Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Physical Protection (PE)
Physical Protection (PE) is one of 14 security control families in NIST SP 800-171 Revision 2 that forms the foundation for CMMC Level 2 certification. The PE family contains 6 security requirements (3.10.1 through 3.10.6) that establish physical access controls for facilities, systems, and equipment processing Controlled Unclassified Information (CUI).
Physical security is often called the “first line of defense” because all technical security controls—firewalls, encryption, multi-factor authentication—can be completely negated if an unauthorized person gains direct physical access to systems. An intruder with physical access can install malware, steal hard drives, copy data, or disable security controls entirely.
The PE family contains 2 Basic Security Requirements (3.10.1 and 3.10.2) and 4 Derived Security Requirements (3.10.3 through 3.10.6). All 6 requirements must be implemented to achieve CMMC Level 2 compliance.
Why Physical Protection Matters for CMMC
Physical Protection requirements are worth 6 total points in the DoD CMMC Scoring Methodology, with each requirement worth 1 point. However, four of the six PE requirements cannot be placed on POA&Ms for Conditional Status:
Cannot be on POA&M:
- PE.L2-3.10.1 (Limit physical access)
- PE.L2-3.10.3 (Escort visitors)
- PE.L2-3.10.4 (Maintain physical access logs)
- PE.L2-3.10.5 (Control physical access devices)
This means organizations must have these controls fully implemented before assessment—there’s no grace period for physical security gaps. Only 3.10.2 (Protect and monitor facility) and 3.10.6 (Alternate work sites) are POA&M-eligible.
Physical security controls are predominantly administrative and procedural rather than technical. They’re implemented through policies, procedures, access controls, and personnel training—not software or hardware configurations. This makes them relatively straightforward to implement but requires organizational discipline to maintain consistently.
The 6 Physical Protection Requirements
3.10.1: Limit Physical Access to Authorized Individuals
Requirement: Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
What This Means
Only authorized personnel should be able to physically access systems processing CUI. This requirement applies to employees, contractors, visitors, and any physical spaces containing CUI or systems that process it.
Implementation Approach
Identify Sensitive Areas: Designate areas where CUI is processed, stored, or transmitted as “sensitive” or “restricted.” These typically include server rooms and data centers, wiring closets with network equipment, offices where CUI work occurs, areas with printers/copiers handling CUI, and storage areas containing CUI media.
Establish Authorization: Maintain a documented list of personnel authorized to access each sensitive area. Authorization should be based on job function and need-to-know. Update authorization lists when personnel change roles or leave the organization.
Deploy Access Controls: Implement physical barriers and access mechanisms including locked doors on sensitive areas with key cards, PIN codes, or biometric readers; perimeter security for facilities (locked exterior doors, reception areas); and secure storage containers for CUI media.
Issue Credentials: Provide authorized personnel with identification credentials such as photo ID badges displaying name and authorization level, key cards or access tokens for electronic access systems, and keys for physical locks (with documented key control).
Prevent Unauthorized Access: Train employees to never hold doors open for unknown individuals (preventing “tailgating”), challenge or report unidentified persons in secure areas, lock workstations when leaving their desks, and secure sensitive documents when not in use (clean desk policy).
Cannot Be on POA&M
This requirement is on the list of controls that cannot be included in a POA&M for Conditional Status. Organizations must have physical access controls fully implemented before CMMC assessment.
3.10.2: Protect and Monitor the Physical Facility
Requirement: Protect and monitor the physical facility and support infrastructure for organizational systems.
What This Means
Beyond limiting access, organizations must actively protect facilities and monitor for unauthorized access attempts. This includes protecting the building itself and supporting infrastructure like power, HVAC, and communications systems.
Implementation Approach
Physical Protection Mechanisms: Deploy security measures including exterior lighting around building perimeters, fencing or barriers for sensitive facilities, reinforced doors and windows on server rooms, secure mounting for equipment to prevent theft, and protection of cabling infrastructure from tampering.
Monitoring Capabilities: Implement surveillance and monitoring such as security cameras at entry points and sensitive areas, alarm systems detecting unauthorized entry, motion sensors in restricted areas after hours, and security personnel or reception staff during business hours.
Infrastructure Protection: Protect supporting systems including uninterruptible power supplies (UPS) for critical systems, climate control for server rooms, fire suppression systems, and cable management preventing accidental disconnection.
Regular Monitoring Review: Establish processes to review camera footage and alarm logs periodically, respond to security alerts and alarms promptly, test monitoring systems to ensure functionality, and document monitoring activities and findings.
3.10.3: Escort Visitors and Monitor Visitor Activity
Requirement: Escort visitors and monitor visitor activity.
What This Means
Anyone without permanent physical access authorization is considered a visitor and must be escorted and monitored in areas where CUI is present. This applies to vendors, maintenance personnel, delivery drivers, customers, guests, and any non-authorized individual.
Implementation Approach
Visitor Management Process: Establish formal procedures for visitor handling. Visitors should sign in at reception with name, organization, purpose, and arrival time. Verify visitor identity through government ID or other credentials. Issue temporary visitor badges distinguishing visitors from employees. Assign an authorized escort who remains with the visitor at all times. Sign visitors out upon departure and collect visitor badges.
Escort Requirements: Escorts must be authorized employees who accompany visitors at all times in sensitive areas, observe visitor activities to prevent unauthorized actions, ensure visitors don’t access systems or information beyond their legitimate purpose, and report any suspicious behavior.
Monitoring Methods: Organizations can monitor visitor activity through direct observation by escort personnel, security cameras in areas visitors access, visitor logs documenting times and locations visited, and sign-in/sign-out records.
Cannot Be on POA&M
This requirement cannot be included in a POA&M for Conditional Status. Visitor escort procedures must be implemented before assessment.
3.10.4: Maintain Audit Logs of Physical Access
Requirement: Maintain audit logs of physical access.
What This Means
Organizations must keep records of who accessed physical facilities and when. Audit logs enable investigation of security incidents and provide accountability for physical access.
Implementation Approach
Types of Audit Logs: Organizations have flexibility in log formats. Logs can be procedural (paper sign-in sheets at reception), automated (electronic access control system logs capturing badge swipes), or hybrid (combination of electronic and manual logging).
Log Content: Physical access logs should capture individual’s name and identification, date and time of access, area or location accessed, and purpose of access (especially for visitors).
Log Retention: Retain physical access logs for a defined period based on organizational policy. Industry standard is typically 90 days to 1 year. Ensure logs are protected from unauthorized modification or deletion.
Log Review: Regularly review physical access logs (quarterly recommended) to identify unusual access patterns such as after-hours access or repeated access to areas outside job function, detect unauthorized access attempts, and investigate discrepancies or anomalies.
Cannot Be on POA&M
This requirement cannot be included in a POA&M for Conditional Status. Physical access logging must be operational before assessment.
3.10.5: Control and Manage Physical Access Devices
Requirement: Control and manage physical access devices.
What This Means
Physical access devices—keys, access cards, PIN codes, combinations, and biometric credentials—must be carefully controlled throughout their lifecycle to prevent unauthorized access.
Implementation Approach
Access Device Inventory: Maintain records of all physical access devices including keys issued (with serial numbers if applicable), access cards/badges assigned, individuals authorized to receive devices, and areas each device can access.
Issuance Controls: Issue devices only to authorized personnel based on documented approval. Record device assignments with dates and authorizing official. Require acknowledgment of responsibilities when devices are issued.
Recovery Procedures: Recover access devices when personnel change roles or no longer need access, employees terminate or transfer, and contractors complete their work. Immediately deactivate electronic credentials when recovered. Re-key or change combinations when keys are lost or compromised.
Periodic Audits: Regularly audit physical access device assignments against current authorization lists. Identify and investigate discrepancies. Verify all issued devices are accounted for.
Cannot Be on POA&M
This requirement cannot be included in a POA&M for Conditional Status. Access device management must be implemented before assessment.
3.10.6: Enforce Safeguarding Measures for CUI at Alternate Work Sites
Requirement: Enforce safeguarding measures for CUI at alternate work sites.
What This Means
Remote work is permitted under NIST 800-171 and CMMC, but organizations must implement safeguards to protect CUI accessed or handled outside primary facilities. Alternate work sites include home offices, satellite offices, customer locations, government facilities, and mobile work (hotels, airports, travel).
Implementation Approach
Define Approved Work Sites: Organizations should formally approve alternate work sites and define security requirements for each type. Different sites may have different requirements—a government facility with existing security may need less than a home office.
Home Office Requirements: For employees working from home with CUI, consider secure workspace away from family members and guests, lockable storage for any printed CUI, encrypted devices with endpoint protection, secure disposal of CUI materials, and prohibition of voice assistants (Alexa, Siri) that could capture CUI discussions.
Technical Safeguards: Implement technical controls for remote CUI access including full disk encryption on all devices accessing CUI, VPN connections for all remote access (no split tunneling per 3.13.7), multi-factor authentication (3.5.3), endpoint detection and response (EDR) software, and mobile device management (MDM) for smartphones/tablets.
Policy and Training: Develop remote work policy documenting acceptable use at alternate sites, CUI handling procedures outside the office, requirements for secure storage and disposal, and reporting procedures for incidents at alternate sites. Train employees on their responsibilities for protecting CUI when working remotely.
Related Controls: This requirement integrates with several other NIST 800-171 controls for remote access including 3.1.12 (Monitor remote access sessions), 3.1.13 (Encrypt remote sessions), 3.1.14 (Route through managed access points), and 3.13.7 (Prevent split tunneling).
NIST SP 800-46 and SP 800-114 provide detailed guidance on enterprise and user security when teleworking.
Common Implementation Challenges
Challenge 1: Shared Facilities Organizations in shared office buildings or co-working spaces face challenges implementing physical security. Solutions include dedicated locked offices for CUI work, portable secure containers for CUI storage, VPN-only access to CUI systems, and negotiating security provisions with building management.
Challenge 2: Legacy Facilities Older buildings may lack infrastructure for modern access control systems. Consider standalone electronic locks that don’t require building-wide installation, key-based access with rigorous key control procedures, and security cameras as compensating detective controls.
Challenge 3: Remote Workforce With widespread remote work, applying physical security to home offices is challenging. Focus on technical controls (encryption, VPN, endpoint security), clear policies for CUI handling at home, and training employees on their responsibilities. Consider limiting CUI access to company-managed devices only.
Challenge 4: Visitor Volume Organizations with frequent visitors may struggle with escort requirements. Solutions include designated visitor areas where CUI is not present, pre-authorization processes for regular vendors, and dedicated escort personnel for high-traffic periods.
Challenge 5: Access Log Management Small organizations may find manual log review burdensome. Automated access control systems reduce manual logging, generate reports for periodic review, and provide alerts for unusual access patterns.
Challenge 6: Key Control Traditional key-based access makes control difficult because keys can be duplicated, lost keys require re-keying, and there’s no audit trail. Consider transitioning to electronic access control systems that provide better accountability and easier credential management.
Key Takeaways
Critical Points:
- 4 of 6 PE requirements cannot be on POA&M—physical security must be in place before assessment (3.10.1, 3.10.3, 3.10.4, 3.10.5)
- Physical security is first line of defense—technical controls are meaningless if attackers gain physical access
- Visitor escort is mandatory—all non-authorized individuals must be escorted in CUI areas
- Access logs required—automated or manual logs must track who accessed facilities and when
- Remote work is permitted—but requires comprehensive safeguards at alternate work sites
- Administrative controls dominate—PE requirements are mostly policies and procedures, not technology
Implementation Priorities:
- Identify and designate sensitive areas where CUI is processed or stored
- Implement access controls (locks, badges, key cards) limiting access to authorized personnel
- Establish visitor management procedures with escort requirements
- Deploy physical access logging (electronic or manual sign-in sheets)
- Implement access device control procedures for keys and badges
- Develop and enforce remote work security policy
Success Factors:
- Document authorization lists and keep them current as personnel change
- Train all employees on physical security responsibilities including visitor escort and tailgating prevention
- Regularly review physical access logs for anomalies
- Audit access device assignments against authorization lists
- Apply technical safeguards (encryption, VPN, EDR) to all remote work scenarios
- Test physical security controls periodically to verify effectiveness
Related Articles and External Resources
Official DoD and NIST Resources:
- DoD Cyber Exchange – CMMC: https://public.cyber.mil/cmmc/
- NIST SP 800-171 Rev 2: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
- NIST SP 800-171A (Assessment Procedures): https://csrc.nist.gov/publications/detail/sp/800-171a/rev-3/final
- NIST SP 800-46 (Telework Security): https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final
- NIST SP 800-114 (User Telework Security): https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final
- DFARS 252.204-7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting
- 32 CFR Part 170 (CMMC Program Rule): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
CMMC Assessment Resources:
- CMMC Level 2 Scoping Guide: https://dodcio.defense.gov/Portals/0/Documents/CMMC/Scoping_L2_V2.0.pdf
- CMMC Assessment Guide Level 2: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_L2_V2.0_FINAL_20211202_508.pdf
- DoD CIO CMMC Documentation: https://dodcio.defense.gov/CMMC/Documentation/
Last Updated: November 2025
This article provides guidance on Physical Protection (PE) requirements for CMMC Level 2 compliance based on NIST SP 800-171 Revision 2, 32 CFR Part 170, and official DoD CMMC program documentation.