The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · Media Protection, NIST SP 800-171, and CMMC evidence

CMMC Media Protection Requirements: All 9 Controls, Scored, and the Evidence to Prove Them

Last updated:

Last verified: against 32 CFR Part 170, NIST SP 800-171 Revision 2, DFARS, and related primary sources.

By The Defense Compliance Report Editorial Team Last verified: August 19, 2026


CMMC media protection requirements are the nine security requirements in the Media Protection family of NIST SP 800-171 Revision 2 — numbered 3.8.1 through 3.8.9 — which CMMC Level 2 adopts word for word under 32 CFR § 170.14(c)(3). They cover paper and digital media holding Controlled Unclassified Information: how you store it, who reaches it, how you mark it, how it travels, which removable devices you allow, how you back it up, and how you destroy it.

Here is the part that changes the remediation order: they are not weighted equally. Two of the nine are worth five points each. Three are worth three. Four are worth one. And under the current rule, only the four one-point Media Protection requirements are even eligible to go on a plan of action. Miss one of the five-pointers and your conditional path closes — at any score.

That single fact changes the order you should fix things in. We'll show you the arithmetic, and where it came from.

Current status — read this before you plan around a deadline. Phase I began November 10, 2025. Under 32 CFR § 170.3(e), Phase II was scheduled one calendar year later, on November 10, 2026, making the original Phase I period November 10, 2025 through November 9, 2026. On July 13, 2026, the Department suspended the transition to Phase II, along with later implementation milestones. Phase I self-assessment requirements remain in force where an applicable solicitation or contract requires them. Safeguarding duties under DFARS 252.204-7012 remain in force where your contract includes the clause. The rollout schedule changed. The nine media protection requirements did not. Any page still counting down to November 10, 2026 as a universal enforcement date is stale.


The nine requirements, with what each one is worth

We pulled every point value below directly from the scoring rule at 32 CFR § 170.24(c)(2)(i)(B), reading the regulation's own nested lists rather than a secondhand summary. We read it on August 19, 2026, when eCFR showed Title 32 current as of August 17, 2026.

Requirement — What it actually requires — Type — Objectives — Points lost if NOT MET — POA&M eligible?
RequirementWhat it actually requiresTypeObjectivesPoints lost if NOT METPOA&M eligible?
MP.L2-3.8.1Physically control and securely store media holding CUI — paper and digitalBasic43No
MP.L2-3.8.2Limit access to CUI on media to authorized usersBasic13No
MP.L2-3.8.3Sanitize or destroy media holding CUI before disposal or reuseBasic25No
MP.L2-3.8.4Mark media with applicable CUI markings and distribution limitationsDerived21Potentially
MP.L2-3.8.5Control access and keep accountability while media travels outside controlled areasDerived21Potentially
MP.L2-3.8.6Protect CUI confidentiality on digital media in transport, by cryptography or alternative physical safeguardsDerived11Potentially
MP.L2-3.8.7Control the use of removable media on system componentsDerived15No
MP.L2-3.8.8Prohibit portable storage devices with no identifiable ownerDerived13No
MP.L2-3.8.9Protect the confidentiality of backup CUI at storage locationsDerived11Potentially
Totals3 Basic, 6 Derived15234 of 9

The objective counts are our count from the official CMMC Level 2 Assessment Guide, Version 2.13, disclosed as a count rather than a number the government publishes as a total. The point values and the POA&M column come straight from the rule.

Is this page for you?

This page is for — This page is not for
This page is forThis page is not for
Contractors whose in-scope systems process, store, or transmit CUIDeciding whether your contract requires Level 2 at all — that's a clause question → see CMMC levels
Teams writing or repairing the Media Protection section of an SSPAnyone who only handles Federal Contract Information. You have one media requirement, not nine → see our CMMC Level 1 checklist
Anyone who just got a finding on 3.8.3 or 3.8.7Readers looking for a universal instruction to ban every USB drive. That is not what the rule says
Manufacturers moving files to CNC, OT, or test equipmentLegal, contractual, or compliance advice

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they commit budget.


What are the CMMC media protection requirements?

Answer capsule. CMMC Level 2 includes nine Media Protection requirements, numbered 3.8.1 through 3.8.9, taken without modification from NIST SP 800-171 Revision 2. They govern the storage, access, marking, transport, removable-media use, device ownership, backup protection, and destruction of paper and digital media containing Controlled Unclassified Information. CMMC Level 1 includes one media safeguard, and CMMC Level 3 adds none.

Media Protection is the eighth of the fourteen NIST SP 800-171 families. CMMC calls families "domains," and the two-letter abbreviation is MP. The full requirement identifier follows a format fixed at § 170.14(c)(1): domain, level, then the original NIST number. So MP.L2-3.8.3 is Media Protection, Level 2, NIST requirement 3.8.3.

Three of the nine are Basic requirements and six are Derived. That distinction isn't cosmetic. The rule explains that basic requirements come from FIPS PUB 200 and derived requirements come from the security controls in NIST SP 800-53 Revision 5 — and it explicitly ties the basic/derived designation to how each requirement is scored.

One word in 3.8.1 does more work than any other in this family: "both paper and digital." Media Protection is where CUI stops being an IT problem and becomes a facility problem. Your travelers on the shop floor, the drawing package sitting in the print tray, the inspection records in the QA binder — all of it is system media if it holds CUI.

Why "9 requirements, 15 objectives, 23 points" are three different numbers

People blur these three constantly, and blurring them costs money. They measure different things.

  • Nine is the number of security requirements. This is what your SSP has to describe.
  • Fifteen is the number of assessment objectives — the individual determination statements underneath those nine requirements. This is what actually gets assessed.
  • Twenty-three is the total deduction exposure if all nine were scored NOT MET. It is not a Media Protection score. There is no such thing. Your assessment score covers the full 110-requirement Level 2 set.

The gap between nine and fifteen creates a self-assessment failure point. Under § 170.24(b)(1), a requirement is MET only when "all applicable objectives for the security requirement are satisfied based on evidence." One requirement, four objectives, and you satisfied three of them, means NOT MET. Full deduction.

MP.L2-3.8.1 is the clearest example. Its four objectives ask separately whether paper media is physically controlled, whether digital media is physically controlled, whether paper media is securely stored, and whether digital media is securely stored. A company with an immaculate media library and an unlocked plan room fails on one objective and loses all three points.

Which NIST version CMMC actually uses

CMMC Level 2 currently maps to NIST SP 800-171 Revision 2. Not Revision 3. The rule at § 170.14(c)(3) states that the Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2, and it incorporates that specific revision by reference.

