PE Domain

Physical Protection CMMC Level 2

Limit physical access to CUI systems and facilities — 6 requirements covering 14 total SPRS points.

6 Requirements
14 SPRS Points at Risk
100% Complete Coverage

Physical Protection Domain Overview

The Physical Protection domain requires organizations to limit and control physical access to organizational systems and the facilities where they are housed, including monitoring physical access to detect and respond to incidents. Physical access bypasses most technical controls. An adversary with physical access to a workstation, server, or storage device can extract CUI without leaving a network trace. For defense contractors operating shop floors and engineering environments, physical security is inseparable from information security.

All 6 Physical Protection Requirements

Every NIST SP 800-171 Rev 2 requirement in the PE family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
PE.L2-3.10.1Limit physical access to organizational systems to authorized individuals.3Yes
PE.L2-3.10.2Protect and monitor the physical facility and support infrastructure for organizational systems.3Yes
PE.L2-3.10.3Escort visitors and monitor visitor activity.1Yes
PE.L2-3.10.4Maintain audit logs of physical access.3Yes
PE.L2-3.10.5Control and manage physical access devices.3Yes
PE.L2-3.10.6Enforce safeguarding measures for CUI at alternate work sites.1Yes

How 1TEN Covers This Domain

Physical Access Control Documentation

Document your facility access controls, authorized personnel lists, and physical security boundaries. The platform maps each area to its access requirements and authorization levels, satisfying 3.10.1 with assessment-ready evidence.

Facility Monitoring & Infrastructure

Track physical security monitoring systems including cameras, alarms, environmental controls, and infrastructure protection measures. The platform documents your facility protection program for 3.10.2 compliance.

Visitor Management & Access Logs

Maintain visitor logs, escort procedures, and physical access audit trails. The platform captures visitor activity, badge assignments, and access device inventories for 3.10.3, 3.10.4, and 3.10.5 requirements.

Alternate Work Site Safeguards

Document and enforce CUI safeguarding measures for remote work locations, home offices, and alternate processing sites. The platform tracks work site authorizations and security controls for 3.10.6 compliance.

Common Tools for PE Compliance

These tools are commonly used by defense contractors to satisfy PE requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will tour in-scope facilities to verify that access controls are in place — locked doors, badge readers, visitor logs, and clean-desk policies. They'll check that escort procedures exist for visitors and that physical access to server rooms and workstations is appropriately restricted.

Why This Domain Matters
A firewall means nothing if someone can walk into your server room. Physical protection is the foundation every other domain builds on.

Related Domains

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo