DKDavid Koran& Associates
Home The CMMC Guide Part III · Audit and Accountability AU.L2-3.3.6
The CMMC Guide · Audit and Accountability Family

AU.L2-3.3.6  Audit Reduction and Reporting

Provide audit record reduction and report generation to support on-demand analysis and reporting.

Family
Audit and AccountabilityAU, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

AU.L2-3.3.6 makes audit records usable on demand. It requires an audit record reduction and report generation capability, so that when an investigation is needed, the organization can turn a large volume of raw logs into focused analysis and reports rather than sifting by hand. It is a one-point requirement and may be deferred on a plan of action.

Audit logs accumulate quickly, and in raw form a large volume of records is nearly unusable for a time-sensitive investigation. This control asks for two related capabilities: reduction, which filters and focuses the records so an analyst can concentrate on what matters, and report generation, which produces readable output on demand. Together they turn a heap of logs into something a person can actually investigate with, which is the difference between having records and being able to use them when it counts.

The requirement · NIST SP 800-171 Rev 2, 3.3.6

Provide audit record reduction and report generation to support on-demand analysis and reporting.

The two capabilities answer a practical question: when something happens, how fast can the organization find and present what the logs show. Reduction narrows the records to the relevant subset, and report generation turns that subset into readable output, both on demand rather than after days of manual work. The control does not require altering the original records; reduction operates on copies or through queries so the source records remain intact for the protection required by 3.3.8.

2The Assessment Objectives

NIST SP 800-171A frames 3.3.6 around two objectives: provide reduction, and provide report generation.

[a]

An audit record reduction capability that supports on-demand analysis is provided. The organization can filter and focus its audit records for analysis.

MeetsA capability to search, filter, and reduce records, such as a SIEM query interface, that focuses analysis on demand.
FailsRecords can only be read raw, so focusing on a specific event means manual sifting through volume.
[b]

A report generation capability that supports on-demand reporting is provided. The organization can produce readable reports from its audit records when needed.

MeetsA capability to generate readable reports from the records on demand, for investigation or review.
FailsNo reporting exists, so findings must be assembled by hand each time.

The two objectives are reduction and reporting, both on demand. The common gap is having raw logs with no capability to reduce or report on them, so that in an investigation the records exist but cannot be turned into usable analysis quickly. The assessor looks for a working capability to focus and present the records, not merely their presence.

3Failure Patterns

The failures are about raw logs with no means to focus or present them.

Raw logs only

Where records can only be read in raw form, an investigation means manually sifting through volume, which is slow and error-prone. A reduction capability that filters to the relevant records is what the control asks for.

No reporting capability

Without report generation, findings have to be assembled by hand each time, which does not support on-demand reporting. A capability to produce readable output from the records satisfies objective [b].

Capability that alters the source

A reduction approach that modifies the original records would conflict with the protection required elsewhere. Reduction should work on copies or through queries so the source records remain intact.

Capability no one can use

A tool that technically exists but that no one is trained to use does not support on-demand analysis in practice. The capability has to be usable by the people who would run an investigation.

The common root
This control fails when logs are kept but not made usable. Having records is not the same as being able to investigate with them, and a heap of raw logs with no way to reduce or report on them leaves the organization slow exactly when speed matters. Reduction and reporting turn storage into a usable tool.

4Ownership

This is an IT-owned control, usually satisfied by the same platform that collects and retains the logs.

RoleResponsibility for this control
IT and system administratorProvides and maintains the reduction and reporting capability, typically within the log platform. Owns the technical evidence.
Security or compliance leadConfirms the capability supports on-demand analysis and reporting and that staff can use it.
Program leadEnsures the capability remains available and retains evidence of it.
See also: This control makes usable the records created under AU.L2-3.3.1 and supports the correlation of AU.L2-3.3.5, while the source records remain protected under 3.3.8.

5Tooling

The control is delivered by the query, filtering, and reporting features of the log collection platform.

ObjectivesToolingWhat it provides
[a]SIEM or log platform search and filteringReduction of records to the relevant subset for on-demand analysis.
[b]Report generation in the log platformReadable reports produced from the records on demand.
IntegrityQuery-based access to retained recordsAnalysis that operates without altering the protected source records.

The caveat is that the capability has to be usable and preserve the source. A platform that offers reduction and reporting satisfies the control only if it is available for on-demand use and does not alter the original records. The assessor examines whether the organization can focus and report on its records when needed, so a demonstrable, usable capability is what counts.

6Evidence

The satisfied version of 3.3.6 shows working reduction and reporting over the retained records.

EvidenceWhat it demonstrates
Reduction capabilityObjective [a]. The search and filtering that focuses records on demand.
Report generation capabilityObjective [b]. The production of readable reports from the records.
Sample report or queryObjectives [a], [b]. A demonstration of on-demand analysis and reporting.

The evidence should show that the organization can reduce and report on its audit records on demand, which a sample query and report demonstrate. The capability within the log platform, shown in use, is the clearest demonstration of the control.

Records you cannot search are records you cannot use

A heap of raw logs is nearly useless in a time-sensitive investigation, and this control asks for the reduction and reporting that turn storage into a usable tool. Standing up on-demand search and reporting over the retained records is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.6[a] and 3.3.6[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Audit and Accountability
AU.L2-3.3.5 · Audit Correlation
Next in Audit and Accountability →
AU.L2-3.3.7 · Time Stamps and Clock Synchronization
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AU.L2-3.3.6 · Edition 2026.1 · Last reviewed July 12, 2026