If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Media Protection (MP)
CMMC Media Protection (MP) Requirements
Media Protection contains 9 CMMC Level 2 requirements focused on protecting Controlled Unclassified Information stored on various types of media. These controls cover everything from USB drives to hard drives to paper documents.
Media means anything that stores information—hard drives, USB drives, CDs, DVDs, backup tapes, memory cards, and even paper documents.
Media protection is often overlooked, but lost or stolen media containing CUI creates serious security incidents. A single misplaced USB drive can expose sensitive defense information.
Why Media Protection Matters for CMMC
The Department of Defense requires Media Protection because CUI exists not just on servers and workstations but on portable media that can be lost, stolen, or improperly disposed of.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
Media protection risks include:
- USB drives lost in parking lots or airports
- Old hard drives are discarded without sanitization
- Backup tapes are stored insecurely
- Paper documents left in printers or trash
- Media stolen from vehicles or offices
A single piece of unprotected media can compromise sensitive defense information and create a reportable incident.
The 9 Media Protection Requirements
MP.L2-3.8.1: Media Protection
“Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.”
All media containing CUI must be protected:
Physical Control
- Know where media is located at all times
- Restrict access to authorized personnel
- Track the movement of media
- Secure media when not in use
Secure Storage
- Lock storage areas containing CUI media
- Use safes or locked cabinets for sensitive media
- Protect against theft and unauthorized access
- Control environmental conditions (temperature, humidity) for sensitive media
This applies to both digital media (drives, tapes, discs) and paper documents containing CUI.
MP.L2-3.8.2: Media Access
“Limit access to CUI on system media to authorized users.”
Not everyone needs access to all CUI media:
- Restrict physical access to media storage areas
- Control who can check out portable media
- Implement access logs for media handling
- Apply need-to-know principles to media access
Need-to-know means only people who require information for their specific job responsibilities should have access.
MP.L2-3.8.3: Media Sanitization
“Sanitize or destroy system media containing CUI before disposal or release for reuse.”
Before disposing of media or reusing it for non-CUI purposes:
Sanitization Methods by Media Type
Hard Drives (HDDs):
- Secure erase using approved software
- Degaussing (magnetic erasure)
- Physical destruction (shredding, crushing)
Solid State Drives (SSDs):
- Manufacturer-specific secure erase
- Physical destruction (most reliable)
USB Drives/Memory Cards:
- Secure erase or physical destruction
- Simple deletion is not sufficient
Optical Media (CDs/DVDs):
- Physical destruction (shredding)
- Cannot be reliably sanitized
Paper:
- Cross-cut shredding
- Pulping or incineration
Sanitization means removing data so thoroughly that it cannot be recovered using any known technique.
MP.L2-3.8.4: Media Marking
“Mark media with necessary CUI markings and distribution limitations.”
CUI media must be clearly marked:
- Apply CUI marking to media labels
- Include distribution limitation statements
- Mark both the media and its container
- Use consistent marking conventions
Marking ensures handlers know the media contains sensitive information and understand handling requirements.
MP.L2-3.8.5: Media Accountability
“Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.”
Track CUI media, especially during transport:
Inventory Management
- Maintain inventory of all CUI media
- Record who has custody of each item
- Track media location and status
- Reconcile inventory regularly
Transport Accountability
- Document media leaving controlled areas
- Record destination and purpose
- Track the chain of custody
- Verify return or proper disposal
MP.L2-3.8.6: Portable Storage Encryption
“Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport outside of controlled areas unless otherwise protected by alternative physical safeguards.”
When transporting digital media containing CUI:
- Encrypt all CUI on portable media
- Use FIPS 140-2 validated encryption
- Protect encryption keys separately from media
- Alternative: Use physical safeguards like locked containers with trusted couriers
FIPS 140-2 stands for Federal Information Processing Standard 140-2—the government standard for cryptographic module security.
Encryption ensures that lost or stolen media does not expose CUI.
MP.L2-3.8.7: Removable Media Control
“Control the use of removable media on system components.”
Restrict and manage removable media:
- Disable USB ports where not needed
- Require authorization for removable media use
- Scan removable media for malware before use
- Log removable media connections
- Use only organization-controlled devices
Uncontrolled removable media introduces malware risk and data exfiltration paths.
MP.L2-3.8.8: Shared Media Protection
“Prohibit the use of portable storage devices when such devices have no identifiable owner.”
Do not use unknown or unattributed media:
- Never use found USB drives
- Require ownership identification on all media
- Do not accept media from untrusted sources
- Destroy or quarantine unknown media
Unknown media may contain malware designed to compromise systems when connected.
MP.L2-3.8.9: Protect Backups
“Protect the confidentiality of backup CUI at storage locations.”
Backup media requires the same protection as primary data:
- Encrypt backup media containing CUI
- Store backups securely (locked storage, secure facility)
- Protect off-site backup storage
- Control access to backup media
- Apply the same handling requirements as the source data
Backups are often overlooked but contain complete copies of CUI.
Implementing Media Protection
Inventory Your Media
Know what media exists in your environment:
- Catalog all media containing CUI
- Track location and custody
- Include backups, archives, and working copies
- Update inventory when media is created or destroyed
Establish Handling Procedures
Document how CUI media should be handled:
- Marking requirements and conventions
- Storage requirements by media type
- Transport procedures
- Access authorization process
- Sanitization and disposal procedures
Control Removable Media
Implement technical and procedural controls:
- Disable USB ports on systems where not needed
- Use device control software to manage removable media
- Require authorization for USB device use
- Scan all removable media before use
Encrypt Portable Media
Use encryption for all portable CUI:
- Hardware-encrypted USB drives
- Full disk encryption on laptops
- Encrypted backup media
- Encryption for media in transit
Sanitize Before Disposal
Never discard media without proper sanitization:
- Use NIST SP 800-88 guidelines for sanitization methods
- Verify sanitization completed successfully
- Document sanitization with certificates of destruction
- Use certified destruction services for high-volume disposal
NIST SP 800-88 is the federal guideline for media sanitization, specifying methods for different media types.
Common Media Protection Mistakes
Mistake 1: Forgetting Paper
Media protection applies to paper documents, too. Shred CUI documents—do not just throw them away.
Mistake 2: Simple Deletion
Deleting files or formatting drives does not sanitize media. Data remains recoverable. Use proper sanitization methods.
Mistake 3: Unencrypted Portables
USB drives and laptops leaving your facility without encryption create unacceptable risk. Encrypt all portable CUI.
Mistake 4: Unknown USB Drives
Using found or gifted USB drives is a common malware vector. Never connect unknown media to CUI systems.
Mistake 5: Ignoring Backups
Backups contain CUI but are often stored less securely than primary data. Apply equivalent protection to backup media.
Key Takeaways
Media Protection’s 9 requirements ensure CUI is protected wherever it is stored—on hard drives, USB drives, backup tapes, or paper. Protect media physically, control access, mark it clearly, encrypt portable media, and sanitize before disposal.
Track all CUI media, control removable media use, and never use unknown storage devices. Remember that media protection includes paper documents, not just digital storage.
Keep reading
More in The 14 Control Families
- Access Control (AC) →
- Audit and Accountability (AU) →
- Awareness and Training (AT) →
- CMMC Incident Response (IR) →
- Configuration Management (CM) →
- Identification and Authentication (IA) →
- Maintenance (MA) →
- Personnel Security (PS) →
- Physical Protection (PE) →
- Risk Assessment (RA) →
- Security Assessment (CA) →
- System and Communications Protection (SC) →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5