This trips up sharp people. NIST published Revision 3 in May 2024 and now lists Revision 2 as withdrawn. That still does not make Revision 3 the CMMC-controlling version. NIST publishes; the Department regulates. NIST's catalog status and the version incorporated into a federal rule are two separate questions, and they are currently out of sync. Build your CMMC Level 2 assessment baseline to Revision 2. Watch Revision 3 for planning. If a vendor offers to "future-proof" you onto Revision 3 as though it's the live CMMC requirement, that's a sales position, not a regulatory one. Our full authority map is on the Rev. 2 vs Rev. 3 comparison.


Which media protection requirements carry the most scoring risk?

Answer capsule. Under the CMMC Level 2 scoring methodology at 32 CFR § 170.24, MP.L2-3.8.3 (sanitize or destroy) and MP.L2-3.8.7 (control removable media) are each worth five points — the regulation's heaviest tier. MP.L2-3.8.1, 3.8.2, and 3.8.8 are worth three each. The remaining four are worth one each, for a combined Media Protection deduction exposure of 23 points.

The rule doesn't assign those values arbitrarily, and it tells you its reasoning in plain terms.

Five points go to requirements that, if not implemented, "could lead to significant exploitation of the network, or exfiltration of CUI." Three points go to requirements with a "specific and confined effect on the security of the network and its data." One point goes to those with "a limited or indirect effect."

Read that top tier again with 3.8.3 and 3.8.7 in mind. The Department is saying that an unwiped drive leaving your building and an unrestricted USB port are, in its judgment, in the same risk class as failing to limit system access or failing to establish baseline configurations. That is a strong signal about where your first dollar goes.

Point value — Media Protection requirements — Share of family exposure
Point valueMedia Protection requirementsShare of family exposure
5 pointsMP.L2-3.8.3, MP.L2-3.8.710 of 23
3 pointsMP.L2-3.8.1, MP.L2-3.8.2, MP.L2-3.8.89 of 23
1 pointMP.L2-3.8.4, MP.L2-3.8.5, MP.L2-3.8.6, MP.L2-3.8.94 of 23

Media Protection is roughly 8% of the 110 Level 2 requirements. It holds two of the 42 five-point requirements in the entire standard. For a family that looks like filing-cabinet housekeeping, that is a disproportionate share of the risk.

One correction worth making: if a comparison table totals Media Protection at 21 points, it is wrong under the current rule. The values in § 170.24 add to 23. Re-check which requirements the table assigned three points to.

There is no partial credit in this family

The scoring rule allows partial credit on exactly two of the 110 requirements: multifactor authentication (IA.L2-3.5.3) and FIPS-validated encryption (SC.L2-3.13.11). Both are named specifically in § 170.24(c)(2)(i)(B)(4). Neither is in Media Protection.

So there is no "mostly compliant" here. A control is MET or it isn't. A media sanitization program that handles hard drives beautifully and never addresses the copier is a five-point loss, not a four-point loss.


Which media protection requirements can go on a POA&M?

Answer capsule. Four of the nine — MP.L2-3.8.4, 3.8.5, 3.8.6, and 3.8.9 — are potentially eligible for a Plan of Action and Milestones under 32 CFR § 170.21, because they carry one point each and none is among the six one-point requirements the rule separately bars. The other five cannot be deferred, because each is worth more than one point. A single unmet five-point media requirement removes the Conditional Level 2 path regardless of the total score.

A Plan of Action and Milestones (POA&M) is the mechanism that lets a contractor achieve a Conditional CMMC status with a limited set of unmet requirements, then close them out. Three gates matter under § 170.21(a)(2):

  1. The assessment score divided by 110 must be 0.8 or higher — that's 88 of 110.
  2. No requirement on the POA&M may have a point value greater than 1, with one narrow exception involving FIPS-validated encryption.
  3. Six named one-point requirements are also barred: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. None is in Media Protection, but they matter whenever you run whole-assessment arithmetic.

Gate two is the one that matters inside this family. Five of the nine media protection requirements are worth three or five points. None of them are POA&M-eligible. The four that are worth one point are only potentially eligible — they still have to sit inside a POA&M that satisfies every other condition, and a POA&M is not a substitute for implementing the requirement. Anything you do defer must be closed within 180 days of the Conditional status date, or the status expires.

The 105-point company

Here's the arithmetic that makes this concrete. "You need 88" is technically true and practically misleading when the open requirements themselves are not POA&M-eligible.

Company A implements 109 of 110 requirements. The one gap is MP.L2-3.8.3 — nobody documents drive destruction. Score: 105 of 110. That's 95%. And there is no Conditional path, because a five-point requirement cannot go on a POA&M.

Company B implements 88 of 110. Its 22 gaps are all one-point requirements, and none is one of the six one-point requirements expressly barred by § 170.21(a)(2)(iii). Score: 88 — exactly the threshold. A Conditional path remains mathematically available, subject to the rest of the POA&M and assessment conditions, with 180 days to close.

The company that scored seventeen points higher is the one with no Conditional Level 2 path.

This is why point value drives remediation sequence, not just remediation effort. It does not mean the one-point requirements are optional. It means the five-pointers are the ones that can quietly disqualify you while your score still looks respectable to a prime asking for a number.


The honest part: most of this family is cheap to fix

We're an independent trade publication on CMMC 2.0 and DIB compliance, and provider-matching forms on this site may generate referral compensation. So let us say the thing that argues against our own commercial interest, up front.

Most of the nine media protection requirements do not require you to buy anything. They require a written media handling policy, labels, secure storage, a destruction method matched to the medium, endpoint controls that govern removable storage, and a decision about who is authorized. If you came here braced to be told you need a platform, for this family, you mostly don't. Anyone selling you an expensive product as "the media protection solution" is selling you something the rule does not ask for.

Now the pivot, and it's a real one.

The cheap family is the one that quietly ends your Conditional status. Two five-pointers, no deferral path, no partial credit. And the expense was never the control — it's the evidence. Buying the right destruction equipment takes an afternoon. Producing an asset-specific destruction record month after month, reconciling it to your inventory, and retaining assessment evidence for six years where the rule requires it is an operating process with an owner and a budget line.

The rule is unusually blunt about this. Under § 170.24(b)(1), all evidence must be "in final form and not draft," and it names what doesn't count: "working papers, drafts, and unofficial or unapproved policies." A company with genuinely good media hygiene can still score NOT MET because the policy that describes it was never formally approved.

So: buy less than you think. Document more than you think. That's the whole family in one line.

