Skip to main content
Compliance Guidance

What Your Contract Actually Requires You to Log

FAR 52.204-21 addresses only physical access logs and DFARS 252.204-7012 names no event types or retention period. The real logging obligation is NIST SP 800-171 section 3.3, which leaves six parameters for the contractor to define and sets no retention number at all. Here is what to write down, and why the 90-day incident preservation duty is not a retention policy.

Brandon Hancock, J.D., CMMC-RPPublished September 3, 2026Updated September 3, 20267 min read

Read your cybersecurity clauses looking for the word "log" and you will find remarkably little. FAR 52.204-21 imposes fifteen basic safeguarding requirements, and exactly one of them concerns logging — a physical one, directing contractors to "maintain audit logs of physical access." DFARS 252.204-7012 never lists a single event type or retention period. The substantive logging obligation lives one level down, in the standard the clause incorporates by reference, and it is written in a way that makes your own documentation the binding answer.

The Clause Points Somewhere Else

DFARS 252.204-7012(b)(2)(i) subjects a covered contractor information system to the security requirements in NIST SP 800-171 "in effect at the time the solicitation is issued or as authorized by the Contracting Officer." That phrasing matters: the applicable revision is fixed by the solicitation, not by whatever NIST has most recently published. Two active contracts in the same building can carry different revisions. Confirm which one your contract incorporated before you rewrite anything.

Whichever revision applies, the logging requirements sit in the Audit and Accountability family — section 3.3. In NIST SP 800-171 Revision 3, finalized May 2024, that family contains eight requirements:

  • 03.03.01 Event Logging — specify the event types selected for logging, and review and update that selection on a defined frequency.
  • 03.03.02 Audit Record Content — each record must capture what type of event occurred, when, where, its source, its outcome, and the identity of the individuals, subjects, objects, or entities associated with it.
  • 03.03.03 Audit Record Generation — generate records for those event types, and "[r]etain audit records for a time period consistent with the records retention policy."
  • 03.03.04 Response to Audit Logging Process Failures — alert defined personnel within a defined time period when logging fails, and take defined additional actions.
  • 03.03.05 Audit Record Review, Analysis, and Reporting — review and analyze on a defined frequency, report findings, and correlate records across repositories.
  • 03.03.06 Audit Record Reduction and Report Generation — support after-the-fact investigation while preserving original content and time ordering.
  • 03.03.07 Time Stamps — use internal system clocks, at a defined granularity, in UTC or with a stated offset.
  • 03.03.08 Protection of Audit Information — protect audit information and logging tools from unauthorized access, modification, and deletion, and limit administration of the logging function to a subset of privileged users.

Six Blanks You Are Required to Fill

Read that list again and count the bracketed assignments. Revision 3 leaves six organization-defined parameters across the family: the event types themselves, how often you revisit that list, how quickly you alert on a logging failure, what else you do when one occurs, how often you review records, and your time-stamp granularity. Notably, it sets no number at all for retention — 03.03.03 defers to your records retention policy.

This is the part contractors most often misread as freedom. It is closer to the opposite. An unfilled parameter is not a satisfied requirement; it is a requirement with no evidence behind it. The value you choose becomes the standard you are measured against, and the place you record it is your system security plan. An assessor does not arrive with a preferred retention period. An assessor arrives with yours.

The 90-Day Rule Is Not a Retention Policy

Defense contractors routinely conflate two different obligations. DFARS 252.204-7012(e) requires that, on discovering a cyber incident, the contractor "preserve and protect images of all known affected information systems ... and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest."

That is a preservation duty, triggered by an incident and running from the date you report it — not a baseline retention period. Setting routine log retention at ninety days does not satisfy it, and satisfying it does not answer 03.03.03.

Note also what paragraph (c)(1)(i) demands before the 72-hour report goes out: a review for evidence of compromise "including, but not limited to, identifying compromised computers, servers, specific data, and user accounts." That determination is made from logs. A contractor whose event selection never captured authentication or file access cannot produce that answer inside 72 hours — and the reporting clock does not pause while you go looking.

What to Write Down This Week

1. Identify which revision of SP 800-171 each active contract incorporated. 2. Write down all six organization-defined parameters as actual values, not as "as needed." 3. Confirm your retention period is stated in a records retention policy the logging requirement can point to. 4. Separate that period, in writing, from the 90-day incident preservation duty — including who is authorized to take forensic images before remediation begins. 5. Verify that logging administration is restricted to a subset of privileged users, so the population that can alter records is smaller than the population being recorded.

If you are not sure which clauses apply to your work in the first place, start with Find My Requirements and the frameworks reference, then build the documentation using the program-building tools and checklists. Contractors operating systems on an agency's behalf should also read our coverage of the CISA Logging Reference Architecture, which can flow separate agency logging expectations into a contract. For which systems the family reaches at all, see CMMC Level 2 scoping and the fifteen basic safeguards.

Key Takeaways

  • The clause is not the requirement. FAR 52.204-21 addresses only physical access logs, and DFARS 252.204-7012 specifies no event types or retention period — the substance is in NIST SP 800-171 section 3.3, and the applicable revision is set by the solicitation.
  • Six parameters are yours to define, and one number is missing entirely. Revision 3 leaves event types, review frequencies, failure-response timing and actions, and time-stamp granularity to the organization, and ties retention to your own records policy. Undefined means unevidenced.
  • Ninety days is a preservation duty, not a retention floor. It starts when you submit the incident report, covers system images and monitoring/packet capture data, and is separate from — not a substitute for — the routine retention period your system security plan states.

This article is educational information about cybersecurity and government contracting requirements. It is not legal advice, and it does not create an attorney-client relationship. Contract-specific obligations depend on the clauses in your award.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?