CMMC and NIST SP 800-171 Rev 2: what AI use leaves in the audit record your assessor reads.
For the CISO, the CMMC and contracts lead, and any subcontractor or vendor handling controlled unclassified information (CUI), this page sets each Audit and Accountability requirement beside what a Verillian record shows when staff use AI on enrolled devices.
What the requirements ask, one by one
| What the requirement asks | A Verillian record shows | It does not show |
|---|---|---|
| 'The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.' The rule counts 'the 110 Level 2 requirements from NIST SP 800-171 R2'. To reach a Level 2 (C3PAO) status the organization must 'complete and achieve a MET result for all security requirements' and 'obtain a Level 2 certification assessment from an authorized or accredited C3PAO'. 32 CFR 170.14(c)(3), 170.4, 170.17(a)(1) | Entries for AI use on enrolled devices, which a reviewer reads in the admin console, running on your own infrastructure. They bear on the Audit and Accountability requirements below. | Which of the 110 requirements you meet, a MET or NOT MET result, or a CMMC status. Those come from an assessment. |
| 3.3.1 'Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.' NIST SP 800-171 Rev 2 | One entry for each captured AI request from an enrolled device to an AI service on your signed policy's list, with the time and the ruling (allowed, redacted or blocked). | The events you chose to log, how long your program keeps them, or any activity outside the captured requests. |
| 3.3.2 'Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions.' NIST SP 800-171 Rev 2 | The user and device as the checkpoint reports them, on an entry that the device signs. | The way accounts are created, or whether each one is unique in your identity systems. |
| 3.3.3 'Review and update logged events.' NIST SP 800-171 Rev 2 | Entries that a reviewer can search by ruling and AI service in the admin console. | The list of event types you log, or the periodic review that updates it. |
| 3.3.4 'Alert in the event of an audit logging process failure.' NIST SP 800-171 Rev 2 | Entries that arrived. This page states no alert for a logging failure. | A failure of the audit logging process, an entry that never arrived, or an alert about either. |
| 3.3.5 'Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.' NIST SP 800-171 Rev 2 | Entries that a reviewer reads and exports from the admin console. | Correlation with your other logs, or any investigation or response. Those stay with your team. |
| 3.3.6 'Provide audit record reduction and report generation to support on-demand analysis and reporting.' NIST SP 800-171 Rev 2 | Search and export of entries in the admin console, using the metadata it indexes: user, device, provider, model and decision. | Reports across your other systems, or the analysis itself. |
| 3.3.7 'Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.' NIST SP 800-171 Rev 2 | The time stamped on each entry. | Whether the clocks behind those times follow an authoritative source. That is set in your environment. |
| 3.3.8 'Protect audit information and audit logging tools from unauthorized access, modification, and deletion.' NIST SP 800-171 Rev 2 | The device signs every entry and hash-links it to the one before. A changed signed field is detectable, because your own admin server checks each entry as it arrives. Content is encrypted with a key you hold, and even Verillian cannot read content. | If the newest entries are deleted, nothing marks the gap, and a deletion made by a person with control of the host is the same. Access to the server and to your other logs stays with your program. |
| 3.3.9 'Limit management of audit logging functionality to a subset of privileged users.' NIST SP 800-171 Rev 2 | Sign-in to the console runs through your own identity provider, and an administrator assigns roles in the console. | Who manages audit logging in your other systems, or which of your users count as privileged. |
| Clause 252.204-7012 (MAY 2024) makes the covered contractor information system 'subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171' as 'in effect at the time the solicitation is issued or as authorized by the Contracting Officer'. Subcontracts are covered too: include the clause where 'subcontract performance will involve covered defense information'. 48 CFR 252.204-7012(b)(2)(i), (m)(1) | Each organization that enrolls devices holds the entries from them on infrastructure it runs. Verillian does not collect them for a prime. | Which revision applies to your contract, what counts as covered defense information, or which subcontracts carry the clause. Your contract and the contracting officer settle those. |
| Limits | Captured requests only, sent by an enrolled device to a provider your signed policy lists. Redaction is best effort, and the Claude API format is the one where screening has been verified. A provider that the signed policy leaves out is not governed. | Completeness, activity within a vendor's hosted service, or whether a prompt held CUI. Verillian is not a CMMC product, a record is not an assessment outcome, and neither gives a contractor a CMMC status. It does not decide CUI boundaries or assessment scope, and it gives no legal advice. No certification is claimed. |
Sources: eCFR, current as of October 6, 2026, for 32 CFR Part 170 and 48 CFR 252.204-7012; NIST SP 800-171 Revision 2 (February 2020, includes updates as of January 28, 2021) on nvlpubs.nist.gov; and NIST's publication page for it. All read on October 8, 2026: 32 CFR 170.4, 32 CFR 170.14, 32 CFR 170.17, 48 CFR 252.204-7012, NIST SP 800-171 Rev 2 (PDF), NIST publication page. Every quotation comes from them.
Aligned to the audit family of NIST SP 800-171 Rev 2, not certified. This is not legal advice or an assessment opinion. Your C3PAO and your counsel decide what satisfies the requirements.
To open an entry next to a requirement, bring a sample request to a demo. We read every request and reply.
Questions about CMMC and AI records
Does CMMC require 800-171 Rev 2 or Rev 3?
Revision 2, in the rule text read here. Section 170.14(c)(3) makes the Level 2 requirements 'identical to the requirements in NIST SP 800-171 R2', and 170.2 incorporates Revision 2 (February 2020, updates as of January 28, 2021) by reference. NIST's own pages show Revision 2 withdrawn on May 14, 2024 and superseded by Revision 3. The clause, dated MAY 2024, refers to the publication 'in effect at the time the solicitation is issued or as authorized by the Contracting Officer'. Which one governs your contract is for your contracting officer to say. This page did not check for a later rule change or a class deviation.
What does the Audit and Accountability family ask of AI use?
It names no AI tool. The nine requirements, 3.3.1 to 3.3.9, speak of system audit logs and records, individual system users and audit logging tools. Whether an AI service sits inside a system in your assessment scope is a call for your CMMC lead and your C3PAO. Where it does, the table above sets each requirement beside what a record shows.
Does using Verillian give a contractor a CMMC status?
No. Only an assessment produces one: section 170.16 sets out the Level 2 self-assessment and 170.17 the certification assessment by a C3PAO. Verillian is not a CMMC product, and no certification is claimed. It adds policy on the devices you enroll and a signed record of captured requests. The system security plan, the scope and each MET or NOT MET result remain the work of your team and your assessor.
Where do the records live?
The admin server and the signed record run on infrastructure you operate. You hold the key that encrypts content, and Verillian never receives your data. A vendor's own hosted model sits beyond what an enrolled device sends.
Read an entry beside these requirements.
Thirty minutes. Bring a sample request, watch it ruled live, and open the signed record together.
