DKDavid Koran& Associates
Home The CMMC Guide Part III · Audit and Accountability AU.L2-3.3.7
The CMMC Guide · Audit and Accountability Family

AU.L2-3.3.7  Time Stamps and Clock Synchronization

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

Family
Audit and AccountabilityAU, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

AU.L2-3.3.7 makes the timestamps in audit records trustworthy. It requires that systems compare and synchronize their internal clocks with an authoritative time source, so that the time stamps on audit records are accurate and consistent across systems. It is a one-point requirement and may be deferred on a plan of action, though it quietly underpins every investigation.

Time is the axis every investigation runs along. To reconstruct what happened, an analyst orders events by their time stamps, and if the clocks on different systems disagree, that ordering breaks: an event that came first appears to come second, and the sequence that would reveal an intrusion is scrambled. This control requires that internal clocks be synchronized to an authoritative source, so that time stamps are accurate and comparable across the environment. It is a small technical measure with outsized importance, because correlation and investigation both depend on a shared, correct clock.

The requirement · NIST SP 800-171 Rev 2, 3.3.7

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

The requirement ties three things together: internal clocks generate the time stamps, an authoritative source defines correct time, and synchronization keeps the clocks aligned to it. The authoritative source is typically a reliable time service the organization designates, and synchronization is usually automatic through the time protocol built into the systems. The control is met when the systems that generate audit records keep their clocks synchronized to that source, so time stamps can be trusted and compared.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.3.7 into three objectives: use internal clocks for time stamps, specify the authoritative source, and synchronize to it.

[a]

Internal system clocks are used to generate time stamps for audit records. Records are time-stamped from the system clock.

MeetsAudit records carry time stamps generated from the system clock.
FailsRecords lack reliable time stamps, so events cannot be ordered.
[b]

An authoritative source with which to compare and synchronize internal system clocks is specified. The organization has designated a correct-time source.

MeetsA specified authoritative time source, such as a designated internal time server or a reliable external service.
FailsNo source is specified, so clocks drift with nothing to correct them.
[c]

Internal system clocks used to generate time stamps are compared to and synchronized with the specified authoritative source. The clocks are kept aligned to the source.

MeetsSystems synchronize their clocks to the authoritative source automatically, so time stamps stay accurate and consistent.
FailsClocks are not synchronized, so systems disagree on the time and records cannot be correlated across them.

The three objectives move from time-stamping to specifying a source to synchronizing with it. The common gap is at objectives [b] and [c], where systems are never pointed at a common authoritative source, so their clocks drift apart and cross-system time stamps cannot be trusted. The assessor looks for synchronization to a designated source across the systems that generate records.

3Failure Patterns

The failures are about unsynchronized clocks and the scrambled event ordering they cause.

Clocks that drift apart

Without synchronization, system clocks drift, and after a while different systems disagree on the time by seconds or minutes. During an investigation that spans systems, that disagreement scrambles the true order of events, which is the harm the control prevents.

No specified source

Where no authoritative source is designated, there is nothing to correct drift against, so objective [b] fails and synchronization has no anchor. A specified source is the reference the whole control depends on.

Some systems left unsynchronized

If most systems synchronize but a few do not, the records from those few carry untrustworthy time stamps and break correlation. Synchronization has to reach the systems that generate audit records, not just the majority.

Inconsistent time zones or formats

Records stamped in inconsistent local time zones without a common reference can confuse ordering even when clocks are technically synchronized. A consistent reference, often coordinated universal time, keeps time stamps comparable.

The common root
This control fails quietly and shows up loudly during an investigation. Unsynchronized clocks scramble the order of events across systems, so the sequence that would reveal what happened cannot be reconstructed. Synchronizing to a common source is a small measure that every later analysis depends on.

4Ownership

This is an IT-owned technical control, usually satisfied by the time synchronization built into the environment.

RoleResponsibility for this control
IT and system administratorSpecifies the authoritative time source and configures systems to synchronize to it. Owns the technical evidence.
Security or compliance leadConfirms synchronization reaches the systems that generate audit records and that time stamps are consistent.
Program leadIncludes time synchronization in periodic checks and retains the configuration evidence.
See also: This control gives trustworthy time stamps to the records created under AU.L2-3.3.1 and is what makes the correlation of AU.L2-3.3.5 reliable.

5Tooling

The control is delivered by the time protocol built into the systems, pointed at a designated source.

ObjectivesToolingWhat it provides
[a]System clock time-stampingAudit records stamped from the system clock.
[b]Designated time source, such as an internal NTP server or reliable serviceThe authoritative source clocks are synchronized to.
[c]NTP or the domain time hierarchy, consistent time referenceAutomatic synchronization of clocks to the source across the systems that generate records.

The caveat is that synchronization has to reach every system that generates audit records and use a consistent reference. A domain time hierarchy anchored to a reliable source covers most systems automatically, but standalone or cloud systems have to be pointed at the source too. The assessor examines the time source and synchronization across the record-generating systems, so coverage and consistency both have to hold.

6Evidence

The satisfied version of 3.3.7 shows a specified source and synchronized clocks across the environment.

EvidenceWhat it demonstrates
Specified time sourceObjective [b]. The designated authoritative source.
Time synchronization configurationObjectives [a], [c]. Systems generating time stamps and synchronizing to the source.
Synchronization status across systemsObjective [c]. Evidence that record-generating systems are actually synchronized.

The evidence should show a designated authoritative source and synchronized clocks on the systems that generate audit records. Configuration pointing systems at the source, plus confirmation they are in sync, is the clearest demonstration of the control.

Investigations run on a shared clock

Unsynchronized clocks scramble the order of events across systems, and the damage surfaces exactly when an investigation needs to reconstruct a sequence. Pointing every record-generating system at a common authoritative time source is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.7. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.7[a] through 3.3.7[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Audit and Accountability
AU.L2-3.3.6 · Audit Reduction and Reporting
Next in Audit and Accountability →
AU.L2-3.3.8 · Protect Audit Information
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AU.L2-3.3.7 · Edition 2026.1 · Last reviewed July 12, 2026