DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.19
The CMMC Guide · Access Control Family

AC.L2-3.1.19  Encrypt CUI on Mobile Devices

Encrypt CUI on mobile devices and mobile computing platforms.

Family
Access ControlAC, 22 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

AC.L2-3.1.19 completes the mobile-device pair. Where 3.1.18 controls which mobile devices may connect, this control requires that the CUI on those devices be encrypted, so that a lost or stolen device does not surrender its data to whoever finds it.

Mobile devices are lost and stolen, and that is the risk this control addresses directly. A phone left in a taxi, a laptop taken from a car, a tablet forgotten at a customer site, each becomes a data breach only if the CUI on it can be read. Encryption of the data at rest on the device is what turns a lost device from a disclosure into an inconvenience, because the finder holds encrypted data they cannot access rather than readable CUI. The control requires that CUI on mobile devices and mobile computing platforms be encrypted, and for an environment handling CUI the encryption is expected to be strong and, where applicable, validated, connecting this control to the cryptographic requirements elsewhere in the framework.

The requirement · NIST SP 800-171 Rev 2, 3.1.19

Encrypt CUI on mobile devices and mobile computing platforms.

The requirement covers mobile devices and mobile computing platforms, which includes the phones and tablets of the paired control and the laptops that carry CUI out of the building. "Encrypt CUI" means the controlled data at rest on those devices is protected by encryption, whether through full-device encryption or the encryption of the container or application that holds the CUI. The encryption protects the data when the device is off or locked and out of the organization's hands, which is precisely when a lost device would otherwise expose it.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.19 into two objectives: identify the mobile devices and platforms that carry CUI, and encrypt the CUI on them.

[a]

Mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. The organization knows which mobile devices and laptops hold CUI, so their encryption can be assured.

MeetsThe identified set of laptops, phones, and tablets that carry CUI, consistent with the mobile inventory of the paired control.
FailsIt is unknown which mobile devices hold CUI, so encryption cannot be confirmed for them.
[b]

Encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. The CUI at rest on those devices is encrypted with a strong method.

MeetsFull-disk encryption on laptops and device or container encryption on phones and tablets, enforced and verified, protecting the CUI at rest.
FailsA laptop carrying CUI has no disk encryption, so its drive can be read if the device is lost or stolen.

The two objectives are identification and encryption. The common gap is at objective [b] on laptops, where phones may be encrypted by default while a laptop carrying far more CUI has no full-disk encryption enabled, so the device most likely to hold a large volume of controlled data is the one left unprotected.

3Failure Patterns

The failures are about devices carrying CUI without encryption, most often the laptop, and about encryption that is present but unverified.

The unencrypted laptop

The most consequential failure of this control is a laptop that carries CUI with no full-disk encryption, because a laptop holds far more data than a phone and is a frequent theft target. Full-disk encryption is available on business operating systems and often needs only to be enabled and its keys managed, yet it is commonly left off, leaving the drive readable to anyone who removes it.

Encryption present but unverified

A device may have encryption available or partially configured while the organization cannot show it is actually enabled and enforced across the identified devices. Objective [b] expects encryption in force and demonstrable, and an assumption that laptops are encrypted, without a report confirming it, does not satisfy the control.

CUI on the personal device outside any container

Where CUI reaches a personal phone through unmanaged mail, it sits outside any encrypted container the organization controls, so even if the phone has device encryption, the organization cannot assure it. Confining CUI to a managed, encrypted application is what brings the personal-device case under this control, tying it to the connection control of the paired requirement.

Weak or unmanaged keys

Encryption is only as strong as the protection of its keys, and full-disk encryption whose recovery keys are unmanaged or stored insecurely weakens the protection. For CUI the encryption is expected to be strong and its keys managed, so a device encrypted with keys left exposed does not fully meet the intent.

The common root
This control fails on the laptop more than the phone. Modern phones often encrypt by default, while the laptop that carries the most CUI is the one whose full-disk encryption was never switched on, so the device with the greatest exposure is the one most often unprotected.

4Ownership

This is an IT-owned technical control whose main demand is enabling and verifying encryption across every mobile device that carries CUI, laptops especially, and managing the keys.

RoleResponsibility for this control
IT and system administratorEnables and enforces encryption on the identified mobile devices, manages the recovery keys, and produces reports confirming encryption is in force. Owns the technical evidence.
Security or compliance leadConfirms the encryption meets the strength expected for CUI and that keys are managed, connecting to the framework's cryptographic requirements.
Program leadEnsures new mobile devices receive encryption before carrying CUI and includes encryption status in periodic review, retaining the confirming reports.
See also: This control completes the mobile pair with AC.L2-3.1.18, and its encryption strength ties to the FIPS-validated cryptography requirement at 3.13.11 and the protection-of-CUI-at-rest requirement at 3.13.16.

5Tooling

The control is delivered by device encryption, managed and verified through the same platforms that manage the devices, with keys escrowed for recovery.

ObjectivesToolingWhat it provides
[a]Device inventory from mobile device managementThe identified mobile devices and laptops carrying CUI, consistent with the paired connection control.
[b] laptopsBitLocker or equivalent full-disk encryption, key escrow to the directory or management platformFull-disk encryption of laptops with recovery keys managed centrally, protecting CUI at rest and verifiable through reporting.
[b] phones and tabletsDevice encryption enforced through mobile device management, encrypted managed appsDevice or container encryption on phones and tablets, enforced and confirmed through the management platform.
VerificationEncryption status and compliance reportsReports confirming encryption is enabled and in force across the identified devices, the evidence the control is actually met.

The caveat is that encryption must be verified, not assumed, and its keys managed. Full-disk encryption that is available but never confirmed enabled, or enabled with recovery keys stored insecurely, does not fully satisfy the control, so the work includes the reporting that proves encryption is in force and the escrow that keeps the keys both recoverable and protected. The assessor tests objective [b] by asking for evidence that the identified devices are encrypted, so a compliance report showing encryption enabled across them is what demonstrates the control.

6Evidence

The satisfied version of 3.1.19 shows the identified mobile devices and verified encryption of the CUI on them.

EvidenceWhat it demonstrates
Mobile device inventoryObjective [a]. The identified devices and platforms that carry CUI.
Encryption status reportObjective [b]. Confirmation that full-disk or device encryption is enabled and in force across the identified devices.
Key management and escrowObjective [b]. Evidence that recovery keys are managed and protected.
Managed application encryptionObjective [b]. Where used, the encrypted app container confining CUI on personal devices.

The evidence should confirm encryption is actually in force rather than merely available, which a compliance or status report across the identified devices provides, and it should account for the laptops as much as the phones, since the laptop is the common gap. Reporting that shows encryption enabled everywhere CUI is carried, with keys managed, is the clearest demonstration of the control.

The laptop is where this one hides

Phones tend to encrypt themselves; the laptop carrying a folder of drawings out to a customer site is the device whose full-disk encryption often was never turned on. Enabling and verifying encryption across every mobile device that carries CUI, and managing the keys, is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.19. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.19[a] and 3.1.19[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.18 · Control Connection of Mobile Devices
Next in Access Control →
AC.L2-3.1.20 · External Systems
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.19 · Edition 2026.1 · Last reviewed July 12, 2026