Evidence for your CMMC Level 2 assessment objectives
Final records for each audit objective, and a plain list of what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| AU.L2-3.3.1 | Audit records created and retained. | Classified events per source. → |
| AU.L2-3.3.4 | Alert when audit logging fails. | A silent-source alert. → |
| AU.L2-3.3.5 | Correlated audit review. | Correlation across sources. → |
| AU.L2-3.3.8 | Audit information protected. | A signature chain that breaks on change. → |
| IR.L2-3.6.1 | Incident handling in operation. | Cases and playbook history. → |
| MP.L2-3.8.7 | Removable media controlled. | Device control. → |
Scoping
Know where the SIEM sits in scope
Under 32 CFR 170.19, a SIEM is a Security Protection Asset, assessed against the Level 2 requirements relevant to what it does. A store of CUI content is a CUI Asset.
Objectives
Answer each objective, not only the family
Assessors score each objective, such as AU.L2-3.3.1[f], and ask for evidence in final form. ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Integrity
Prove nobody changed your logs
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Completeness
Know when logging stops
The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.
Response
Track every incident to its close
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
IA.L2-3.5.3
Multifactor authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
SC.L2-3.13.11
FIPS-validated cryptography. ARRTECH does not claim FIPS 140-3 validated cryptography.
170.19(c)(2)(ii)
Responsibilities documented in your SSP and a customer responsibility matrix. Confirm ARRTECH’s part with us before your assessment.
By rule
Naming a clause is not a claim of certification.
AU.L2-3.3.1
Create and retain system audit logs and records, scored objective by objective. ARRTECH: classified events per source, with retention set per source or per group.
AU.L2-3.3.4
Alert in the event of an audit logging process failure. ARRTECH: a silent-source alert and a system summary report of source and agent status.
AU.L2-3.3.5
Correlate audit record review, analysis and reporting processes. ARRTECH: correlation rules across sources. A saved query becomes a report.
AU.L2-3.3.8
Protect audit information and audit logging tools from unauthorized access, modification and deletion. ARRTECH: a signature chain that breaks on change, and role-based rights on each log source.
IR.L2-3.6.1
Establish an operational incident-handling capability. ARRTECH: SIEM cases and SOAR incidents with an execution history of playbook runs.
MP.L2-3.8.7
Control the use of removable media on system components. ARRTECH: device control by device class, vendor, product or serial number.
Questions
Is ARRTECH CMMC certified?
CMMC status belongs to your system, not a vendor’s product. Naming an objective is not a claim of certification.
What does the assessor accept?
Final records. The Assessment Guide says all evidence must be in final form and not draft.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Is there a ready CMMC report?
No ready report is named. A saved query becomes a report, on a schedule.
Sources
Guide
What is CMMC Level 2?
The DoD program that assesses contractor systems holding CUI against the requirements of NIST 800-171 Rev. 2.
What is a Security Protection Asset?
A system that provides security to your assessment scope, such as a SIEM, whether or not it holds CUI.
What is an assessment objective?
A lettered part of a requirement, such as 3.3.1[f]. Each must be met for the requirement to be met.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.