Physical Protection (PE): the 6 CMMC Level 2 requirements a subcontractor self-assesses
The Physical Protection family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 6 high, 0 medium; 0 of 6 need CMMC-specific evidence
- SOC 2reuse candidates 3 high, 2 medium; 1 of 6 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 5 high, 0 medium; 1 of 6 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 6 high, 0 medium; 0 of 6 need CMMC-specific evidence
- CIS Controls v8reuse candidates 1 high, 0 medium; 5 of 6 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 6 high, 0 medium; 0 of 6 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 6 high, 0 medium; 0 of 6 need CMMC-specific evidence
The requirements
6CMMC L2 PE.L2-3.10.1Limit Physical Access 5 points in the score
Limit physical access to systems, equipment and their operating environments to authorized individuals.
What an assessor asks to see: Physical access authorization list for controlled areas; Access control mechanism evidence such as badge system configuration; Periodic review of who holds physical access
Where subcontractors usually fall short: Access lists not reviewed so departed staff retain badges; Server and equipment areas within general office access; Authorization granted verbally without record
CMMC L2 PE.L2-3.10.2Monitor Facility 5 points in the score
Protect and monitor the physical facility and the support infrastructure that organizational systems depend on.
What an assessor asks to see: Facility protection measures and monitoring arrangements; Evidence support infrastructure such as power and cabling is protected; Monitoring records or alarm and camera coverage evidence
Where subcontractors usually fall short: Facility monitored while support infrastructure is not; Monitoring equipment installed but recordings unreviewed; Shared or landlord controlled infrastructure unassessed
CMMC L2 PE.L2-3.10.3Escort Visitors 1 point in the score
Escort visitors and monitor visitor activity while they are on site.
What an assessor asks to see: Visitor procedure requiring escort and monitoring; Visitor logs recording escort assignment; Evidence monitoring continues for the visit duration
Where subcontractors usually fall short: Visitors signed in but not escorted; Contractors treated as staff and left unescorted; Escort recorded at entry only
CMMC L2 PE.L2-3.10.4Physical Access Logs 1 point in the score
Maintain audit logs recording physical access to facilities holding organizational systems.
What an assessor asks to see: Physical access logs, electronic or manual; Defined retention period for physical access records; Evidence logs are reviewed
Where subcontractors usually fall short: Logs captured but never retained or reviewed; Manual visitor books used with incomplete entries; Badge system logs overwritten quickly
CMMC L2 PE.L2-3.10.5Manage Physical Access 1 point in the score
Control and manage physical access devices such as keys, locks, combinations and badge readers.
What an assessor asks to see: Inventory of physical access devices and their holders; Issue, return and change records for keys and combinations; Evidence combinations and locks are changed on personnel change
Where subcontractors usually fall short: Keys issued with no inventory or return process; Combinations never changed after staff departures; Master keys uncontrolled
CMMC L2 PE.L2-3.10.6Alternative Work Sites 1 point in the score
Enforce safeguarding measures for CUI at alternate work sites such as home or remote offices.
What an assessor asks to see: Alternate work site policy defining required safeguards; Evidence safeguards are communicated and acknowledged; Assessment or attestation of alternate work site conditions
Where subcontractors usually fall short: Remote work policy silent on physical safeguards for CUI; Safeguards defined but compliance never checked; Printing and paper CUI at home not addressed