements is implemented.
- 03.03.06.a[04] an audit record reduction and report generation capability that supports after-the-fact investigations of incidents is implemented.
- 03.03.06.b[01] the original content of audit records is preserved.
- 03.03.06.b[02] the original time ordering of audit records is preserved.
Draws on Rev. 2 3.3.6.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.3.6 → Rev. 3 03.03.06 Audit Record Reduction and Report Generation
8 words kept, 5 removed, 24 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- New security requirement title
- Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit record reduction and report generation
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.
NIST's Rev. 3 discussion for 03.03.06
Audit records are generated in <a href="#/cprt/framework/version/SP_800_171_3_0_0/home?element=03.03.03">03.03.03</a>. Audit record reduction and report generation occur after audit record generation. Audit record reduction is a process that manipulates collected audit information and organizes it in a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always come from the same system or organizational entities that conduct auditing activities. An audit record reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can help generate customizable reports. The time ordering of audit records can be a significant issue if the granularity of the time stamp in the record is insufficient.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.3.6 as written in Rev. 2.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.03.06
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]