Media Protection (MP): the 9 CMMC Level 2 requirements a subcontractor self-assesses
The Media Protection family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 7 high, 1 medium; 1 of 9 need CMMC-specific evidence
- SOC 2reuse candidates 6 high, 2 medium; 1 of 9 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 3 high, 4 medium; 2 of 9 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
- CIS Controls v8reuse candidates 6 high, 2 medium; 1 of 9 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
The requirements
9CMMC L2 MP.L2-3.8.1Media Protection 3 points in the score
Physically control and securely store system media holding CUI, in both paper and digital form.
What an assessor asks to see: Media storage arrangements and physical security of storage locations; Media inventory covering paper and digital media holding CUI; Access records for media storage areas
Where subcontractors usually fall short: Digital media controlled while paper records are not; Media stored in unsecured shared areas; No inventory so media cannot be accounted for
CMMC L2 MP.L2-3.8.2Media Access 3 points in the score
Limit access to CUI held on system media to users authorized to see it.
What an assessor asks to see: Authorization list for access to CUI bearing media; Access control mechanism for media storage and digital media; Records of access granted and revoked
Where subcontractors usually fall short: Access limited by physical location rather than by authorization; Authorization not revoked when roles change; Backup media accessible to general operations staff
CMMC L2 MP.L2-3.8.3Media Disposal 5 points in the score
Sanitize or destroy system media containing CUI before the media is disposed of or released for reuse.
What an assessor asks to see: Sanitization and destruction procedure with approved methods; Sanitization or destruction certificates and records; Evidence the method matches the media type
Where subcontractors usually fall short: Reformatting treated as sanitization; Disposal handled by a third party without certificates; Reuse within the organization skips sanitization
CMMC L2 MP.L2-3.8.4Media Markings 1 point in the score
Mark media with the CUI markings and distribution limitations that apply to its contents.
What an assessor asks to see: Marking procedure defining required markings and limitations; Sample marked media, paper and digital; Evidence marking is applied at creation
Where subcontractors usually fall short: Marking applied to documents but not to the media itself; Distribution limitations omitted from markings; Legacy media unmarked with no remediation plan
CMMC L2 MP.L2-3.8.5Media Accountability 1 point in the score
Restrict who may access media holding CUI, and keep that media accounted for whenever it moves beyond controlled areas.
What an assessor asks to see: Transport procedure including custody and accountability steps; Transport logs recording media, custodian and destination; Evidence of receipt confirmation at destination
Where subcontractors usually fall short: Media transported without a custody record; Accountability ends when media leaves the site; Courier arrangements unassessed
CMMC L2 MP.L2-3.8.6Portable Storage Encryption 1 point in the score
Apply cryptographic protection to CUI held on digital media during transport, unless equivalent alternative physical safeguards protect it instead.
What an assessor asks to see: Encryption configuration for portable and transported digital media; Evidence of encryption status for media in transit; Documented alternative physical safeguards where encryption is not used
Where subcontractors usually fall short: Encryption assumed but not verified per device; Alternative safeguards claimed without documentation; Backup media shipped unencrypted
CMMC L2 MP.L2-3.8.7Removable Media 5 points in the score
Govern which removable media may be used on system components, and enforce that restriction at the components themselves.
What an assessor asks to see: Removable media policy defining permitted use; Technical control over removable media ports and devices; Records of approved exceptions
Where subcontractors usually fall short: Policy exists with no technical enforcement; Control applied to storage devices but not to other removable media; Exceptions granted without expiry
CMMC L2 MP.L2-3.8.8Shared Media 3 points in the score
Prohibit the use of portable storage devices that have no identifiable owner.
What an assessor asks to see: Policy prohibiting unidentified portable storage; Technical control blocking unknown devices; Awareness material communicating the prohibition
Where subcontractors usually fall short: Prohibition stated but any device still mounts; Ownership identification process undefined; Found devices connected to check contents
CMMC L2 MP.L2-3.8.9Protect Backups 1 point in the score
Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.
What an assessor asks to see: Backup inventory identifying which backups contain CUI; Protection applied at backup storage locations, encryption or physical control; Access controls and records for backup storage
Where subcontractors usually fall short: Production data protected while backups are not; Offsite and cloud backup locations unassessed; Backup encryption keys stored alongside the backups