▸ Check whether Conditional status is still on the table for your scope

Mark each requirement in the nine-row table above as MET, NOT MET, or Not Applicable. If any of MP.L2-3.8.1, 3.8.2, 3.8.3, 3.8.7, or 3.8.8 is NOT MET, the Conditional Level 2 path is closed. If only 3.8.4, 3.8.5, 3.8.6, or 3.8.9 is open, add those deductions to every other Level 2 gap, confirm the overall score remains at least 88, and verify that every open requirement satisfies § 170.21.

Do not put CUI, drawings, contract numbers, credentials, asset names, or sensitive system details in any worksheet or planning tracker. Use generalized descriptions only.


What actually counts as system media?

Answer capsule. Under the CMMC Level 2 assessment materials, system media includes both paper and digital items that contain CUI — not only removable drives. Printouts, external drives, optical discs, backup tapes, endpoint storage, memory inside printers and copiers, and cloud backup replicas can all qualify. The test is whether the item holds CUI, not whether it looks like an IT asset.

This section exists because an incomplete inventory can defeat every control that follows it. You can't protect media you never wrote down.

Non-digital media in a typical defense shop:

  • Printed drawings and specification packages
  • Work instructions and routers on the production floor
  • First-article and inspection records
  • Shipping and packing documentation
  • Engineering notebooks and handwritten notes
  • Archive boxes in a storage room nobody has opened since the last move
  • Output sitting in a shared printer tray

Digital media people remember: USB flash drives, external hard drives and SSDs, memory cards, optical discs, backup tapes, laptop and workstation drives.

Digital media people forget:

  • Printers, copiers, scanners, and multifunction devices. Many have internal storage that retains images of what passed through them. That storage goes out the door at lease-return, service swap, or end of life.
  • CNC controllers, OT gear, lab instruments, and test equipment with removable storage.
  • Cloud backup replicas and snapshots held by a provider.
  • Failed drives sitting in a drawer awaiting an RMA that never happened.
  • Devices returned under warranty before anyone sanitized them.

A note on scope discipline, because over-scoping is as expensive as under-scoping: a device that never processes, stores, or transmits CUI does not become in-scope merely because it is removable. But you need a defensible basis for saying so, grounded in your actual data flow — not in a policy sentence asserting it. Specialized Assets get specific treatment under § 170.19 and the CMMC scoping guidance; our CMMC scoping guide walks the asset categories.

There is also a formal route for a requirement that genuinely doesn't apply. Under § 170.24(b)(3), a requirement or objective that does not apply at the time of assessment is scored Not Applicable, which is treated the same as MET. That finding still has to be supported by the actual scope and evidence. Separately, § 170.24(c)(2)(i)(B)(8) provides that if you previously received a favorable DoD CIO adjudication that a requirement is not applicable — or that an alternative measure is equally effective — that adjudication must be written into your system security plan to be considered during an assessment. A policy sentence declaring "N/A" is not self-proving. Document the basis and which route you're relying on.


The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The required CMMC status comes from the solicitation or contract, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


Does your cloud, GCC High tenant, or CUI enclave cover media protection?

Answer capsule. Not automatically. Under 32 CFR §§ 170.16 and 170.17, a cloud or external-service arrangement divides responsibility through the applicable service description and Customer Responsibility Matrix (CRM), which must be documented or referenced in the contractor's SSP. The five non-deferrable Media Protection requirements do carry 19 of the family's 23 points. But that is not the same as saying a provider can never implement part of them. The real question is who implements each applicable objective — and who can produce the evidence.

This is the section we'd hand to anyone who bought a government cloud tenant and assumed the file-handling problem was solved.

A CUI enclave — a deliberately narrowed environment where CUI is contained — is a legitimate and often excellent scope-reduction strategy. When properly designed, it can genuinely move implementation work off your plate in Access Control, System and Communications Protection, Identification and Authentication, and Audit and Accountability. It does considerably less for Media Protection, for a structural reason: paper, local devices, removable-media workflows, physical transport, and contractor-owned equipment still exist outside the provider boundary.

The table below is our editorial responsibility map, derived from the requirement text and the CRM rules in § 170.16(c)(2)–(3) and § 170.17(c)(5)–(6). It is not a regulatory determination. Your actual CRM, service description, assessment scope, and SSP govern the split.

Requirement — Likely responsibility split — verify it in the CRM — Points at stake — POA&M eligible?
RequirementLikely responsibility split — verify it in the CRMPoints at stakePOA&M eligible?
MP.L2-3.8.1Shared. The provider can protect media inside its service; you still own paper and local digital media outside it3No
MP.L2-3.8.2Shared. Service access controls cover media inside the tenant; your authorization process must cover media outside it3No
MP.L2-3.8.3Split by media owner. The provider sanitizes its infrastructure; you handle your paper, drives, copiers, devices, and provider-exit evidence5No
MP.L2-3.8.4Often customer-led. A service can automate some markings, but the authority, physical labels, and media outside the service remain yours1Potentially
MP.L2-3.8.5Mostly customer-led outside the service. Physical custody and accountability remain with the party moving the media1Potentially
MP.L2-3.8.6Split by transported media. The provider handles confidentiality for provider-controlled digital media moved outside its controlled areas; you handle customer-controlled devices and removable media in transport1Potentially
MP.L2-3.8.7Shared. A provider may govern managed endpoints; you still own unmanaged endpoints, OT, and the actual removable-media workflow5No
MP.L2-3.8.8Mostly customer-led for your devices. The provider controls ownership of its assets; you must identify the owner of portable storage you allow3No
MP.L2-3.8.9Shared. The provider may operate backups, but locations, administrative access, confidentiality controls, and evidence must be mapped1Potentially

Line up the last two columns and the actual pattern is hard to miss. The five non-deferrable requirements total 19 of 23 points, and each still leaves the contractor with either direct implementation work, evidence work, or both. A CRM entry proves the allocation; it does not prove implementation by itself. Pair it with provider artifacts and customer-side records that satisfy every applicable objective.

That is not an argument against enclaves. It's an argument for knowing what you still own after you buy one — and for making sure the person who wrote the check knows too.

Before you rely on any provider for any part of this family, get written answers on: the exact service boundary, the requirements and objectives assigned to each party, where backup replicas and snapshots reside, who holds administrative access, which party produces the evidence an assessor will examine, media sanitization responsibilities at end of contract, and the data-destruction process when you leave. Our managed enclave guide and GCC High guide cover the architecture side.

▸ Map your environment to the provider category that actually closes media gaps

Readiness work, managed security, evidence workflow, and enclave architecture are four different purchases, and the media gaps you just found point to different ones. Tell The Defense Compliance Report's Find My CMMC Path tool your required level, FCI/CUI handling, assessment type, cloud environment, and timeline. It maps you to a provider category — not a ranked provider — before you request a single quote.

Map my path →

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. Do not submit CUI, drawings, or sensitive contract details — this intake is for provider-category routing only.


Does CMMC prohibit USB drives?

Answer capsule. No. CMMC contains no blanket prohibition on USB drives. MP.L2-3.8.7 requires the organization to control the use of removable media on system components, and MP.L2-3.8.8 prohibits portable storage devices that have no identifiable owner. Prohibition, an approved-device allowlist, a controlled transfer station, and governed exceptions can all be defensible implementation models when they are enforced, evidenced, and sufficient for the applicable objectives.

This is the question that sends teams toward the fastest-looking answer — "just ban them" — and that answer can be the wrong one.

Together these two requirements are worth eight points, neither is deferrable, and they fail for different reasons. 3.8.7 is about the use of removable media on the system component: is that use governed and enforced? 3.8.8 is about the device: can you identify an accountable owner? A company can pass one and fail the other. Approved company drives with no identifiable owner fail 3.8.8. A perfect serialized inventory on machines that accept any drive can still fail 3.8.7.

Four defensible models

Model — Best fit — Main advantage — Main risk
ModelBest fitMain advantageMain risk
Complete prohibitionEnvironments with no legitimate removable-media dependencySimplest to state and enforceWorkarounds appear the moment it conflicts with production
Approved-device allowlistLimited, known legitimate useDevices are identifiable and controlledRequires real technical enforcement plus inventory discipline
Controlled transfer stationManufacturing, lab, and OT workflowsIsolates high-risk transfers from ordinary endpointsThe station itself becomes a critical controlled process
Time-limited exceptionRare vendor, maintenance, or legacy needHandles genuine business necessityExceptions quietly become permanent

Here's the operational judgment we'd offer, and it cuts against instinct: an unenforced blanket ban is often less defensible than a narrow, technically enforced exception. A policy that prohibits removable media while production systems still accept any device doesn't cure the gap — it documents it. You've handed an assessor a written statement of intent and a floor that contradicts it. Interviews can surface that contradiction, because the machinists will simply explain how they actually load programs.

What a controlled manufacturing exception should contain

If your CNC controllers, coordinate measuring machines, or test rigs need removable media, build the workflow rather than pretending it doesn't exist:

  1. An approved source system where the file originates
  2. A dedicated transfer station, separated from general office endpoints
  3. Serialized, physically identified, approved media only
  4. A named custodian or owning project for each device
  5. A malware scan or validation step before transfer
  6. A logged transfer record
  7. A defined destination machine
  8. Secure storage when the device isn't in use
  9. Read-only use wherever technically feasible
  10. Review, sanitization, or destruction before reuse
  11. A written expiration or review date on the exception
  12. A lost-device and incident procedure

That's more work than writing "USB drives are prohibited." It's also the version that survives a floor walk. If this is your situation, our machine shop and manufacturer guides go deeper on the OT side.

One documented data point, with its limits stated. DoD OIG Report DODIG-2022-061 examined ten academic and research contractors and found that five had not restricted the use of removable media through automated mechanisms. That is a sample of ten in one segment. It is not a prevalence estimate for the Defense Industrial Base, and we won't present it as one. What it is: documented evidence, from the government's own auditors, that this specific control fails in the field.


How do you sanitize or destroy media containing CUI?

Answer capsule. MP.L2-3.8.3 requires media containing CUI to be sanitized or destroyed before disposal and sanitized before release for reuse — two separate assessment objectives, both of which must be satisfied. Worth five points and not eligible for a POA&M, it is one of the two heaviest requirements in the Media Protection family and the only one that also appears at CMMC Level 1.

Two objectives, two different failure modes. "Before disposal" covers the drive going in the dumpster. "Before release for reuse" covers the laptop handed to a new hire, the leased copier going back, the drive repurposed for a non-CUI system. A disposal-only procedure handles the first and forgets the second.

On methods: the CMMC Level 2 Assessment Guide points to NIST SP 800-88 for media sanitization. NIST published SP 800-88 Revision 2 on September 26, 2025. One clarification worth stating plainly, because these documents get conflated: SP 800-88 informs how you sanitize. It does not change which baseline CMMC Level 2 is assessed against. That remains NIST SP 800-171 Revision 2 under § 170.14(c)(3).

Method has to match the medium. There is no single destructive answer that fits every technology, and prescribing one is how people end up with unverifiable results:

Media type — The specific problem — Watch for
Media typeThe specific problemWatch for
PaperSimple to destroy, easy to overlookRegular trash, unattended recycling bins, off-site shredding with no per-batch record
Magnetic hard diskWell-established methodsVerification step is skipped; failed drives never get processed
Solid-state driveWear leveling and over-provisioning mean data can survive a logical overwriteMethods designed for magnetic media applied to flash
USB flash mediaSame flash behavior, plus it's easy to lose track ofDevices absent from inventory entirely
Optical mediaStraightforward destructionDiscs archived in a drawer, never inventoried
Backup tapeLong retention, off-site storageTapes at a third-party vault outside the sanitization program
Printer / copier / MFD storageStorage isn't visible to usersLease return, service swap, and end-of-life all move it off-site
Mobile device storageMixed personal and business useDevice wiped, cloud backup untouched
Failed or inaccessible mediaCan't be sanitized by normal meansSits in a drawer indefinitely with no disposition

Normal file deletion and quick formatting generally do not demonstrate sanitization. They remove ordinary access paths without necessarily rendering the underlying data infeasible to recover.

The record is the deliverable

Because the absence of recoverable data is not a self-explaining artifact, the assessor needs records and test evidence. A defensible sanitization record ties one action to one asset and includes: asset or media identifier, custodian, media type, CUI status, method used, tool or equipment, operator, date, verification method, verification result, witness or reviewer where applicable, and final disposition.

If you outsource destruction, verify the scope of service, custody and transport, asset-level reconciliation, the actual method, the verification step, downstream handling, and the failed-media process. A certificate stating that "electronics were recycled" on a given date is not an asset-specific sanitization record. It is a receipt. Your evidence should let a sampled certificate reconcile back to the specific asset or media item it covers.


How should CUI media be marked?

Answer capsule. MP.L2-3.8.4 requires media containing CUI to carry applicable CUI markings and distribution limitations — two assessment objectives, worth one point, and potentially eligible for a POA&M. The marking rules themselves are not in NIST SP 800-171; they come from the government-wide CUI program and the CUI Registry maintained by the National Archives.

