DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.3
The CMMC Guide · Maintenance Family

MA.L2-3.7.3  Sanitize Equipment for Off-Site Maintenance

Ensure equipment removed for off-site maintenance is sanitized of any CUI.

Family
MaintenanceMA, 6 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MA.L2-3.7.3 protects CUI when equipment leaves for repair. It requires that equipment removed for off-site maintenance be sanitized of any CUI first, so that data does not walk out the door on a device sent to a third party. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

When a device is sent off-site for maintenance, it passes out of the organization's control and into a repair shop or vendor, and any CUI still on it goes along. This control requires that such equipment be sanitized of CUI before it leaves, so the data does not travel with the hardware to a place the organization cannot protect. It is a straightforward but important safeguard against an easily overlooked leak, the hard drive sent out for repair with sensitive data still on it.

The requirement · NIST SP 800-171 Rev 2, 3.7.3

Ensure equipment removed for off-site maintenance is sanitized of any CUI.

The requirement is specific: before equipment leaves organizational spaces for off-site maintenance, any CUI on it is sanitized. Sanitization means removing the data so it cannot be recovered, whether by securely wiping storage, removing the storage entirely, or another effective method. The point is that the device carries no CUI when it leaves the organization's control.

2The Assessment Objective

NIST SP 800-171A frames 3.7.3 as a single objective: sanitize equipment of CUI before off-site maintenance.

Equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. Devices leaving for repair carry no CUI.

MeetsEquipment is sanitized of CUI before it leaves for off-site maintenance.
FailsDevices are sent out for repair with CUI still on them.

The single objective is sanitizing equipment before off-site maintenance. The common failure is a device sent for repair without its CUI removed. The assessor looks for a process that sanitizes equipment before it leaves.

3Failure Patterns

The failures are about CUI leaving on equipment sent for repair.

Devices sent out with data intact

A device sent to a repair shop with CUI still on its storage exposes that data to whoever handles the device. Sanitizing before it leaves prevents the exposure.

Incomplete sanitization

Deleting files without securely wiping storage can leave recoverable data. Sanitization has to remove CUI so it cannot be recovered, or the storage has to be removed entirely.

No process for off-site maintenance

Without a defined step to sanitize equipment before off-site maintenance, devices go out ad hoc and CUI slips through. A process tied to sending equipment out closes this.

The common root
This control fails when equipment leaves faster than data is removed. Sending a device for repair is routine, and the CUI on it is easy to forget, so unless sanitization is a required step before the device leaves, sensitive data travels out to a place the organization cannot control.

4Ownership

This is an IT-owned control tied to the process for sending equipment out.

RoleResponsibility for this control
IT and system administratorSanitizes equipment of CUI before it leaves for off-site maintenance. Owns the sanitization evidence.
Security or compliance leadConfirms sanitization is a required step and is effective.
Program leadIncludes off-site maintenance in the equipment handling process and retains the records.
See also: This control draws on the media sanitization practices of the media protection family and complements the maintenance controls of MA.L2-3.7.2.

5Tooling

The control is delivered by sanitization before equipment leaves for maintenance.

ObjectiveToolingWhat it provides
sanitizeSecure wipe, storage removalRemoval of CUI so it cannot be recovered.
processOff-site maintenance procedureA required sanitization step before equipment leaves.

The caveat is that sanitization has to be effective and a required step, not an afterthought. Deleting files is not the same as securely removing recoverable data, and without a required step in the off-site process, devices leave with data intact. The assessor examines whether equipment is sanitized before off-site maintenance, so an effective, required process is what demonstrates the control.

6Evidence

The satisfied version of 3.7.3 shows equipment sanitized before off-site maintenance.

EvidenceWhat it demonstrates
Sanitization recordsThe objective. Equipment sanitized of CUI before leaving.
Off-site maintenance procedureThe objective. Sanitization required before off-site maintenance.

The evidence should show equipment sanitized of CUI before it leaves for off-site maintenance, tied to a required process. The sanitization records and the off-site procedure are the clearest demonstration of the control.

Do not let data leave on a device sent for repair

Equipment sent off-site passes out of the organization's control, and any CUI on it goes along unless it is removed first. Building sanitization into the process for sending equipment out is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.3. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Maintenance
MA.L2-3.7.2 · Control Maintenance Tools and Personnel
Next in Maintenance →
MA.L2-3.7.4 · Check Media for Malicious Code
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.3 · Edition 2026.1 · Last reviewed July 12, 2026