---
title: "What is the Consolidated Audit Trail (CAT)?"
description: "The Consolidated Audit Trail is a central record of order and trade events in US equities and listed options, created by the SEC under Rule 613 so regulators can reconstruct market activity across every venue and firm from one source."
source: https://www.pico.net/kb/what-is-a-consolidated-audit-trail/
markdown_url: https://www.pico.net/kb/what-is-a-consolidated-audit-trail.md
---

# What is the Consolidated Audit Trail (CAT)?
The Consolidated Audit Trail, usually shortened to CAT, is a central record of order and trade events in US equities and listed options. It was created by the SEC under Rule 613 and built out through the CAT NMS Plan, so that regulators can reconstruct market activity across every venue and participating firm from a single source rather than assembling it from each one separately.

## What it replaced

Before CAT, reconstructing an event across venues meant requesting data from each one, in different formats, with clocks that did not necessarily agree. Piecing together a single afternoon could take weeks, and the result was only as good as the least precise contributor. CAT addresses that by standardising what is reported, in what format, and to what level of time precision.

## Why timestamps are the hard part

Most of the reporting burden is ordinary data engineering. The timestamps are not. An order lifecycle may touch several systems within microseconds, and a record that cannot place those events in the right order is not a reconstruction so much as a list.

That is why precision and clock synchronisation are treated as first-class requirements rather than implementation details. A timestamp is only meaningful relative to a reference every other participant also uses, which in practice means traceability to NIST and continuous evidence that the traceability held.

## Where the data comes from

Firms generally have two options. They can instrument the trading applications themselves, which means changing systems that are deliberately kept stable and adding work to a latency-sensitive path. Or they can derive the record from the network, where the same order events are already visible in transit.

The second approach has a property the first lacks: it is independent of the systems being reported on. If an application and the wire disagree about when something happened, only an external observer can say which is right.

## Capturing the record without changing trading systems

Corvil takes the network approach, deploying as a passive overlay that timestamps order lifecycle events to nanosecond precision with NIST-traceable clock synchronisation and continuous integrity monitoring. See [Corvil for Consolidated Audit Trail](https://www.pico.net/products/corvil-analytics/consolidated-audit-trail/) for how the record is collected and reported, and the related question of [trade reconstruction](https://www.pico.net/kb/what-is-trade-reconstruction/), which is what the record ultimately exists to support.