MP.L2-3.8.1 — Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
What this control requires
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
Source: CMMC L2 v2.13 MP.L2-3.8.1 / NIST SP 800-171 R2 3.8.1 (official control text).
Why this matters
When Controlled Unclassified Information lives on physical media — USB drives, printed designs, backup tapes, or even handwritten notes — unauthorized access is as simple as someone walking away with it. This control requires the organization to physically secure all media containing CUI through locks, logs, and accountability procedures. Without proper storage and tracking, sensitive data can be stolen, lost, or inadvertently disclosed through careless handling. Physical protection is the foundational layer that complements digital access controls, ensuring CUI cannot be compromised through the oldest threat vector: someone simply taking it.
What evidence assessors expect
Assessors typically look for: photo, PDF, screenshot. FORCE coaches you through the exact implementation steps and captures each artifact in-platform.
Related controls
See your live posture on MP.L2-3.8.1.
FORCE shows where you stand on this control and walks you through closing it.
Start a free trial tenant →