Protect system media containing CUI — 9 requirements covering 21 total SPRS points.
The Media Protection domain requires organizations to protect system media containing CUI — both digital and non-digital — including how it is accessed, marked, stored, transported, sanitized, and disposed of. Removable media and physical documents are among the easiest vectors for CUI exfiltration. A USB drive leaving a facility, a hard drive disposed of without sanitization, or a printout left in a recycling bin can each expose CUI as effectively as a network breach.
All Media Protection requirements assessed during a CMMC Level 2 certification.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| MP.L2-3.8.1 | Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. | 3 | Yes |
| MP.L2-3.8.2 | Limit access to CUI on system media to authorized users. | 3 | Yes |
| MP.L2-3.8.3 | Sanitize or destroy system media before disposal or reuse. | 5 | Conditional |
| MP.L2-3.8.4 | Mark media with necessary CUI markings and distribution limitations. | 1 | Yes |
| MP.L2-3.8.5 | Control access to media containing CUI and maintain accountability for media during transport. | 1 | Yes |
| MP.L2-3.8.6 | Implement cryptographic mechanisms to protect the confidentiality of CUI during transport unless otherwise protected by alternative physical safeguards. | 1 | Yes |
| MP.L2-3.8.7 | Control the use of removable media on system components. | 5 | Conditional |
| MP.L2-3.8.8 | Prohibit the use of portable storage devices when such devices have no identifiable owner. | 3 | Yes |
| MP.L2-3.8.9 | Protect the confidentiality of backup CUI at storage locations. | 1 | Yes |
Platform capabilities that address Media Protection requirements.
Automatically classify and tag system media containing CUI so protection controls are applied consistently across paper and digital formats.
Track media sanitization and destruction activities with auditable records that satisfy assessor evidence requirements for disposal procedures.
Verify that cryptographic mechanisms are in place for CUI during transport and maintain chain-of-custody documentation for media in transit.
Define and enforce policies governing removable media usage on system components, including ownership verification and access restrictions.
Continuously monitor backup storage locations to ensure CUI confidentiality protections remain in place and alert on configuration drift.
Generate and apply compliant CUI markings and distribution limitation statements to media, reducing manual errors and ensuring consistency.
These tools are commonly used by defense contractors to satisfy MP requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will verify procedures for marking CUI media, controlling access to removable storage, sanitizing media before disposal, and securing paper records. They’ll look for evidence that portable storage device policies are enforced technically — not just in policy documents.
A single mishandled USB drive or unencrypted backup can expose controlled information at scale. Media protection is where policy meets physical reality.
1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.
Request a Demo