DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.9
The CMMC Guide · Access Control Family

AC.L2-3.1.9  Privacy and Security Notices

Provide privacy and security notices consistent with applicable CUI rules.

Family
Access ControlAC, 22 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

AC.L2-3.1.9 is among the simplest requirements in the framework, and it is one of the few that most contractors can satisfy in an afternoon. It requires that system-use notices, the banner a user sees at logon, be displayed and that their content be consistent with the rules that apply to the CUI the organization handles.

The notice serves two purposes. It informs users that the system is monitored and that its use carries conditions, which supports later action against misuse, and it reflects the specific handling rules that attach to the information the system contains. The control is light in effort but not merely cosmetic, because the banner is the point at which a user is formally put on notice, and a system that quietly grants access without any statement of its conditions has skipped a small but expected step. A defensible notice, displayed before or at logon on the systems that handle CUI, is the whole of the control.

The requirement · NIST SP 800-171 Rev 2, 3.1.9

Provide privacy and security notices consistent with applicable CUI rules.

The phrase "consistent with applicable CUI rules" is what keeps this from being a generic banner requirement. The content of the notice should reflect the handling rules that apply to the CUI in the environment, which for most defense contractors means the standard system-use language together with any specific notice requirements that flow down through the contract. The organization does not draft these rules; it reflects the ones that apply.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.9 into two objectives: the required notice content is identified and consistent with the applicable rules, and the notice is displayed.

[a]

Privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. The organization has determined the notice content required by the rules that apply to its CUI, aligned to the specific CUI category.

MeetsApproved banner wording aligned to the applicable handling rules and CUI category, recorded as the standard notice.
FailsNo determination of required content, or a generic notice unrelated to the applicable CUI rules.
[b]

Privacy and security notices are displayed. The identified notice is actually presented to users at logon on the systems that handle CUI.

MeetsA logon banner on the systems handling CUI stating the system is for authorized use and is monitored, shown before sign-in.
FailsSystems present no notice at logon on some subset of systems.

The two objectives separate content from presentation: the organization identifies what the notice must say under the applicable rules and its CUI category, and the systems actually show it. Satisfaction is straightforward to demonstrate, which is why the more common shortfall is not a wrong banner but no banner at all on some subset of systems.

3Failure Patterns

The failures are minor and easily fixed, and they cluster, as with lockout, on the systems that central configuration does not reach.

No banner at all

Many environments simply present a login prompt with no system-use notice, because nobody ever configured one. This is the most common shortfall and the easiest to correct, requiring only that a defined notice be deployed to the systems that handle CUI.

The banner that misses the standalone systems

A logon notice pushed by Group Policy appears on domain-joined machines and is absent on the workgroup system, the standalone controller, and the local sign-in, the same coverage gap that affects other centrally managed settings. The notice has to reach the systems in scope, not merely the convenient ones.

Generic content unrelated to the applicable rules

A banner copied from a template may state general terms of use without reflecting the CUI handling rules that actually apply, which weakens the "consistent with applicable CUI rules" element of the requirement. The content should align with the rules that flow to the organization rather than a boilerplate unrelated to them.

The cloud and remote sign-in without a notice

The system-use notice configured for local logon may not appear on the cloud identity portal or the remote access gateway, leaving the more exposed entry points without the statement of conditions. Where CUI is reached through cloud or remote services, the notice belongs there as well.

The common root
This control fails by omission rather than by error. The banner is easy to write and easy to deploy, and the shortfall is almost always a system or a sign-in surface that was simply left without one.

4Ownership

This is an IT-owned control with a small content contribution from whoever tracks the applicable handling rules. Its only real demand is consistent deployment.

RoleResponsibility for this control
IT lead or system administratorDeploys the logon notice across the systems that handle CUI, including standalone machines and cloud and remote sign-in surfaces. Owns the deployment evidence.
Security or compliance leadDetermines the notice content consistent with the applicable CUI rules and any notice language that flows through the contract, and confirms the deployed banner reflects it.
Program leadIncludes notice coverage in periodic review so new systems and services receive it, and retains a record of the standard notice text.
See also: The notice sits alongside the broader awareness obligations of the awareness and training family, which addresses what users are taught beyond what the banner states.

5Tooling

The control is deployed with native banner settings and needs no special software, only consistent application across every sign-in surface.

ObjectiveToolingWhat it provides
[b] domainGroup Policy interactive logon message title and textThe logon notice displayed on domain-joined systems before sign-in, set centrally and applied consistently.
[b] standaloneLocal security policy, configuration baselinesThe same notice on workgroup machines and local accounts that Group Policy does not reach.
[b] cloud and remoteEntra ID or identity-provider sign-in banner, VPN and remote gateway login noticeThe notice on the cloud portal and remote access surfaces, so the exposed sign-in carries it as well.
ContentA defined standard notice textThe approved wording, consistent with the applicable CUI rules, kept as the reference deployed everywhere.

The caveat is simply completeness. Every platform can display a logon notice, so the control turns on whether it appears everywhere a user signs in to reach CUI. The assessor confirms the objective by signing in, or observing sign-in, on representative systems and checking that the notice is present and consistent with the applicable rules.

6Evidence

The satisfied version of 3.1.9 shows the defined notice and its presence across the relevant systems.

EvidenceWhat it demonstrates
Standard notice textObjective [a]. The approved wording, consistent with the applicable CUI rules.
Group Policy banner configurationObjective [b]. The notice deployed to domain-joined systems.
Standalone system configurationObjective [b]. The notice present on workgroup machines and local sign-ins.
Cloud and remote sign-in noticeObjective [b]. The notice on the cloud portal and remote access.
Screenshots of the displayed noticeObjective [b]. Direct evidence the banner appears at logon on representative systems.

The evidence is easy to produce, and a short set of screenshots across a domain machine, a standalone machine, and a cloud sign-in usually demonstrates the control convincingly. Because the shortfall is almost always a missing banner rather than a wrong one, the evidence that matters most is the coverage across the different sign-in surfaces.

A quick control worth finishing completely

The login banner takes an afternoon, and the only way to get it wrong is to leave it off the standalone machine or the cloud sign-in. Confirming the notice is present and consistent everywhere CUI is reached is part of the onsite readiness work this practice does, usually alongside the other quick configuration controls.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.9. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.9[a] and 3.1.9[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.8 · Limit Unsuccessful Logon Attempts
Next in Access Control →
AC.L2-3.1.10 · Session Lock
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.9 · Edition 2026.1 · Last reviewed July 12, 2026