Compliance
CMMC Level 2 evidence produced continuously by the SOC.
NIST SP 800-171 evidence map
| Control | Requirement | SOC evidence | Count | Last generated | Status |
|---|---|---|---|---|---|
| 3.3.1 | Create and retain system audit logs | Normalized audit trail of every alert, query and action | 18,422 | Oct 8 07:30 | Current |
| 3.3.2 | Ensure actions traceable to users | Actor + approval reference per action | 1,326 | Oct 8 07:30 | Current |
| 3.3.5 | Correlate audit review and reporting | Cross-source correlation (XDR, SCM, M365) | 1,284 | Oct 8 07:30 | Current |
| 3.6.1 | Operational incident-handling capability | Investigation records with verdict and reasoning | 412 | Oct 8 07:30 | Current |
| 3.6.2 | Track, document and report incidents | Incident timeline, DFARS clock, escalation log | 37 | Oct 8 07:30 | Current |
| 3.6.3 | Test incident response capability | Unit 42 tabletop exercise report | 1 | Oct 8 07:30 | Due Nov 2026 |
| 3.14.3 | Monitor security alerts and advisories | 24/7 AI triage coverage report | 30 | Oct 8 07:30 | Current |
| 3.14.6 | Monitor inbound/outbound traffic | SCM traffic/threat log reviews | 9,120 | Oct 8 07:30 | Current |
| 3.14.7 | Identify unauthorized use | Entra ID risky sign-in investigations | 64 | Oct 8 07:30 | Current |
| 3.13.1 | Monitor and protect communications at boundaries | NGFW / Prisma Access posture (BPA) snapshots | 12 | Oct 8 07:30 | Current |
| 3.1.12 | Monitor and control remote access | GlobalProtect / Prisma Access session reviews | 180 | Oct 8 07:30 | Current |
DFARS 252.204-7012 · reportable incident
No active clock. Start it from an investigation (e.g. XDR-4821).
- Determine CUI impact on affected systems
- Collect facts for DIBNet report
- Preserve images and packet capture for 90 days
- Medium assurance certificate ready
Supply-chain model requirements
DoW supply-chain determination on Anthropic (FASCSA, Mar 2026) — no Anthropic models; blocked by policy; monthly provenance attestation.
Not legal advice — confirm requirements with your contracting officer.
Model provenance
DEMO DATACustomer-approved models only · MP-01 · customer model approval policy v1.0
All Anthropic models blocked by account policy. Monthly provenance attestation records models used and invocation counts. View model registry
Last 30 days: 41,920 model invocations · 0 Anthropic invocations · source: CloudTrail
September 8–October 8, 2026 (last 30 days) · Synthetic evidence, not a certification of the live demo chat.
CMMC responsibility matrix
| 24/7 monitoring & triage (3.14.x) | Vault |
| Incident handling & reporting (3.6.x) | Shared |
| Audit log retention (3.3.1) | Customer |
| Boundary protection config (3.13.1) | Customer |
| Response actions within policy | Shared |
| DIBNet report submission | Customer |
Boundary statement
Vault Agentics does not store, process or transmit CUI or ITAR technical data. The AI SOC runs in the customer's FedRAMP High AWS GovCloud account.