DNS Monitoring for CMMC Compliance

CMMC 2.0 is being phased into Department of Defense contracts, and defense contractors handling Controlled Unclassified Information (CUI) must reach Level 2 — the 110 security practices of NIST SP 800-171 — verified by self-assessment or a C3PAO. DNS is part of the environment those practices cover, and ZoneWatcher generates the audit logging and monitoring evidence assessors sample.

DNS in Your CMMC Scope

Your DNS records route email that carries CUI, point at the systems that store it, and control how partners and DoD counterparts reach your services. A compromised MX record silently redirects sensitive correspondence. A hijacked A record impersonates your infrastructure. These are exactly the threat scenarios the 800-171 practice families — audit and accountability, configuration management, incident response, and system integrity — are written to counter.

Relevant Level 2 Practices

AU.L2-3.3.1 — Audit Logging
Contractors must create and retain audit logs sufficient to monitor, analyze, and investigate unlawful or unauthorized activity. ZoneWatcher records every DNS change with timestamps and before/after values, giving you a retained, reviewable audit trail for the DNS layer without manual collection.
CM.L2-3.4.3 — Track and Review System Changes
Configuration management requires that changes to organizational systems are tracked, reviewed, and approved. ZoneWatcher's change history documents every DNS modification, and change management workflows let you require review before changes ship — turning an assessor's toughest sampling request into a lookup.
IR.L2-3.6.1 — Incident Handling
An operational incident-handling capability spans detection through recovery. ZoneWatcher's real-time alerts on unauthorized DNS changes provide the detection trigger, delivered to email, Slack, Microsoft Teams, or webhooks so your response procedures start promptly — with the change history supporting later analysis and reporting.
SI.L2-3.14.6 — Monitor for Attacks
System and information integrity practices require monitoring systems and communications for indicators of attack. Continuous DNS, WHOIS, and TLS certificate monitoring — including Certificate Transparency log watching for unauthorized certificates on your domains — covers an attack surface most SIEM deployments miss.

Evidence for Your Assessment

Whether you're self-assessing against 800-171 for SPRS or facing a C3PAO, assessors want objective evidence that practices are implemented and operating. ZoneWatcher provides:

  • Retained audit logs of every DNS change across your domains
  • Documented change tracking with attribution where the source is known
  • Proof of continuous monitoring and configured alerting
  • Zone exports supporting contingency and recovery documentation
  • Point-in-time PDF reports to drop straight into your assessment evidence

The same evidence serves your NIST SP 800-171 self-assessment score today and your formal CMMC assessment when it lands in your contracts.

A note on certifications

This guide explains how ZoneWatcher helps your organization prepare for its own audit against this framework. It is not a claim that ZoneWatcher holds this certification. For details on how we secure ZoneWatcher itself, see our security overview.

Ready to protect your DNS?

Start your free trial today and get full access to all monitoring features.