DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.21
The CMMC Guide · Access Control Family

AC.L2-3.1.21  Limit Use of Portable Storage

Limit use of portable storage devices on external systems.

Family
Access ControlAC, 22 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

AC.L2-3.1.21 narrows the external-systems concern of the previous control to a specific and common vector: the portable storage device that a person carries from the organization's environment to an external system. It requires that the use of such devices on external systems be limited, closing a path by which CUI, or malware, moves between the controlled environment and systems the organization does not manage.

The concern runs in both directions. A thumb drive that leaves the environment holding CUI and is plugged into a home computer carries controlled data onto an unverified system; the same drive plugged back in can carry malware from that outside system into the environment. Because portable storage is small, personal, and easy to move without thought, it is a quiet channel across the boundary that formal network controls do not see. The control asks the organization to limit the use of portable storage on external systems, whether by restricting which devices may be used, prohibiting the practice, or controlling it under defined conditions, so that this easy path across the boundary is deliberately governed rather than left open.

The requirement · NIST SP 800-171 Rev 2, 3.1.21

Limit use of portable storage devices on external systems.

The requirement addresses portable storage devices, thumb drives, external drives, memory cards, used on external systems, meaning systems outside the organization's authorization boundary. "Limit use" ranges from restricting the practice to specific organization-controlled devices, to prohibiting the use of organizational portable storage on external systems entirely, to controlling it under conditions the organization sets. The organization decides the degree of limitation appropriate to its environment, and the control is satisfied when that limit is defined and enforced rather than left to individual habit.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.21 into three objectives: identify and document the use of portable storage on external systems, define the limits on that use, and enforce those limits.

[a]

The use of portable storage devices containing CUI on external systems is identified and documented. The organization has defined how, and whether, its portable storage may be used on external systems.

MeetsA defined policy stating that organizational portable storage may not be used on external systems, or may be used only under specific controlled conditions.
FailsNo position is taken, so portable storage moves between the environment and outside systems freely and unrecorded.
[b]

Limits on the use of portable storage devices containing CUI on external systems are defined. The specific restrictions are written down: which devices, under what conditions, or an outright prohibition, so there is a defined limit to enforce.

MeetsA policy stating the permitted conditions, such as approved and encrypted devices only, or an outright prohibition, specific enough to enforce.
FailsA vague instruction to be careful with USB drives that sets no actual limit.
[c]

The use of portable storage devices containing CUI on external systems is limited as defined. The defined limit is enforced, so the practice is actually constrained rather than only discouraged on paper.

MeetsPortable storage use is controlled through device policy and encryption, or the practice is prohibited and enforced through removable-media controls.
FailsThe limit is defined while nothing enforces it, so any drive is used anywhere regardless.

The three objectives move from documenting the practice to defining its limits to enforcing them, the pattern seen throughout this family. The common gap is at objective [c], where a policy discourages using organizational drives on outside systems while no technical control makes the limit real, so the practice continues out of habit. The assessor looks for enforcement that constrains the use, not merely a statement against it.

3Failure Patterns

The failures are about portable storage moving across the boundary without limit, and about a policy that exists without any enforcement behind it.

The drive that goes everywhere

A personal thumb drive used to move files between the shop, home, and a customer site travels across the boundary repeatedly, carrying CUI out and potentially carrying malware back. Without a defined and enforced limit, this everyday convenience is an unmonitored channel between the environment and every external system the drive touches.

Policy without enforcement

A policy may state that organizational portable storage is not to be used on external systems while nothing technically restricts it, so objective [c] fails even though [a] and [b] are documented. Removable-media controls or device restrictions have to make the limit real, since a rule against a convenient practice that nothing enforces will not hold.

No distinction between organizational and personal drives

Where the organization has not defined which portable storage is permitted, personal drives of unknown provenance are used freely in the environment and organizational drives leave it without control. Defining and controlling the permitted devices, and prohibiting the rest, is what gives this control something to enforce.

Unencrypted drives crossing the boundary

Even where some use is permitted, portable storage that carries CUI onto external systems without encryption exposes the data if the drive is lost or the external system is compromised. This ties to the media protection family, and an encrypted, controlled device is the minimum where portable storage is allowed to cross the boundary at all.

The common root
This control fails because the thumb drive is invisible to network controls. It crosses the boundary in a pocket, carrying CUI out and malware back, and unless the organization defines and enforces a limit, the easiest path across the boundary is the one nothing is watching.

4Ownership

This is an IT-owned control with a policy decision behind it about whether portable storage may cross the boundary at all, and its enforcement overlaps with the broader removable-media controls of the media protection family.

RoleResponsibility for this control
IT and system administratorEnforces the defined limit through removable-media controls, device restrictions, and encryption of permitted devices. Owns the technical evidence.
Security or compliance leadDefines the limit on portable storage use on external systems, whether prohibition or controlled use, and confirms enforcement makes it real.
Department supervisorsReinforce the practice on the floor, since portable storage habits are workflow habits, and a limit that ignores how files actually move will be worked around.
Program leadIncludes portable storage in periodic review and retains the policy and enforcement records.
See also: This control narrows the external-systems requirement at AC.L2-3.1.20 to portable storage specifically, and it overlaps with the removable-media and portable-storage controls of the media protection family.

5Tooling

The control is enforced with removable-media controls and device policy, the same tooling that governs portable storage generally, applied to the crossing of the boundary.

ObjectivesToolingWhat it provides
[a]Portable storage policy in the access and media policyThe defined limit on using portable storage on external systems, whether prohibition or controlled conditions.
[c] enforcementGroup Policy or Intune removable-storage controls, device control policiesRestricting or blocking portable storage use, and permitting only approved, controlled devices where use is allowed.
[c] protectionBitLocker To Go or equivalent encryption on permitted devicesEncrypting the permitted portable storage so that CUI crossing the boundary is protected if the device is lost.
VerificationDevice control logs and policy reportsEvidence that the limit is enforced across the environment, showing which devices are permitted and that others are blocked.

The caveat is that a workable limit accounts for how files actually move. A blanket prohibition that ignores a legitimate need for portable media will be circumvented, so the durable approach is often a small set of controlled, encrypted devices for the genuine cases and enforcement against the rest. The assessor tests objective [c] by checking whether portable storage use is actually constrained, so the enforcement has to be present rather than only the policy.

6Evidence

The satisfied version of 3.1.21 shows the defined limit and its enforcement across the environment.

EvidenceWhat it demonstrates
Portable storage policyObjective [a]. The defined limit on using portable storage on external systems.
Removable-media control configurationObjective [c]. The enforcement restricting or blocking portable storage use.
Approved device listObjectives [a], [b]. Where use is permitted, the controlled, encrypted devices allowed and the exclusion of others.
Device control logsObjective [c]. Records showing the limit in operation across the environment.

The evidence should show that the limit is enforced rather than merely stated, through the removable-media controls that constrain the practice, and where use is permitted, that the allowed devices are controlled and encrypted. Configuration and logs demonstrating that portable storage use is actually limited, paired with the defined policy, are the clearest demonstration of the control.

The thumb drive is the boundary nobody watches

Portable storage crosses the boundary in a pocket, and a policy alone will not stop it. Defining a workable limit that accounts for how files really move, providing controlled encrypted devices for the legitimate cases, and enforcing against the rest is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.21. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.21[a] through 3.1.21[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.20 · External Systems
Next in Access Control →
AC.L2-3.1.22 · Control Publicly Posted CUI
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.21 · Edition 2026.1 · Last reviewed July 12, 2026