Why Physical Security Is Not an Afterthought in CMMC
Most CMMC compliance conversations focus on network architecture, access control policies, and audit logging. Physical security receives less attention, which is precisely why it produces findings during assessments. An adversary with physical access to a workstation, a server room, or an unlocked laptop does not need to defeat your firewall. Physical access bypasses most technical controls entirely.
For small defense contractors, the PE domain is often the one where the gap between assumed and actual compliance is largest. A locked front door is not a physical security program. The six requirements in this domain describe a layered, documented, and auditable physical access control system, and a C3PAO assessor will walk your facility to verify that what is in your SSP matches what they see.
None of the six PE requirements appear on the list of controls prohibited from POA&M deferral. That means gaps in physical security can be documented in a POA&M and remediated within the 180-day window, provided the rest of your assessment supports a conditional CMMC status. That said, arriving at a C3PAO assessment with no physical access program in place is a significant indicator to assessors that compliance posture across other domains may be similarly informal.
All Six PE Domain Requirements
The Physical Protection domain maps directly to NIST SP 800-171 section 3.10. Every requirement below applies to your CUI environment, which means the systems, facilities, and work sites where CUI is processed, stored, or transmitted.
| Requirement | Description | SPRS | POA&M Eligible |
|---|---|---|---|
| PE.L2-3.10.1 | Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals. | 3 pts | Yes |
| PE.L2-3.10.2 | Protect and monitor the physical facility and support infrastructure for organizational systems. | 3 pts | Yes |
| PE.L2-3.10.3 | Escort visitors and monitor visitor activity. | 1 pt | Yes |
| PE.L2-3.10.4 | Maintain audit logs of physical access. | 3 pts | Yes |
| PE.L2-3.10.5 | Control and manage physical access devices (keys, key cards, combinations, access badges). | 3 pts | Yes |
| PE.L2-3.10.6 | Enforce safeguarding measures for CUI at alternate work sites. | 1 pt | Yes |
Facility Controls: Requirements 3.10.1, 3.10.2, and 3.10.5
The first three facility-facing requirements work together to define a complete physical access control program for your CUI environment. They address who can enter, how the facility is monitored, and how the physical credentials that grant access are managed.
PE.L2-3.10.1: Limit Physical Access to Authorized Individuals
This requirement establishes the foundation of your physical access program. Every system, piece of equipment, and operating environment where CUI is present must be physically accessible only to individuals who are explicitly authorized. That authorization must be documented, not assumed.
In practice, this means server rooms and network closets are locked and access is restricted to IT staff. Workstations used for CUI are in areas where unauthorized individuals cannot sit down and use them. Engineering areas with CUI drawings on screens are not accessible to visitors, vendors, or employees with no business need to be there.
PE.L2-3.10.2: Protect and Monitor the Physical Facility
Limiting access is one half of the requirement. Monitoring to detect unauthorized access attempts is the other. 3.10.2 requires that the physical facility and its supporting infrastructure be both protected and monitored.
Protection typically means physical barriers: locks, doors, access control systems, and perimeter security. Monitoring means surveillance cameras, alarm systems, or security procedures that detect and respond to physical access events. Both elements must be present. A facility with locked doors but no monitoring for after-hours intrusion satisfies the letter of protection but not the monitoring obligation.
Supporting infrastructure deserves specific attention here. Power systems, HVAC, and network cabling that serves CUI systems are within scope for 3.10.2. A locked server room with an unlocked utility closet containing the same server's power distribution and network connections is an incomplete control.
PE.L2-3.10.5: Control and Manage Physical Access Devices
Keys, key cards, access badges, PIN combinations, and any other credentials that grant physical access to CUI areas must be managed as controlled items. This requirement has several components assessors evaluate individually.
| Control Element | What It Requires |
|---|---|
| Inventory of access devices | You must know what physical access credentials exist, who holds them, and what areas they grant access to. An undocumented spare key in a desk drawer is a gap. |
| Issuance and return procedures | Access credentials must be formally issued and returned. When an employee leaves or changes roles, their credentials must be collected and deactivated. This mirrors the account termination requirement in the AC domain but applies to physical credentials. |
| Lost or stolen credential procedures | A documented procedure for responding to a lost or stolen access credential. For key card systems, deactivation is immediate. For physical keys, a response plan is required. |
| Periodic review | Access authorizations should be reviewed periodically to confirm that current credential holders still have a business need for the access they hold. |
Visitor Controls and Physical Access Logs: Requirements 3.10.3 and 3.10.4
PE.L2-3.10.3: Escort Visitors and Monitor Visitor Activity
Any individual who is not an authorized employee and who enters an area where CUI systems are present must be escorted by an authorized employee and monitored throughout the visit. The requirement does not define "visitor" narrowly. Delivery personnel, cleaning crews, IT vendors, building maintenance staff, and any other non-employee who enters a CUI area qualifies.
