1Overview
AC.L2-3.1.19 completes the mobile-device pair. Where 3.1.18 controls which mobile devices may connect, this control requires that the CUI on those devices be encrypted, so that a lost or stolen device does not surrender its data to whoever finds it.
Mobile devices are lost and stolen, and that is the risk this control addresses directly. A phone left in a taxi, a laptop taken from a car, a tablet forgotten at a customer site, each becomes a data breach only if the CUI on it can be read. Encryption of the data at rest on the device is what turns a lost device from a disclosure into an inconvenience, because the finder holds encrypted data they cannot access rather than readable CUI. The control requires that CUI on mobile devices and mobile computing platforms be encrypted, and for an environment handling CUI the encryption is expected to be strong and, where applicable, validated, connecting this control to the cryptographic requirements elsewhere in the framework.
Encrypt CUI on mobile devices and mobile computing platforms.
The requirement covers mobile devices and mobile computing platforms, which includes the phones and tablets of the paired control and the laptops that carry CUI out of the building. "Encrypt CUI" means the controlled data at rest on those devices is protected by encryption, whether through full-device encryption or the encryption of the container or application that holds the CUI. The encryption protects the data when the device is off or locked and out of the organization's hands, which is precisely when a lost device would otherwise expose it.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.19 into two objectives: identify the mobile devices and platforms that carry CUI, and encrypt the CUI on them.
Mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. The organization knows which mobile devices and laptops hold CUI, so their encryption can be assured.
Encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. The CUI at rest on those devices is encrypted with a strong method.
The two objectives are identification and encryption. The common gap is at objective [b] on laptops, where phones may be encrypted by default while a laptop carrying far more CUI has no full-disk encryption enabled, so the device most likely to hold a large volume of controlled data is the one left unprotected.
3Failure Patterns
The failures are about devices carrying CUI without encryption, most often the laptop, and about encryption that is present but unverified.
The unencrypted laptop
The most consequential failure of this control is a laptop that carries CUI with no full-disk encryption, because a laptop holds far more data than a phone and is a frequent theft target. Full-disk encryption is available on business operating systems and often needs only to be enabled and its keys managed, yet it is commonly left off, leaving the drive readable to anyone who removes it.
Encryption present but unverified
A device may have encryption available or partially configured while the organization cannot show it is actually enabled and enforced across the identified devices. Objective [b] expects encryption in force and demonstrable, and an assumption that laptops are encrypted, without a report confirming it, does not satisfy the control.
CUI on the personal device outside any container
Where CUI reaches a personal phone through unmanaged mail, it sits outside any encrypted container the organization controls, so even if the phone has device encryption, the organization cannot assure it. Confining CUI to a managed, encrypted application is what brings the personal-device case under this control, tying it to the connection control of the paired requirement.
Weak or unmanaged keys
Encryption is only as strong as the protection of its keys, and full-disk encryption whose recovery keys are unmanaged or stored insecurely weakens the protection. For CUI the encryption is expected to be strong and its keys managed, so a device encrypted with keys left exposed does not fully meet the intent.
4Ownership
This is an IT-owned technical control whose main demand is enabling and verifying encryption across every mobile device that carries CUI, laptops especially, and managing the keys.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Enables and enforces encryption on the identified mobile devices, manages the recovery keys, and produces reports confirming encryption is in force. Owns the technical evidence. |
| Security or compliance lead | Confirms the encryption meets the strength expected for CUI and that keys are managed, connecting to the framework's cryptographic requirements. |
| Program lead | Ensures new mobile devices receive encryption before carrying CUI and includes encryption status in periodic review, retaining the confirming reports. |
5Tooling
The control is delivered by device encryption, managed and verified through the same platforms that manage the devices, with keys escrowed for recovery.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Device inventory from mobile device management | The identified mobile devices and laptops carrying CUI, consistent with the paired connection control. |
| [b] laptops | BitLocker or equivalent full-disk encryption, key escrow to the directory or management platform | Full-disk encryption of laptops with recovery keys managed centrally, protecting CUI at rest and verifiable through reporting. |
| [b] phones and tablets | Device encryption enforced through mobile device management, encrypted managed apps | Device or container encryption on phones and tablets, enforced and confirmed through the management platform. |
| Verification | Encryption status and compliance reports | Reports confirming encryption is enabled and in force across the identified devices, the evidence the control is actually met. |
The caveat is that encryption must be verified, not assumed, and its keys managed. Full-disk encryption that is available but never confirmed enabled, or enabled with recovery keys stored insecurely, does not fully satisfy the control, so the work includes the reporting that proves encryption is in force and the escrow that keeps the keys both recoverable and protected. The assessor tests objective [b] by asking for evidence that the identified devices are encrypted, so a compliance report showing encryption enabled across them is what demonstrates the control.
6Evidence
The satisfied version of 3.1.19 shows the identified mobile devices and verified encryption of the CUI on them.
| Evidence | What it demonstrates |
|---|---|
| Mobile device inventory | Objective [a]. The identified devices and platforms that carry CUI. |
| Encryption status report | Objective [b]. Confirmation that full-disk or device encryption is enabled and in force across the identified devices. |
| Key management and escrow | Objective [b]. Evidence that recovery keys are managed and protected. |
| Managed application encryption | Objective [b]. Where used, the encrypted app container confining CUI on personal devices. |
The evidence should confirm encryption is actually in force rather than merely available, which a compliance or status report across the identified devices provides, and it should account for the laptops as much as the phones, since the laptop is the common gap. Reporting that shows encryption enabled everywhere CUI is carried, with keys managed, is the clearest demonstration of the control.
The laptop is where this one hides
Phones tend to encrypt themselves; the laptop carrying a folder of drawings out to a customer site is the device whose full-disk encryption often was never turned on. Enabling and verifying encryption across every mobile device that carries CUI, and managing the keys, is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.19. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.19[a] and 3.1.19[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov