to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.3.6Be able to search and report on logs in Rev. 3

Reworded: 03.03.06 Audit Record Reduction and Report Generation.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.3.6 Reduction & Reporting

Provide audit record reduction and report generation to support on-demand analysis and reporting.

Assessment objectives · 800-171A

  1. [a] an audit record reduction capability that supports on-demand analysis is provided
  2. [b] a report generation capability that supports on-demand analysis is provided
  3. [c] an audit record reduction capability that supports on-demand reporting is provided
  4. [d] a report generation capability that supports on-demand reporting is provided

Rev. 3 · not adopted 03.03.06 Audit Record Reduction and Report Generation

a. Implement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after-the-fact investigations of incidents.

b. Preserve the original content and time ordering of audit records.

Determination statements · 800-171A Rev. 3

  1. 03.03.06.a[01] an audit record reduction and report generation capability that supports audit record review is implemented.
  2. 03.03.06.a[02] an audit record reduction and report generation capability that supports audit record analysis is implemented.
  3. 03.03.06.a[03] an audit record reduction and report generation capability that supports audit record reporting requirements is implemented.
  4. 03.03.06.a[04] an audit record reduction and report generation capability that supports after-the-fact investigations of incidents is implemented.
  5. 03.03.06.b[01] the original content of audit records is preserved.
  6. 03.03.06.b[02] the original time ordering of audit records is preserved.

Draws on Rev. 2 3.3.6.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.3.6 → Rev. 3 03.03.06 Audit Record Reduction and Report Generation

Provide Implement an audit record reduction and report generation to support on-demand capability that supports audit record review, analysis, and reporting requirements, and after-the-fact investigations of incidents. Preserve the original content and time ordering of audit records.

8 words kept, 5 removed, 24 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for audit record reduction and report generation

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.

NIST's Rev. 3 discussion for 03.03.06

Audit records are generated in <a href="#/cprt/framework/version/SP_800_171_3_0_0/home?element=03.03.03">03.03.03</a>. Audit record reduction and report generation occur after audit record generation. Audit record reduction is a process that manipulates collected audit information and organizes it in a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always come from the same system or organizational entities that conduct auditing activities. An audit record reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can help generate customizable reports. The time ordering of audit records can be a significant issue if the granularity of the time stamp in the record is insufficient.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.3.6 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.03.06
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]