Escort procedures must be defined in policy and practiced consistently. An assessor will ask how visitors are handled, who is responsible for escort, what happens when a visitor needs to access a restricted area, and whether there is a process for situations where no escort is available. They will also review visitor log records to verify that the procedure is being followed in practice, not just on paper.
One common gap: organizations have visitor sign-in procedures at the front desk but no escort requirement once the visitor is inside. Signing in at reception does not satisfy 3.10.3. An authorized employee must accompany the visitor throughout their time in any CUI-relevant area.
PE.L2-3.10.4: Maintain Audit Logs of Physical Access
Physical access to CUI facilities must be logged and those logs must be retained. The purpose is the same as any other audit log: to support detection of and response to unauthorized access events, and to provide a record for investigation when something goes wrong.
What qualifies as a physical access audit log depends on your access control technology. A badge reader system that logs entry and exit events with timestamps and individual identifiers is the most straightforward implementation. A manual sign-in sheet is the minimum viable version, but it requires discipline to maintain accurately and is easy to challenge during an assessment.
Visitor logs are a component of 3.10.4 as well as 3.10.3. They serve dual purpose: they document escort compliance (3.10.3) and contribute to the physical access audit record (3.10.4). A well-maintained visitor log that captures name, organization, purpose, escort name, entry time, and exit time satisfies both requirements simultaneously.
Remote Work and Alternate Work Sites: PE.L2-3.10.6
3.10.6 is the requirement that generates the most questions and the most unwarranted anxiety. The full text is straightforward: enforce safeguarding measures for CUI at alternate work sites. What it does not say is as important as what it does. It does not require a dedicated locked office. It does not require a home SCIF. It does not require physical inspections of employee residences.
What it requires is that your organization define what physical safeguards are expected at alternate work sites, communicate those expectations to employees, and have some reasonable basis to believe they are being followed. The responsibility for defining adequate safeguards belongs to the organization, not to individual employees.
What a Compliant Alternate Work Site Policy Covers
| Policy Element | What It Should Address |
|---|---|
| Screen privacy | CUI must not be visible to household members or other individuals who are not authorized. Employees working in shared spaces must use privacy screens or work in a location where the screen is not visible to others. |
| Physical access to devices | CUI devices must not be left unattended and unlocked. Screen lock must be enabled and set to a short timeout. Household members must not be able to use CUI devices. |
| Printing restrictions | CUI must not be printed at home unless the printer is specifically authorized and output is handled in accordance with the organization's media protection policy. In most cases, home printing of CUI should be prohibited outright. |
| Physical document handling | Any physical CUI materials (if permitted) must be stored securely when not in use and disposed of through authorized means. Home recycling bins and household shredders are not acceptable CUI disposal methods. |
| Reporting requirements | Employees must know how to report a physical security incident at an alternate work site, including loss or theft of a device, inadvertent disclosure to household members, or loss of physical CUI materials. |
Employee Acknowledgment
The policy itself is necessary but not sufficient. Assessors want evidence that employees have received, read, and acknowledged the alternate work site policy. A signed acknowledgment form or a documented training completion record serves this purpose. The acknowledgment should be renewed when the policy changes and at a defined periodic interval.
Technical Controls as Compensating Measures
Because organizations cannot directly inspect home environments, technical controls carry more of the compliance burden for 3.10.6 than they do for facility-based requirements. The following technical controls strengthen your posture under this requirement and demonstrate that physical safeguarding at alternate sites is enforced beyond just policy.
| Technical Control | How It Supports 3.10.6 |
|---|---|
| Screen lock via MDM or group policy | Automatic lock after a defined inactivity period, enforced centrally rather than left to employee discretion. Prevents household members from accessing an unattended CUI session. |
| Full disk encryption on remote endpoints | If a device is lost or stolen, encryption limits the physical access exposure. Also required under other NIST SP 800-171 controls, making this a cross-domain investment. |
| Endpoint DLP with print restrictions | If home printing of CUI is prohibited, a technical control blocking print jobs to unauthorized printers enforces the policy without relying on employee judgment. |
| VPN-only access to CUI systems | A physically compromised device does not automatically compromise CUI if the attacker cannot authenticate to the VPN. Removes the assumption that device possession equals data access. |
| Remote wipe capability | The ability to remotely wipe a lost or stolen device reduces physical access risk and is directly relevant to assessor conversations about 3.10.6 incident response procedures. |
What to Expect During the Physical Security Assessment
The PE domain assessment includes all three CMMC examination methods: document review, interviews, and physical testing. The physical testing component is what distinguishes PE from most other domains. Assessors will physically tour your facility.
