Subcontractor CMMC Tracker

Media Protection (MP): the 9 CMMC Level 2 requirements a subcontractor self-assesses

The Media Protection family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

9
CMMC L2 MP.L2-3.8.1Media Protection 3 points in the score

Physically control and securely store system media holding CUI, in both paper and digital form.

What an assessor asks to see: Media storage arrangements and physical security of storage locations; Media inventory covering paper and digital media holding CUI; Access records for media storage areas
Where subcontractors usually fall short: Digital media controlled while paper records are not; Media stored in unsecured shared areas; No inventory so media cannot be accounted for
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.2Media Access 3 points in the score

Limit access to CUI held on system media to users authorized to see it.

What an assessor asks to see: Authorization list for access to CUI bearing media; Access control mechanism for media storage and digital media; Records of access granted and revoked
Where subcontractors usually fall short: Access limited by physical location rather than by authorization; Authorization not revoked when roles change; Backup media accessible to general operations staff
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.3Media Disposal 5 points in the score

Sanitize or destroy system media containing CUI before the media is disposed of or released for reuse.

What an assessor asks to see: Sanitization and destruction procedure with approved methods; Sanitization or destruction certificates and records; Evidence the method matches the media type
Where subcontractors usually fall short: Reformatting treated as sanitization; Disposal handled by a third party without certificates; Reuse within the organization skips sanitization
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.4Media Markings 1 point in the score

Mark media with the CUI markings and distribution limitations that apply to its contents.

What an assessor asks to see: Marking procedure defining required markings and limitations; Sample marked media, paper and digital; Evidence marking is applied at creation
Where subcontractors usually fall short: Marking applied to documents but not to the media itself; Distribution limitations omitted from markings; Legacy media unmarked with no remediation plan
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.5Media Accountability 1 point in the score

Restrict who may access media holding CUI, and keep that media accounted for whenever it moves beyond controlled areas.

What an assessor asks to see: Transport procedure including custody and accountability steps; Transport logs recording media, custodian and destination; Evidence of receipt confirmation at destination
Where subcontractors usually fall short: Media transported without a custody record; Accountability ends when media leaves the site; Courier arrangements unassessed
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.6Portable Storage Encryption 1 point in the score

Apply cryptographic protection to CUI held on digital media during transport, unless equivalent alternative physical safeguards protect it instead.

What an assessor asks to see: Encryption configuration for portable and transported digital media; Evidence of encryption status for media in transit; Documented alternative physical safeguards where encryption is not used
Where subcontractors usually fall short: Encryption assumed but not verified per device; Alternative safeguards claimed without documentation; Backup media shipped unencrypted
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.7Removable Media 5 points in the score

Govern which removable media may be used on system components, and enforce that restriction at the components themselves.

What an assessor asks to see: Removable media policy defining permitted use; Technical control over removable media ports and devices; Records of approved exceptions
Where subcontractors usually fall short: Policy exists with no technical enforcement; Control applied to storage devices but not to other removable media; Exceptions granted without expiry
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.8Shared Media 3 points in the score

Prohibit the use of portable storage devices that have no identifiable owner.

What an assessor asks to see: Policy prohibiting unidentified portable storage; Technical control blocking unknown devices; Awareness material communicating the prohibition
Where subcontractors usually fall short: Prohibition stated but any device still mounts; Ownership identification process undefined; Found devices connected to check contents
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 MP.L2-3.8.9Protect Backups 1 point in the score

Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.

What an assessor asks to see: Backup inventory identifying which backups contain CUI; Protection applied at backup storage locations, encryption or physical control; Access controls and records for backup storage
Where subcontractors usually fall short: Production data protected while backups are not; Offsite and cloud backup locations unassessed; Backup encryption keys stored alongside the backups
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)