This requirement sends people looking in the wrong document. NIST SP 800-171 tells you to mark. It does not tell you how. That comes from your contract, the designating agency's direction, and the authorized markings published in the CUI Registry.

For paper: banner markings, footers, cover sheets, container and folder labels, and portion marking only where applicable guidance requires it.

For digital media: apply the physical-media label or other authorized marking appropriate to the device, mark files or folders where required, and maintain the corresponding entry in your media inventory. The National Archives publishes SF 902 for media such as hard drives and SF 903 for USB-sized media. Those are available resources, not a universal mandate that every contractor apply one specific form to every item.

The one thing not to do: invent your own dissemination controls because they sound safer. Limited dissemination controls are drawn from the authorized set in the CUI Registry and are directed by the designating agency. A homemade marking creates a handling instruction downstream recipients cannot reliably interpret, and it can conflict with the agency's own requirements. When in doubt, ask the contracting officer or designating agency in writing and keep the answer with your marking procedure.


How do you move CUI media outside your facility?

Answer capsule. Transporting CUI media outside controlled areas can trigger two requirements. MP.L2-3.8.5 addresses access control and accountability during transport. MP.L2-3.8.6 addresses confidentiality, and permits either cryptographic mechanisms or alternative physical safeguards. Each is worth one point and each is potentially eligible for a POA&M.

They are easy to collapse into one requirement. They are not, and the evidence differs.

3.8.5 is a custody question. Its two objectives ask whether access to media containing CUI is controlled, and whether accountability is maintained during transport outside controlled areas. A minimum defensible transport record: record ID, media identifier, general media type, sender, authorized recipient, origin and destination, release date and time, carrier or custodian, tracking number where applicable, the protective method used, custody transfers, receipt confirmation, any exception or incident, and final disposition.

A courier's parcel tracking number is not, by itself, that record. Tracking proves a box moved. It does not establish which controlled media was inside, or that the person who signed for it was authorized to receive it. A tracking-only process leaves that distinction unproved.

3.8.6 is a confidentiality question, and it contains an escape hatch people misread. The requirement calls for cryptographic mechanisms unless the media is otherwise protected by alternative physical safeguards. That's a real alternative, not an informal exemption. If you rely on it, document why cryptography wasn't used, which physical safeguards protect confidentiality, who approved the approach, which transport scenarios it covers, and how the safeguards are inspected.

If you do use cryptography, MP.L2-3.8.6 also points you into SC.L2-3.13.11. Verify the implementation rather than trusting the box. A product marketing claim of "AES-256" does not by itself establish an appropriate validated implementation — validation is specific to module, version, and operating configuration, and the validated mode has to actually be enabled. Identify the exact product and module, locate the relevant validation record, confirm it covers your version and use, and keep configuration evidence containing no CUI. Recheck after firmware or product changes. The deeper treatment of FIPS validation and its own separate scoring impact lives on our CMMC FIPS 140-2 requirements page.

And to head off a common conflation: media in transport is not the same as email in transit. Different requirement, different family, different evidence. See CUI email encryption.


How do backups fit into CMMC media protection?

Answer capsule. MP.L2-3.8.9 requires the confidentiality of backup CUI to be protected at storage locations. Worth one point and potentially POA&M-eligible, it applies wherever a backup copy of CUI is stored — including off-site media, cloud replicas, snapshots, disaster-recovery environments, and copies held by a service provider.

The structural trap is straightforward: a team can document live production media handling thoroughly and still never map the copies.

Inventory every location, not every product: local backup appliances, offline media, tape libraries, off-site vaults, cloud backup services, provider-side replicas, snapshots, disaster-recovery environments, administrator exports, and any copies your managed service provider holds on your behalf.

"The cloud encrypts it" is an incomplete answer. You still need to know which service and configuration are in use, where the backup is stored, who can administer or retrieve it, which party supplies the evidence an assessor will examine, whether encryption applies at rest and in relevant transport, how keys and privileged access are controlled, and how the arrangement is assigned in the CRM and described in your scope and SSP. Our CMMC-compliant backup guide covers architecture and product selection; this requirement is about proving confidentiality at the storage location.


What evidence will a self-assessor or C3PAO look for?

Answer capsule. CMMC Level 2 assessments use the NIST SP 800-171A assessment methods — examine, interview, and test — against each applicable objective. For the nine media protection requirements, that means 15 objectives, every applicable one of which must be satisfied by evidence in final form. A written policy supports an objective; it does not, by itself, demonstrate implementation.

Assessment procedure is prescribed by § 170.14(d), which incorporates NIST SP 800-171A. A self-assessment and a Level 2 certification assessment use the same requirement objectives, assessment methods, and scoring basis. The procedures and reporting path differ: the OSA submits a Level 2 self-assessment to SPRS, while an authorized or accredited C3PAO — a CMMC Third-Party Assessment Organization — submits a certification assessment through the CMMC instantiation of eMASS for transmission to SPRS.

  • Examine — policies, procedures, SSP sections, inventories, logs, configurations, records, contracts, and physical evidence.
  • Interview — the people who actually administer, use, transport, store, and dispose of media. Not only the person who wrote the policy.
  • Test — exercising the control under controlled conditions. For example, testing whether an unapproved clean device is blocked on a representative endpoint, or tracing a sampled media record end to end.

Media Protection lends itself to direct observation and testing because so much of it is physically visible. An assessor can walk the floor, look at the print tray, inspect the storage area, sample a record, and observe whether the control works.

A useful hierarchy for judging your own evidence:

  1. Implemented and tested — configurations, logs, sampled records, a controlled test showing the mechanism behaved as designed. Strongest.
  2. Operational records — transport logs, media inventory, destruction records with asset-level detail, approval records.
  3. Governance — policy, procedure, role assignment, SSP description. Necessary, not sufficient.
  4. Draft or planned — useful for remediation, not proof of implementation. And per § 170.24(b)(1), explicitly unacceptable as assessment evidence.

Our minimum artifact set for this family: an approved media handling policy, a media inventory covering paper and digital, an authorized-user determination, a sanitization and destruction record, a transport and accountability log, marking samples, and removable-media configuration evidence with a controlled test result.

One planning note changes how you build records. For a Level 2 self-assessment, § 170.16(c)(4) requires the artifacts used as evidence to be retained for six years from the CMMC Status Date. For a Level 2 certification assessment, § 170.17(c)(4) requires the hashed artifacts used as evidence to be retained for six years. Design your logs as something you can maintain and retrieve for six years, not as a binder you assemble the week before.

▸ Build the evidence pack before you need it

Our CMMC Readiness Checklist is a 32-point checklist mapped to the 14 NIST SP 800-171 Revision 2 control families, including the media artifacts an assessor examines. Use it to see where you stand before you engage anyone.

Download the CMMC Readiness Checklist →

Do not submit CUI, drawings, export-controlled content, or sensitive contract details.


How does media protection change at Level 1 and Level 3?

Answer capsule. CMMC Level 1 includes exactly one media requirement: sanitize or destroy media containing Federal Contract Information before disposal or release for reuse, drawn from 48 CFR 52.204-21(b)(1)(vii). CMMC Level 3 adds no media requirements at all — Media Protection is one of four NIST SP 800-171 Revision 2 families that the 24 selected NIST SP 800-172 February 2021 requirements do not touch.

Reading the rule tables directly produces two useful findings.

Level 1: the one control you already own is the expensive one. § 170.14(c)(2) sets the Level 1 requirements as those in 48 CFR 52.204-21(b)(1)(i) through (xv) — fifteen safeguards. Exactly one is a media requirement: MP.L1-b.1.vii, sanitize or destroy media containing FCI before disposal or reuse. That is the same control that carries five points at Level 2 as MP.L2-3.8.3. If you're an FCI-only contractor moving toward CUI work, you already hold one of the two heaviest media requirements in the standard. Build that program properly now and you've de-risked one of the two largest media exposures at Level 2.

Level 3: adding nothing is not relief. We read all 24 rows of Table 1 to § 170.14(c)(4). The enhanced requirements land in Access Control, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Personnel Security, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Media Protection is absent — one of four families, alongside Audit and Accountability, Maintenance, and Physical Protection, that Level 3 leaves untouched.

NIST published SP 800-172 Revision 3 on May 13, 2026 and now lists the February 2021 edition as withdrawn. CMMC Level 3 still incorporates the February 2021 edition and its selected 24 requirements. The publication currently favored in NIST's catalog and the publication incorporated into 32 CFR Part 170 are, again, different questions.

That sounds like good news until you read the Level 3 scoring rule. § 170.24(c)(3) requires a maximum Level 2 certification-assessment score before a Level 3 certification assessment can begin. Maximum means all 110 Level 2 requirements MET. A Level 3 contractor therefore enters Level 3 with no open Level 2 media gap — not even one of the four one-point requirements that could otherwise be placed on a Level 2 POA&M.

Comparison — Level 1 — Level 2 — Level 3
ComparisonLevel 1Level 2Level 3
Information protectedFCICUICUI associated with critical programs or high-value assets
Media requirements199 inherited from Level 2; none added
Media deduction exposurePass/fail, all requirements23 pointsAll Level 2 requirements must already be MET
Media POA&M availableNo POA&Ms at Level 14 of 9 potentiallyNo open Level 2 media gap when Level 3 begins
CMMC-controlling source48 CFR 52.204-21(b)(1)NIST SP 800-171 Rev. 2Selected NIST SP 800-172 February 2021 requirements

Is CMMC media protection the same as DFARS incident media preservation?

Answer capsule. No. The CMMC Media Protection family governs the ordinary lifecycle of media containing CUI. DFARS 252.204-7012 separately requires a contractor that discovers a reportable cyber incident to preserve and protect images of affected systems and relevant monitoring or packet capture data for at least 90 days from submission of the incident report. Both may apply to the same company, for different reasons.

We're including this because "media protection and preservation" is a phrase that appears in both contexts and sends people to the wrong requirement.

Comparison — CMMC Media Protection (MP.L2-3.8.x) — DFARS 252.204-7012 incident preservation
ComparisonCMMC Media Protection (MP.L2-3.8.x)DFARS 252.204-7012 incident preservation
TriggerOrdinary handling of media containing CUIDiscovery of a reportable cyber incident
PurposeProtect media across its lifecyclePreserve evidence for government review and damage assessment
CoversPaper, USB, backups, transport, disposalSystem images and relevant monitoring or packet-capture data
TimingContinuousAt least 90 days from submission of the incident report
EvidenceInventory, access, transport, sanitization, device controlPreserved forensic artifacts and incident records

A contractor may need both processes and should not assume one satisfies the other. The clause text is at Acquisition.gov.

Four DFARS and SPRS records people confuse

Authority — What it does — What appears in or moves through SPRS
AuthorityWhat it doesWhat appears in or moves through SPRS
DFARS 252.204-7012Imposes applicable safeguarding, cyber-incident reporting, and 90-day incident-evidence preservation dutiesNot the source of a CMMC status by itself
DFARS 252.204-7019Requires a current NIST SP 800-171 DoD Assessment for covered systems relevant to an offer when the provision appliesThe offeror verifies that current summary scores are posted in SPRS
DFARS 252.204-7020Governs Basic, Medium, and High NIST SP 800-171 DoD Assessments and government access for assessmentSummary-level NIST DoD Assessment scores are posted in SPRS
DFARS 252.204-7021Requires the CMMC status and affirmation specified by the solicitation or contractCMMC self-assessment results and affirmations are submitted in SPRS; certification results move through eMASS into SPRS

The NIST SP 800-171 DoD Assessment score used under 252.204-7019 and 252.204-7020 is not the same record as the CMMC Level 2 status and affirmation required under 32 CFR Part 170 and 252.204-7021. They may evaluate the same 110-requirement baseline, but the authority, submission fields, status labels, and contract consequence are different. Do not treat one SPRS screen as proof that the other requirement is satisfied.


The failure patterns, and how they get caught

Answer capsule. Media protection findings can arise where a written policy describes a clean process but the real environment includes untracked paper, anonymous USB drives, copier storage, missing transport records, generic destruction certificates, or unmapped backup copies. Because assessments test and interview as well as examine, contradictions between policy and practice tend to surface rather than pass.

Failure pattern — Why it costs you — What exposes it — Corrective direction
Failure patternWhy it costs youWhat exposes itCorrective direction
Unknown or unapproved USB devices still functionUndermines 3.8.7 and potentially 3.8.8 — 8 points, neither deferrableControlled device test and endpoint logsEnforce prohibition or allowlisting technically, not only on paper
Media inventory omits paperThe physical CUI path is ungoverned; 3.8.1 can failFacility walkthrough and interviewsAdd paper locations, custodians, and storage
Destruction record isn't asset-specificCannot establish what happened to a given deviceReconciling one certificate to one serial numberTie method, operator, verification, and disposition to the asset
Copier and printer storage overlookedCUI can leave on embedded storage at lease returnAsset review and the service contractAddress storage, maintenance access, and end-of-life
Courier tracking substitutes for accountabilityDoesn't establish authorized custody under 3.8.5Sampling one shipmentAdd media identity and authorized-recipient fields
Backup locations incompleteCopies sit outside the stated boundaryArchitecture and provider reviewMap replicas, snapshots, and off-site copies
Policy bans USB, production uses itGovernance contradicts operation; the policy documents the gapInterviews with the people who move filesBuild a controlled exception workflow instead
Markings improvisedMay conflict with the designating agency's requirementsLabel sample and source reviewMap every marking to its authority

A second Inspector General audit, DODIG-2021-098, examined five DoD additive-manufacturing sites and emphasized labeling, securing, and scanning removable media connected to those systems. Again: a specific audit of a specific segment, not a claim about every machine shop. But two separate OIG reviews landing on removable media is a pattern worth taking seriously when you're deciding what to fix first.


What did the July 2026 suspension actually change?

Answer capsule. Phase I began November 10, 2025. Under the original one-calendar-year schedule in 32 CFR § 170.3(e), it would have run through November 9, 2026, with Phase II beginning November 10, 2026. On July 13, 2026, the Department suspended the transition to Phase II along with pending and future implementation milestones. Phase I self-assessment requirements remain in effect where an applicable solicitation or contract requires them. The suspension changed the rollout schedule; it did not change the nine media protection requirements or how they are scored.

What is suspended: the transition to Phase II and the milestones that followed it. If your planning materials still show November 10, 2026 as a universal enforcement date, remove it.

What is not suspended: applicable Phase I self-assessment requirements. Contract-specific NIST SP 800-171 obligations. Applicable DFARS 252.204-7012 safeguarding and reporting duties. The requirement to submit accurate CMMC self-assessment results and affirmations in SPRS when the solicitation or contract requires that CMMC status.

There's a version of this news that reads as a reprieve, and we'd caution against it. The pause did not turn a Level 2 self-assessment into a low-stakes exercise. Under § 170.16, the OSA submits the score, scope information, POA&M status, and annual affirmation into SPRS. The Department can conduct a DCMA DIBCAC assessment, and those results take precedence over a pre-existing self-assessment status. A five-point media requirement scored MET without evidence can still become a contract problem.

Our Phase II suspension coverage tracks what changed and what's still moving. Treat any regulatory timing you read anywhere — including here — as accurate to its stated verification date and no further.


Your first 30 days on media protection

Answer capsule. A focused 30-day sequence cannot guarantee assessment readiness, but it can convert an undefined media problem into an owned, testable program. The sequence we recommend: discover the media, decide the allowed workflows, implement the controls, then collect and test evidence — prioritizing the five requirements that cannot be placed on a POA&M.

Days 1–7 — Find it. Trace CUI through your actual operation. Inventory paper and digital media. Walk the print room, the plan room, the shop floor, the storage room, the disposal queue. Open the service contract on the copier. Identify every removable-media use, including the ones nobody documented. Assign an owner to each location. Map each path to a requirement number. Record unknowns — without putting CUI in the tracker.

Days 8–14 — Decide. Choose your removable-media model. Define who is authorized and on what basis. Assign custodians. Select marking practices and their authority. Define transport methods. Choose sanitization methods per media type. Map what your providers own versus what you own. Update the SSP and the procedures to match the decisions you just made, not the ones you wish you'd made.

Days 15–21 — Implement. Configure endpoint restrictions. Lock or redesign storage. Label and serialize approved devices. Start the transport log. Start the sanitization record. Map every backup location. Train the people who actually handle media, using their real workflow.

Days 22–30 — Test it like an assessor would. Under change control, use approved clean test media to verify that an unapproved-device condition is blocked on a representative endpoint; do not introduce unknown media to production. Pull one authorized-user determination and check whether the basis is documented. Trace one transported item end to end. Reconcile one disposal record to one asset. Follow one copier through its lifecycle. Trace one backup copy to its storage location. Interview an operator and see whether their answer matches the policy.

Then rank what you found by point value and deferrability. The five non-deferrable requirements go first. Always.

▸ Get scoped quotes from the provider categories that fit the gaps you found

If your 30 days surfaced work you can't absorb internally — evidence programs, SSP repair, endpoint enforcement, or enclave architecture — the next step is comparing the right category, not calling whoever answers first. Tell us your level, scope, environment, and timeline and we'll help you compare source-checked provider options in the categories that fit.

Request scoped quotes from matched provider categories →

Do not submit CUI, drawings, contract numbers, credentials, or sensitive system details. This intake is for provider-category routing only.


What we actually verified

We don't ask you to take our word for any of this. Here's what we read, and what each source supports.

Source — What it supports — Read on
SourceWhat it supportsRead on
32 CFR § 170.24 at eCFREvery point value; MET/NOT MET/N/A; final-form evidence; partial-credit limits; Level 3 maximum-score prerequisite; DoD CIO adjudicationAug. 19, 2026
32 CFR § 170.21 at eCFRThe 88-point threshold, one-point ceiling, six separately barred one-point requirements, and 180-day closeoutAug. 19, 2026
32 CFR § 170.14 at eCFRLevel 2 mapping to NIST SP 800-171 Rev. 2; Level 1 mapping; all 24 Level 3 requirementsAug. 19, 2026
32 CFR § 170.16 and § 170.17SPRS/eMASS reporting paths, CRM and SSP treatment, ESP scope, affirmations, and six-year artifact retentionAug. 19, 2026
CMMC Level 2 Assessment Guide, Version 2.13The 15 assessment objectives, counted by us; assessment methods; MP implementation examples and discussionAug. 19, 2026
NIST SP 800-171 Rev. 2 and Rev. 3NIST publication status and dates; why current NIST catalog status is not the same as the CMMC-incorporated versionAug. 19, 2026
NIST SP 800-172 February 2021 and Rev. 3Current-vs-CMMC-controlling Level 3 version distinctionAug. 19, 2026
NIST SP 800-88 Rev. 2Current media-sanitization guidance and September 26, 2025 final-publication dateAug. 19, 2026
DFARS 252.204-7012, 7019, 7020, and 7021Safeguarding and incident preservation; NIST DoD Assessment records; CMMC status and affirmation distinctionsAug. 19, 2026
2025 CMMC acquisition final rule, 32 CFR § 170.3, current CMMC program notice, and July 13, 2026 suspension releasePhase I effective date, original one-year phase schedule, Phase II suspension, and continued Phase I self-assessment requirementsAug. 19, 2026
Cyber AB CMMC Assessment Process v2.0 and Cyber AB MarketplaceAuthorized/accredited C3PAO status, assessment independence, conflict rules, and no-guarantee requirementsAug. 19, 2026
National Archives CUI resourcesCUI media labels SF 902 and SF 903 and marking resourcesAug. 19, 2026
DODIG-2022-061 and DODIG-2021-098The two removable-media findings cited above, with their sample limitations statedAug. 19, 2026

What we calculated rather than quoted: the 23-point family total and the 15-objective count are our arithmetic from the sources above, shown so you can check them. What is editorial judgment: the provider-responsibility map, the remediation sequencing, the minimum evidence sets, the failure-pattern table, and the provider-category guidance. All of it is derived from verified facts on this page, and all of it is labeled.

