Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Media Protection (MP)
CMMC Media Protection (MP) Requirements
Media Protection contains 9 CMMC Level 2 requirements focused on protecting Controlled Unclassified Information stored on various types of media. These controls cover everything from USB drives to hard drives to paper documents.
Media means anything that stores information—hard drives, USB drives, CDs, DVDs, backup tapes, memory cards, and even paper documents.
Media protection is often overlooked, but lost or stolen media containing CUI creates serious security incidents. A single misplaced USB drive can expose sensitive defense information.
Why Media Protection Matters for CMMC
The Department of Defense requires Media Protection because CUI exists not just on servers and workstations but on portable media that can be lost, stolen, or improperly disposed of.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
Media protection risks include:
- USB drives lost in parking lots or airports
- Old hard drives are discarded without sanitization
- Backup tapes are stored insecurely
- Paper documents left in printers or trash
- Media stolen from vehicles or offices
A single piece of unprotected media can compromise sensitive defense information and create a reportable incident.
The 9 Media Protection Requirements
MP.L2-3.8.1: Media Protection
“Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.”
All media containing CUI must be protected:
Physical Control
- Know where media is located at all times
- Restrict access to authorized personnel
- Track the movement of media
- Secure media when not in use
Secure Storage
- Lock storage areas containing CUI media
- Use safes or locked cabinets for sensitive media
- Protect against theft and unauthorized access
- Control environmental conditions (temperature, humidity) for sensitive media
This applies to both digital media (drives, tapes, discs) and paper documents containing CUI.
MP.L2-3.8.2: Media Access
“Limit access to CUI on system media to authorized users.”
Not everyone needs access to all CUI media:
- Restrict physical access to media storage areas
- Control who can check out portable media
- Implement access logs for media handling
- Apply need-to-know principles to media access
Need-to-know means only people who require information for their specific job responsibilities should have access.
MP.L2-3.8.3: Media Sanitization
“Sanitize or destroy system media containing CUI before disposal or release for reuse.”
Before disposing of media or reusing it for non-CUI purposes:
Sanitization Methods by Media Type
Hard Drives (HDDs):
- Secure erase using approved software
- Degaussing (magnetic erasure)
- Physical destruction (shredding, crushing)
Solid State Drives (SSDs):
- Manufacturer-specific secure erase
- Physical destruction (most reliable)
USB Drives/Memory Cards:
- Secure erase or physical destruction
- Simple deletion is not sufficient
Optical Media (CDs/DVDs):
- Physical destruction (shredding)
- Cannot be reliably sanitized
Paper:
- Cross-cut shredding
- Pulping or incineration
Sanitization means removing data so thoroughly that it cannot be recovered using any known technique.
MP.L2-3.8.4: Media Marking
“Mark media with necessary CUI markings and distribution limitations.”
CUI media must be clearly marked:
- Apply CUI marking to media labels
- Include distribution limitation statements
- Mark both the media and its container
- Use consistent marking conventions
Marking ensures handlers know the media contains sensitive information and understand handling requirements.
MP.L2-3.8.5: Media Accountability
“Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.”
Track CUI media, especially during transport:
Inventory Management
- Maintain inventory of all CUI media
- Record who has custody of each item
- Track media location and status
- Reconcile inventory regularly
Transport Accountability
- Document media leaving controlled areas
- Record destination and purpose
- Track the chain of custody
- Verify return or proper disposal
MP.L2-3.8.6: Portable Storage Encryption
“Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport outside of controlled areas unless otherwise protected by alternative physical safeguards.”
When transporting digital media containing CUI:
- Encrypt all CUI on portable media
- Use FIPS 140-2 validated encryption
- Protect encryption keys separately from media
- Alternative: Use physical safeguards like locked containers with trusted couriers
FIPS 140-2 stands for Federal Information Processing Standard 140-2—the government standard for cryptographic module security.
Encryption ensures that lost or stolen media does not expose CUI.
MP.L2-3.8.7: Removable Media Control
“Control the use of removable media on system components.”
Restrict and manage removable media:
- Disable USB ports where not needed
- Require authorization for removable media use
- Scan removable media for malware before use
- Log removable media connections
- Use only organization-controlled devices
Uncontrolled removable media introduces malware risk and data exfiltration paths.
MP.L2-3.8.8: Shared Media Protection
“Prohibit the use of portable storage devices when such devices have no identifiable owner.”
Do not use unknown or unattributed media:
- Never use found USB drives
- Require ownership identification on all media
- Do not accept media from untrusted sources
- Destroy or quarantine unknown media
Unknown media may contain malware designed to compromise systems when connected.
MP.L2-3.8.9: Protect Backups
“Protect the confidentiality of backup CUI at storage locations.”
Backup media requires the same protection as primary data:
- Encrypt backup media containing CUI
- Store backups securely (locked storage, secure facility)
- Protect off-site backup storage
- Control access to backup media
- Apply the same handling requirements as the source data
Backups are often overlooked but contain complete copies of CUI.
Implementing Media Protection
Inventory Your Media
Know what media exists in your environment:
- Catalog all media containing CUI
- Track location and custody
- Include backups, archives, and working copies
- Update inventory when media is created or destroyed
Establish Handling Procedures
Document how CUI media should be handled:
- Marking requirements and conventions
- Storage requirements by media type
- Transport procedures
- Access authorization process
- Sanitization and disposal procedures
Control Removable Media
Implement technical and procedural controls:
- Disable USB ports on systems where not needed
- Use device control software to manage removable media
- Require authorization for USB device use
- Scan all removable media before use
Encrypt Portable Media
Use encryption for all portable CUI:
- Hardware-encrypted USB drives
- Full disk encryption on laptops
- Encrypted backup media
- Encryption for media in transit
Sanitize Before Disposal
Never discard media without proper sanitization:
- Use NIST SP 800-88 guidelines for sanitization methods
- Verify sanitization completed successfully
- Document sanitization with certificates of destruction
- Use certified destruction services for high-volume disposal
NIST SP 800-88 is the federal guideline for media sanitization, specifying methods for different media types.
Common Media Protection Mistakes
Mistake 1: Forgetting Paper
Media protection applies to paper documents, too. Shred CUI documents—do not just throw them away.
Mistake 2: Simple Deletion
Deleting files or formatting drives does not sanitize media. Data remains recoverable. Use proper sanitization methods.
Mistake 3: Unencrypted Portables
USB drives and laptops leaving your facility without encryption create unacceptable risk. Encrypt all portable CUI.
Mistake 4: Unknown USB Drives
Using found or gifted USB drives is a common malware vector. Never connect unknown media to CUI systems.
Mistake 5: Ignoring Backups
Backups contain CUI but are often stored less securely than primary data. Apply equivalent protection to backup media.
Key Takeaways
Media Protection’s 9 requirements ensure CUI is protected wherever it is stored—on hard drives, USB drives, backup tapes, or paper. Protect media physically, control access, mark it clearly, encrypt portable media, and sanitize before disposal.
Track all CUI media, control removable media use, and never use unknown storage devices. Remember that media protection includes paper documents, not just digital storage.
Related Articles:
- What is CMMC Level 2?
- CMMC Access Control Requirements for Level 2
- NIST SP 800-171 Rev 2 – Media Protection Family
- NIST SP 800-88 – Media Sanitization Guidelines
- 32 CFR Part 170 – CMMC Program Rule
Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” specifically the Media Protection family (Section 3.8), NIST SP 800-88 “Guidelines for Media Sanitization,” and the DoD CMMC Level 2 Assessment Guide.
Need help implementing media protection for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.