MP Domain

Media Protection
CMMC Level 2

Protect system media containing CUI — 9 requirements covering 21 total SPRS points.

9 Requirements
21 SPRS Points at Risk
100% Complete Coverage

Media Protection Domain Overview

The Media Protection domain requires organizations to protect system media containing CUI — both digital and non-digital — including how it is accessed, marked, stored, transported, sanitized, and disposed of. Removable media and physical documents are among the easiest vectors for CUI exfiltration. A USB drive leaving a facility, a hard drive disposed of without sanitization, or a printout left in a recycling bin can each expose CUI as effectively as a network breach.

NIST SP 800-171 Requirements

All Media Protection requirements assessed during a CMMC Level 2 certification.

RequirementDescriptionPointsPOA&M
MP.L2-3.8.1Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.3Yes
MP.L2-3.8.2Limit access to CUI on system media to authorized users.3Yes
MP.L2-3.8.3Sanitize or destroy system media before disposal or reuse.5Conditional
MP.L2-3.8.4Mark media with necessary CUI markings and distribution limitations.1Yes
MP.L2-3.8.5Control access to media containing CUI and maintain accountability for media during transport.1Yes
MP.L2-3.8.6Implement cryptographic mechanisms to protect the confidentiality of CUI during transport unless otherwise protected by alternative physical safeguards.1Yes
MP.L2-3.8.7Control the use of removable media on system components.5Conditional
MP.L2-3.8.8Prohibit the use of portable storage devices when such devices have no identifiable owner.3Yes
MP.L2-3.8.9Protect the confidentiality of backup CUI at storage locations.1Yes

How 1TEN Covers This Domain

Platform capabilities that address Media Protection requirements.

Media Classification Engine

Automatically classify and tag system media containing CUI so protection controls are applied consistently across paper and digital formats.

3.8.13.8.4

Sanitization Workflow Tracker

Track media sanitization and destruction activities with auditable records that satisfy assessor evidence requirements for disposal procedures.

3.8.3

Transport Encryption Validator

Verify that cryptographic mechanisms are in place for CUI during transport and maintain chain-of-custody documentation for media in transit.

3.8.53.8.6

Removable Media Policy Enforcer

Define and enforce policies governing removable media usage on system components, including ownership verification and access restrictions.

3.8.73.8.8

Backup Protection Monitor

Continuously monitor backup storage locations to ensure CUI confidentiality protections remain in place and alert on configuration drift.

3.8.9

CUI Marking Automation

Generate and apply compliant CUI markings and distribution limitation statements to media, reducing manual errors and ensuring consistency.

3.8.43.8.2

Common Tools for MP Compliance

These tools are commonly used by defense contractors to satisfy MP requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will verify procedures for marking CUI media, controlling access to removable storage, sanitizing media before disposal, and securing paper records. They’ll look for evidence that portable storage device policies are enforced technically — not just in policy documents.

MP Domain

A single mishandled USB drive or unencrypted backup can expose controlled information at scale. Media protection is where policy meets physical reality.

Related Domains

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo