---
title: "Compliance monitoring, written as evidence"
description: "NIST 800-53, 800-171, CMMC Level 2 and CIS monitoring recorded as hash-chained evidence in your tenant. An unobserved control is a declared gap."
url: https://policycortex.com/platform/governance-compliance
sealed: 2026-09-02
amended: 2026-09-02
register: platform/governance-compliance
records: 5
digest: sha3:e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26c
---

# Monitoring that leaves a record, not a green light.

Register / Mechanism / Monitoring

PolicyCortex monitors your cloud against NIST 800-53, NIST 800-171 and CMMC Level 2, and CIS benchmarks, and writes every observation as evidence: content hashed with SHA3-256, timestamped, appended to the chain in your tenant, retained seven years. The control mapping is stored on the record. A control that stopped being observed produces a declared gap, not a stale green.

[Request verification](https://policycortex.com/contact) · [Proof of state](https://policycortex.com/proof/state)

![The PolicyCortex readiness view: every control in one of five states, with permitted automatic fixes flagged per control](https://policycortex.com/images/pcx-readiness-five-state-1600.webp)

Exhibit G-2 · every control in one of five states, with permitted automatic fixes flagged per control. Illustrative demo data; the interface is real.

## One observation, one record.

One record per resource, per capture, whether the capture ran on schedule or a change triggered it. The claim is not a sentence about the resource; it is the raw provider response underneath, hashed. The fields that make an observation file as compliance evidence are these.

- **resource.id**: The full provider path of the resource this record is about: the identifier the cloud API resolves, not a friendly name someone typed into a spreadsheet.
- **control.mapping**: The control statements this state bears on, stored on the record. One encryption setting can evidence NIST 800-171 3.13.16 and 800-53 SC-28 at once, and the mapping is written down, not implied.
- **asset.scope**: The declared boundary the resource sits in: CUI enclave, environment, production class. Scoping arguments get settled by this field instead of by the meeting.
- **state.proof**: The raw cloud API response that grounds the claim, stored verbatim. If a narrative and this payload ever disagree, the payload wins.
- **content.hash**: SHA3-256 digest of the record content. Anyone holding the record can recompute it; a matching digest means unaltered content.
- **captured.at**: UTC timestamp of the capture. Every claim in the evidence base reads as of this field, not as of whenever someone last looked.

![The PolicyCortex control implementation table: CMMC Level 2 controls by family with implementation status and evidence counts](https://policycortex.com/images/pcx-system-control-collections-1600.webp)

Exhibit G-1 · the 110-requirement table where observations file, control by control. Illustrative demo data; the interface is real.

See also

- [Proof of state, the full record](https://policycortex.com/proof/state)
- [Where the collectors run](https://policycortex.com/architecture#boundaries)

## Drift is a finding, not a dashboard color.

Changes made around the system, in the portal, through a direct API call, from a pipeline that never met a gate, surface at the next state capture as drift records with no authority attached. A change with no authority is not a blind spot. It is a finding, and it is recorded as one.

Configuration tampering becomes detectable for the same reason: expected state is on record, so an unexplained delta from the last capture anchors the detection. Every control sits in one of five honest states, and permitted automatic fixes are flagged per control; a fix, when one runs, is approval gated and arrives with its own record.

See also

- [Proof of change, where drift is recorded](https://policycortex.com/proof/change)
- [Proof of agency, how a fix is gated](https://policycortex.com/proof/agency)

## What is written when nothing was watching.

A collector down for six hours does not produce six hours of silence. It produces a gap record: which stream, from when to when, why, and when the gap was declared. Evidence with fewer rows and no explanation is indistinguishable from evidence that was trimmed, so the register declares the gap and lets you hold us to it.

Why absence is a record and not a smaller number is argued in full in the [architecture](https://policycortex.com/architecture#gaps).

## Where the observations file.

Monitoring files under continuous monitoring, with the audit family governing how the records themselves are protected. The mapping is quiet on purpose: the record is the product, and the rows below are where monitoring evidence files. The full list of supported frameworks follows them.

- **NIST 800-53**: CA-7 continuous monitoring grounded in point-in-time records, with the AU family covering how those records are protected, retained, and reviewed.
- **NIST 800-171 / CMMC Level 2**: One evidence base for the 110 requirements: state records handed to your assessor as generated evidence with the raw payload attached.
- **CIS Benchmarks**: Benchmark observations written as evidence on the same chain, hashed and timestamped like every other record.
- **FedRAMP 20x**: Machine-readable by construction. State and control mappings export as OSCAL 1.1.2.
- **MITRE ATT&CK**: Configuration tampering becomes detectable because expected state is on record: an unexplained delta from the last capture anchors the detection.

- **Supported frameworks**: CMMC Levels 1 to 3 · NIST SP 800-171 Rev 2/3 · NIST SP 800-53 Rev 5 · DFARS 252.204-7012 · FedRAMP Low, Moderate, High · FISMA · ITAR/EAR · HIPAA · SOX · PCI DSS · CIS Benchmarks for AWS, Azure, and GCP · SOC 2 Type II · NIST AI RMF · MITRE ATT&CK and ATLAS

See also

- [The federal record](https://policycortex.com/federal)
- [How the record becomes a package](https://policycortex.com/platform/ato-authorization)

## What this layer does not do.

**Stated limit.** Monitoring cannot attest to what it never observed. Environments outside connected scope produce no records, and the record says so with a declared gap. The record is not the verdict: it does not guarantee an assessment outcome, and it is not the assessor. It is what you hand the assessor so the argument is about the environment instead of about the evidence.

See your controls as records, not as a score. [Request verification](https://policycortex.com/contact)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | THE OBSERVATION | d20f97ae9ea8 | 7e2b4914b287 |
| REC 0001 | DRIFT | a086572fd780 | d20f97ae9ea8 |
| REC 0002 | DECLARED GAPS | 45143d6b2e8e | a086572fd780 |
| REC 0003 | FRAMEWORK MAP | 2bc01802ea50 | 45143d6b2e8e |
| REC 0004 | STATED LIMIT | e8f3df854713 | 2bc01802ea50 |

Head sha3:e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26c. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
