Limit physical access to CUI systems and facilities — 6 requirements covering 14 total SPRS points.
The Physical Protection domain requires organizations to limit and control physical access to organizational systems and the facilities where they are housed, including monitoring physical access to detect and respond to incidents. Physical access bypasses most technical controls. An adversary with physical access to a workstation, server, or storage device can extract CUI without leaving a network trace. For defense contractors operating shop floors and engineering environments, physical security is inseparable from information security.
Every NIST SP 800-171 Rev 2 requirement in the PE family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| PE.L2-3.10.1 | Limit physical access to organizational systems to authorized individuals. | 3 | Yes |
| PE.L2-3.10.2 | Protect and monitor the physical facility and support infrastructure for organizational systems. | 3 | Yes |
| PE.L2-3.10.3 | Escort visitors and monitor visitor activity. | 1 | Yes |
| PE.L2-3.10.4 | Maintain audit logs of physical access. | 3 | Yes |
| PE.L2-3.10.5 | Control and manage physical access devices. | 3 | Yes |
| PE.L2-3.10.6 | Enforce safeguarding measures for CUI at alternate work sites. | 1 | Yes |
Document your facility access controls, authorized personnel lists, and physical security boundaries. The platform maps each area to its access requirements and authorization levels, satisfying 3.10.1 with assessment-ready evidence.
Track physical security monitoring systems including cameras, alarms, environmental controls, and infrastructure protection measures. The platform documents your facility protection program for 3.10.2 compliance.
Maintain visitor logs, escort procedures, and physical access audit trails. The platform captures visitor activity, badge assignments, and access device inventories for 3.10.3, 3.10.4, and 3.10.5 requirements.
Document and enforce CUI safeguarding measures for remote work locations, home offices, and alternate processing sites. The platform tracks work site authorizations and security controls for 3.10.6 compliance.
These tools are commonly used by defense contractors to satisfy PE requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.
Assessors will tour in-scope facilities to verify that access controls are in place — locked doors, badge readers, visitor logs, and clean-desk policies. They'll check that escort procedures exist for visitors and that physical access to server rooms and workstations is appropriately restricted.
A firewall means nothing if someone can walk into your server room. Physical protection is the foundation every other domain builds on.
1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.
Request a Demo