Log Retention Checker
Check whether your current log retention settings meet PCI DSS, HIPAA, SOC 2, GDPR, NIS2, and FedRAMP requirements across 18 source types.
- Covers 7 major compliance frameworks and their specific log requirements
- Maps your hot and cold retention tiers against framework minimums
- Flags non-compliant source types with specific citations
- Generates a formal log retention policy template
Retention compliance check
PCI DSS 4.0
12 months online + 12 months archive
HIPAA Security Rule
6 years for audit records
SOC 2 (CC7.2)
Duration of observation period + 3 months
GDPR Article 5
As long as necessary + documented justification
NIS2 Directive
Minimum 12 months
FedRAMP Moderate
90 days online, 1 year archive
NIST 800-53 AU-11
3 years for national security systems
PCI DSS and NIS2 require longer hot-tier retention than your current 90-day setting.
How this tool works
Select your compliance frameworks
Choose the regulations and standards applicable to your organisation. You can select multiple frameworks for a combined view.
Enter your current retention settings
Input how many days your hot (searchable) and cold (archived) log tiers are retained per source type.
See your compliance status and gaps
The tool maps your current settings against each framework's minimum requirement and flags non-compliant source types.
What to do with the result
Identify compliance gaps
Take the gap report to your cloud storage or SIEM vendor to understand the cost of extending retention tiers.
Document your retention policy
Use the output as the basis for your formal log retention policy document required by most compliance frameworks.
Estimate storage cost impact
Use the SIEM cost calculator alongside this tool to model the cost of extending hot-tier retention to meet requirements.
Log retention checker: frequently asked questions
What log sources does the checker cover?
The checker covers 18 source categories: authentication systems, endpoint/EDR, cloud platform (AWS/Azure/GCP), network devices, DNS, email, web proxy, application logs, database activity, cloud access security broker, identity provider, SaaS audit logs, container/Kubernetes, code platform (GitHub/GitLab), API gateways, IAM systems, data loss prevention, and vulnerability scanner outputs.
Does PCI DSS 4.0 require 12 months of searchable logs?
PCI DSS 4.0 Requirement 10.7.1 requires that audit logs are retained for at least 12 months, with the most recent 3 months available for immediate analysis. Logs older than 3 months can be archived but must be retrievable.
What counts as an 'audit record' under HIPAA's 6-year requirement?
HIPAA's 6-year requirement (45 CFR 164.530(j)) applies to policies, procedures, and documentation — not necessarily to raw log events. However, audit trail records supporting required security activities should be retained for the duration they may be needed in litigation or investigation, typically 3-6 years.
How does GDPR's 'as long as necessary' retention principle work in practice?
GDPR does not mandate a specific log retention period — you must document your legitimate purpose, apply the minimum necessary retention, and have a defined deletion schedule. Security logs are typically justified for 12-24 months under legitimate interest for fraud prevention and security investigations.
Can ManySignal help me meet retention requirements without SIEM costs scaling linearly?
Yes. ManySignal uses tiered storage — hot (30-90 days, full search), warm (90-365 days, fast recall), and cold (1-7 years, compliance archive). Cold-tier storage costs are significantly lower than hot-tier SIEM indexing, allowing you to meet 6-year HIPAA requirements economically.
What happens if I fail a log retention audit finding?
Failure to retain required logs can result in fines, remediation requirements, and loss of certification. PCI DSS violations can result in increased card brand assessment fees. HIPAA violations related to missing audit records carry civil monetary penalties starting at $100 per violation.
Does the checker account for different retention periods per log source type?
Yes. You can set different retention values for each source category. Many frameworks specify different periods for authentication logs versus network flow logs versus application logs.
How should I handle log retention for cloud-native environments with ephemeral workloads?
Ephemeral workload logs (Lambda, containers, serverless) must be centralised into a persistent log store before the workload terminates. ManySignal's collectors buffer and centralise these logs automatically, ensuring they are not lost when a container or function exits.
Meet retention requirements without breaking your SIEM budget
ManySignal's tiered storage lets you retain logs for 7 years at a fraction of hot-tier indexing cost. Book a demo.