The Facility Walkthrough
Expect the assessment team to walk every area of your facility where CUI systems are present. They will observe whether doors to server rooms and CUI work areas are locked. They will note whether workstations display CUI in areas visible to visitors or unauthorized personnel. They will look for unlocked server racks, uncontrolled network access points, and any physical access paths that are not accounted for in your SSP boundary documentation.
The walkthrough findings will be compared against your network diagram and SSP boundary description. Discrepancies between what the SSP describes and what assessors observe are findings regardless of how well-documented the policy is.
Document Review
Assessors will request your physical access control policy, your visitor log records, your physical access credential inventory, and your alternate work site policy with employee acknowledgments. They will look for evidence that logs are being actively maintained, not just that a log exists. A visitor log with the last entry six months ago in an organization that receives regular vendor visits is a finding.
Interviews
Expect questions directed at both IT staff and general employees. Common interview questions for PE include: who is authorized to access the server room and how is that list maintained; what happens when a visitor arrives who needs to access a restricted area; what do you do if you lose your access badge; and what are the rules for working with CUI at home. The answers should be consistent with the documented policies and with each other.
Common PE Findings
| Finding | Why It Matters |
|---|---|
| No visitor log or an inconsistently maintained one | The most common PE finding across assessments. A log that exists but has not been updated in months is treated the same as no log. |
| Server room or network closet accessible without dedicated access control | A door that is "usually locked" is not a controlled door. Access must be consistently enforced, not situationally applied. |
| Physical access credential inventory does not match actual issued credentials | Former employees' badges still active, undocumented spare keys, and combinations not changed after departures are all gaps under 3.10.5. |
| No alternate work site policy | The second most common PE finding for organizations with remote workers. The complete absence of any policy is an immediate finding with no ambiguity. |
| Alternate work site policy exists but employees have not acknowledged it | A policy in a shared drive that no one has read does not satisfy the requirement. Documented acknowledgment is required evidence. |
| CUI workstations visible to visitors in open areas | Particularly common in small contractor offices where the CUI environment is not separated from general workspace. Observation alone constitutes a finding under 3.10.1. |
Frequently Asked Questions
No. PE.L2-3.10.6 does not specify what physical controls must be in place at alternate work sites. It requires that your organization define and enforce safeguarding measures appropriate for the environment. A dedicated locked office is ideal but not mandated. Reasonable alternatives include a documented policy requiring screen privacy, device locking, and printing restrictions, combined with technical controls that enforce those expectations. What is not acceptable is having no policy at all.
Yes. Any individual who is not an authorized employee and who enters an area where CUI systems are present is a visitor for purposes of 3.10.3. This includes IT vendors, cleaning crews, building maintenance personnel, delivery drivers, auditors, and any other non-employee. The escort requirement applies to all of them. Your visitor log should capture every such visit.
Yes. Physical keys are a legitimate access control mechanism. The challenge is that physical keys produce no audit log (satisfying 3.10.4 requires a supplemental manual log) and are harder to manage than electronic credentials when employees leave. If you use physical keys, you need a documented inventory of all keys, a clear issuance and return process, and a plan for re-keying when keys are lost or when an employee with key access departs. Electronic badge systems are easier to audit and manage, but they are not required if physical keys are properly controlled and documented.
No. None of the six PE requirements appear on the list of controls prohibited from POA&M deferral under 32 CFR 170.21. If a PE gap is identified during your C3PAO assessment, it can be placed on a POA&M and remediated within the 180-day conditional window. That said, arriving at a C3PAO assessment with no physical access program is a significant red flag that may affect how assessors approach the rest of your assessment.
Requirements 3.10.1 through 3.10.5 apply to facilities where CUI systems are present. If your organization is fully remote with no physical office and no on-premises infrastructure, those requirements apply to wherever your servers, network equipment, and CUI workstations are located. If you use a colocation facility for servers, the colo's physical security controls are relevant and should be documented in your SSP. If all infrastructure is cloud-hosted in a FedRAMP-authorized environment, the physical security controls for that infrastructure are the cloud provider's responsibility and should be reflected in your documentation. PE.L2-3.10.6 still applies fully, as all work sites are alternate work sites in a fully remote organization.