1Overview
AC.L2-3.1.9 is among the simplest requirements in the framework, and it is one of the few that most contractors can satisfy in an afternoon. It requires that system-use notices, the banner a user sees at logon, be displayed and that their content be consistent with the rules that apply to the CUI the organization handles.
The notice serves two purposes. It informs users that the system is monitored and that its use carries conditions, which supports later action against misuse, and it reflects the specific handling rules that attach to the information the system contains. The control is light in effort but not merely cosmetic, because the banner is the point at which a user is formally put on notice, and a system that quietly grants access without any statement of its conditions has skipped a small but expected step. A defensible notice, displayed before or at logon on the systems that handle CUI, is the whole of the control.
Provide privacy and security notices consistent with applicable CUI rules.
The phrase "consistent with applicable CUI rules" is what keeps this from being a generic banner requirement. The content of the notice should reflect the handling rules that apply to the CUI in the environment, which for most defense contractors means the standard system-use language together with any specific notice requirements that flow down through the contract. The organization does not draft these rules; it reflects the ones that apply.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.9 into two objectives: the required notice content is identified and consistent with the applicable rules, and the notice is displayed.
Privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. The organization has determined the notice content required by the rules that apply to its CUI, aligned to the specific CUI category.
Privacy and security notices are displayed. The identified notice is actually presented to users at logon on the systems that handle CUI.
The two objectives separate content from presentation: the organization identifies what the notice must say under the applicable rules and its CUI category, and the systems actually show it. Satisfaction is straightforward to demonstrate, which is why the more common shortfall is not a wrong banner but no banner at all on some subset of systems.
3Failure Patterns
The failures are minor and easily fixed, and they cluster, as with lockout, on the systems that central configuration does not reach.
No banner at all
Many environments simply present a login prompt with no system-use notice, because nobody ever configured one. This is the most common shortfall and the easiest to correct, requiring only that a defined notice be deployed to the systems that handle CUI.
The banner that misses the standalone systems
A logon notice pushed by Group Policy appears on domain-joined machines and is absent on the workgroup system, the standalone controller, and the local sign-in, the same coverage gap that affects other centrally managed settings. The notice has to reach the systems in scope, not merely the convenient ones.
Generic content unrelated to the applicable rules
A banner copied from a template may state general terms of use without reflecting the CUI handling rules that actually apply, which weakens the "consistent with applicable CUI rules" element of the requirement. The content should align with the rules that flow to the organization rather than a boilerplate unrelated to them.
The cloud and remote sign-in without a notice
The system-use notice configured for local logon may not appear on the cloud identity portal or the remote access gateway, leaving the more exposed entry points without the statement of conditions. Where CUI is reached through cloud or remote services, the notice belongs there as well.
4Ownership
This is an IT-owned control with a small content contribution from whoever tracks the applicable handling rules. Its only real demand is consistent deployment.
| Role | Responsibility for this control |
|---|---|
| IT lead or system administrator | Deploys the logon notice across the systems that handle CUI, including standalone machines and cloud and remote sign-in surfaces. Owns the deployment evidence. |
| Security or compliance lead | Determines the notice content consistent with the applicable CUI rules and any notice language that flows through the contract, and confirms the deployed banner reflects it. |
| Program lead | Includes notice coverage in periodic review so new systems and services receive it, and retains a record of the standard notice text. |
5Tooling
The control is deployed with native banner settings and needs no special software, only consistent application across every sign-in surface.
| Objective | Tooling | What it provides |
|---|---|---|
| [b] domain | Group Policy interactive logon message title and text | The logon notice displayed on domain-joined systems before sign-in, set centrally and applied consistently. |
| [b] standalone | Local security policy, configuration baselines | The same notice on workgroup machines and local accounts that Group Policy does not reach. |
| [b] cloud and remote | Entra ID or identity-provider sign-in banner, VPN and remote gateway login notice | The notice on the cloud portal and remote access surfaces, so the exposed sign-in carries it as well. |
| Content | A defined standard notice text | The approved wording, consistent with the applicable CUI rules, kept as the reference deployed everywhere. |
The caveat is simply completeness. Every platform can display a logon notice, so the control turns on whether it appears everywhere a user signs in to reach CUI. The assessor confirms the objective by signing in, or observing sign-in, on representative systems and checking that the notice is present and consistent with the applicable rules.
6Evidence
The satisfied version of 3.1.9 shows the defined notice and its presence across the relevant systems.
| Evidence | What it demonstrates |
|---|---|
| Standard notice text | Objective [a]. The approved wording, consistent with the applicable CUI rules. |
| Group Policy banner configuration | Objective [b]. The notice deployed to domain-joined systems. |
| Standalone system configuration | Objective [b]. The notice present on workgroup machines and local sign-ins. |
| Cloud and remote sign-in notice | Objective [b]. The notice on the cloud portal and remote access. |
| Screenshots of the displayed notice | Objective [b]. Direct evidence the banner appears at logon on representative systems. |
The evidence is easy to produce, and a short set of screenshots across a domain machine, a standalone machine, and a cloud sign-in usually demonstrates the control convincingly. Because the shortfall is almost always a missing banner rather than a wrong one, the evidence that matters most is the coverage across the different sign-in surfaces.
A quick control worth finishing completely
The login banner takes an afternoon, and the only way to get it wrong is to leave it off the standalone machine or the cloud sign-in. Confirming the notice is present and consistent everywhere CUI is reached is part of the onsite readiness work this practice does, usually alongside the other quick configuration controls.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.9. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.9[a] and 3.1.9[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov