Vault SOC

Compliance

CMMC Level 2 evidence produced continuously by the SOC.

NIST SP 800-171 evidence map

ControlRequirementSOC evidenceCountLast generatedStatus
3.3.1Create and retain system audit logsNormalized audit trail of every alert, query and action18,422Oct 8 07:30Current
3.3.2Ensure actions traceable to usersActor + approval reference per action1,326Oct 8 07:30Current
3.3.5Correlate audit review and reportingCross-source correlation (XDR, SCM, M365)1,284Oct 8 07:30Current
3.6.1Operational incident-handling capabilityInvestigation records with verdict and reasoning412Oct 8 07:30Current
3.6.2Track, document and report incidentsIncident timeline, DFARS clock, escalation log37Oct 8 07:30Current
3.6.3Test incident response capabilityUnit 42 tabletop exercise report1Oct 8 07:30Due Nov 2026
3.14.3Monitor security alerts and advisories24/7 AI triage coverage report30Oct 8 07:30Current
3.14.6Monitor inbound/outbound trafficSCM traffic/threat log reviews9,120Oct 8 07:30Current
3.14.7Identify unauthorized useEntra ID risky sign-in investigations64Oct 8 07:30Current
3.13.1Monitor and protect communications at boundariesNGFW / Prisma Access posture (BPA) snapshots12Oct 8 07:30Current
3.1.12Monitor and control remote accessGlobalProtect / Prisma Access session reviews180Oct 8 07:30Current

DFARS 252.204-7012 · reportable incident

No active clock. Start it from an investigation (e.g. XDR-4821).

  • Determine CUI impact on affected systems
  • Collect facts for DIBNet report
  • Preserve images and packet capture for 90 days
  • Medium assurance certificate ready

Supply-chain model requirements

DoW supply-chain determination on Anthropic (FASCSA, Mar 2026) — no Anthropic models; blocked by policy; monthly provenance attestation.

Not legal advice — confirm requirements with your contracting officer.

Model provenance

DEMO DATA

Customer-approved models only · MP-01 · customer model approval policy v1.0

All Anthropic models blocked by account policy. Monthly provenance attestation records models used and invocation counts. View model registry

Last 30 days: 41,920 model invocations · 0 Anthropic invocations · source: CloudTrail

September 8–October 8, 2026 (last 30 days) · Synthetic evidence, not a certification of the live demo chat.

CMMC responsibility matrix

24/7 monitoring & triage (3.14.x)Vault
Incident handling & reporting (3.6.x)Shared
Audit log retention (3.3.1)Customer
Boundary protection config (3.13.1)Customer
Response actions within policyShared
DIBNet report submissionCustomer

Boundary statement

Vault Agentics does not store, process or transmit CUI or ITAR technical data. The AI SOC runs in the customer's FedRAMP High AWS GovCloud account.