What we did not do: inspect your environment. This page is not a guarantee of assessment success, and evidence expectations vary with scope, architecture, contract terms, and sampling. eCFR showed Title 32 current as of August 17, 2026 when we read it. Regulatory status can change during the current program review — check the date on this page against the date you're reading it.


Frequently asked questions

How many CMMC media protection requirements are there?

Nine, at CMMC Level 2, numbered MP.L2-3.8.1 through MP.L2-3.8.9. Those nine break into 15 assessment objectives in the official CMMC Level 2 Assessment Guide. CMMC Level 1 has one media requirement; CMMC Level 3 adds none.

How many points are the media protection requirements worth?

Twenty-three, in total deduction exposure: two five-point requirements, three three-point requirements, and four one-point requirements, per 32 CFR § 170.24. That is not a standalone Media Protection score — your assessment score covers all 110 Level 2 requirements.

Does CMMC ban USB drives?

No. MP.L2-3.8.7 requires you to control the use of removable media on system components, and MP.L2-3.8.8 prohibits portable storage devices with no identifiable owner. Prohibition, an approved-device allowlist, a controlled transfer station, or governed exceptions can all be defensible models, depending on your environment, when they are enforced and evidenced against the applicable objectives.

Does a USB drive holding CUI have to be encrypted?

For media in transport outside controlled areas, MP.L2-3.8.6 permits cryptographic mechanisms or alternative physical safeguards. Encryption is often the practical choice, and other requirements in your environment may independently call for it — but the requirement itself allows either, provided you document what you chose and why.

Is paper covered by CMMC media protection?

Yes. MP.L2-3.8.1 requires you to physically control and securely store system media containing CUI, "both paper and digital," and MP.L2-3.8.3 requires you to sanitize or destroy it before disposal. Printouts, drawings, travelers, and inspection records holding CUI are in scope.

Are printers and copiers in scope?

They can be, when they process or store CUI. Many multifunction devices retain internal images of what passed through them. Assess printed output, temporary queues, internal storage, maintenance access, drive replacement, and end-of-life sanitization rather than treating the device as an ordinary office appliance.

Can media protection requirements go on a POA&M?

Only the four worth one point — MP.L2-3.8.4, 3.8.5, 3.8.6, and 3.8.9 — and only if every other conditional-status condition is met. MP.L2-3.8.1, 3.8.2, 3.8.3, 3.8.7, and 3.8.8 all exceed one point, so § 170.21(a)(2)(ii) makes them ineligible.

What happens if I miss just one five-point media requirement?

You lose the Conditional Level 2 path entirely, regardless of your total score, because a requirement worth more than one point cannot be placed on a POA&M. A company at 105 of 110 with a five-point media gap has no conditional route; a company at exactly 88 can still have a Conditional path only when every gap is POA&M-eligible and every other condition is met.

Which sanitization standard should I use?

The CMMC Level 2 Assessment Guide points to NIST SP 800-88 for media sanitization, and NIST published SP 800-88 Revision 2 on September 26, 2025. SP 800-88 informs method selection. It does not replace NIST SP 800-171 Revision 2 as the baseline CMMC Level 2 is assessed against.

Does cloud backup automatically satisfy MP.L2-3.8.9?

No. You still need to establish where backup CUI resides, how its confidentiality is protected, who holds administrative access, which party produces the evidence, and how the arrangement appears in your scope and system security plan.

Is a written media protection policy enough?

Not by itself. A policy supports an assessment objective, but it does not demonstrate implementation alone. Assessments also weigh implementation evidence, personnel understanding, records, configurations, and tests — and under § 170.24(b)(1), evidence must be in final form, which excludes drafts and unapproved policies.

Is CMMC media protection the same as DFARS incident media preservation?

No. Media Protection governs the ordinary lifecycle of CUI media. DFARS 252.204-7012 separately requires preserving images of affected systems and relevant monitoring or packet-capture data for at least 90 days from submission of a reportable cyber-incident report. Different trigger, different purpose, different evidence.

Did the July 2026 suspension change the media protection requirements?

No. Phase I began November 10, 2025. The Department suspended the transition to Phase II and later milestones on July 13, 2026; Phase II had been scheduled for November 10, 2026. Applicable Phase I self-assessment and DFARS safeguarding duties remain in force. The nine requirements and their point values are unchanged.

These answers are educational. For contract interpretation, use your contracting officer or qualified federal-contracts counsel. For implementation and scoping support, use a qualified CMMC practitioner.


Where to go from here

If this is you — Do this next
If this is youDo this next
Not sure which of your media holds CUIRun the inventory in Days 1–7 above before you buy anything
Know the media, no proceduresWrite the policy, assign custodians, and get it formally approved — drafts don't count
Procedures but thin evidenceBuild the sanitization and transport records first; they're the ones an assessment can sample
Uncontrolled USB dependencies in productionDesign the controlled exception workflow rather than publishing a ban you can't enforce
Real technical gaps you can't close internallyCompare CMMC provider categories and use Who to Hire First before you compare individual vendors
Unsure of your required level or assessment typeRead your contract clause, review the CMMC levels, then use Find My CMMC Path; use the contracting officer or counsel for contract interpretation
Need a budget range before you engage providersUse the CMMC Level 2 cost guide to separate assessment, remediation, managed service, and enclave costs

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path →

Do not submit CUI, drawings, contract numbers, export-controlled content, or sensitive contract details. This intake is for provider-category routing only.


Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

Independence: The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.

Not advice: This page is educational research, not legal, contractual, or compliance advice. Your contract clauses and your actual FCI/CUI handling determine which requirements apply to you. Use your contracting officer or qualified federal-contracts counsel for contract interpretation, and a qualified CMMC practitioner for implementation and scoping support.

Research approach documented at Methodology and Editorial Standards. Editorial research not formally reviewed by a Subject Matter Advisor — see our Editorial Review Process. Found an error? Our Corrections policy explains how we handle it.