DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.2
The CMMC Guide · Media Protection Family

MP.L2-3.8.2  Limit Access to CUI on Media

Limit access to CUI on system media to authorized users.

Family
Media ProtectionMP, 9 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MP.L2-3.8.2 limits who can reach CUI on media. It requires that access to CUI on system media be limited to authorized users, so that the data on media is available only to those who are supposed to have it. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.

Protecting media physically is only half the picture; the CUI on it also has to be restricted to authorized users. This control requires that access to CUI on media be limited, whether that media is a shared drive, a removable device, or stored digital media, so that people without authorization cannot read the CUI it holds. It is the media expression of the same least-access principle that runs through the access control family, applied to the data at rest on media.

The requirement · NIST SP 800-171 Rev 2, 3.8.2

Limit access to CUI on system media to authorized users.

The requirement is that only authorized users can access the CUI held on media. In practice this is achieved through access controls on digital media and storage and through physical control of media that holds CUI, so that reaching the data requires authorization. It complements the physical protection of 3.8.1 by governing who may access the CUI, not just where the media is kept.

2The Assessment Objective

NIST SP 800-171A frames 3.8.2 as a single objective: limit access to CUI on media to authorized users.

Access to CUI on system media is limited to authorized users. Only authorized users can access CUI on media.

MeetsAccess to CUI on media is restricted to authorized users through access controls and physical control.
FailsCUI on media is accessible to users who are not authorized for it.

The single objective is limiting access to authorized users. The common failure is broadly accessible storage where CUI on media can be read by people without authorization. The assessor looks for access to CUI on media restricted to authorized users.

3Failure Patterns

The failures are about CUI on media reachable by the unauthorized.

Broadly accessible storage

Where CUI on shared digital media is accessible to everyone rather than only authorized users, access is not limited. Restricting access to the CUI through permissions closes this.

Removable media without access control

CUI on removable media that anyone can read once they have the device fails the control if the device is not physically controlled or the data protected. Access has to be limited to authorized users.

Authorization not defined

Without defining who is authorized for the CUI, access cannot be limited to them. Knowing the authorized users is the basis for restricting access.

The common root
This control fails when CUI on media is treated as reachable by anyone with general access. Physical protection keeps media in place, but the data on it still has to be restricted to authorized users, and broadly accessible storage lets unauthorized people read CUI the physical controls did not stop.

4Ownership

This is an IT-owned control tied to access controls on media and storage.

RoleResponsibility for this control
IT and system administratorRestricts access to CUI on media to authorized users through access controls. Owns the technical evidence.
Security or compliance leadDefines who is authorized for CUI and confirms access is limited to them.
Program leadReviews media access and retains the evidence.
See also: This control complements the physical protection of MP.L2-3.8.1 and applies the least-access principle of the access control family to CUI on media.

5Tooling

The control is delivered by access controls on digital media and physical control of media holding CUI.

ObjectiveToolingWhat it provides
digitalAccess controls on media and storageRestriction of CUI on digital media to authorized users.
physicalPhysical control of media holding CUIRestriction of access to media that holds CUI.

The caveat is that limiting access depends on knowing who is authorized. Access controls restrict CUI to those users, but only if the authorized set is defined. The assessor examines whether access to CUI on media is limited to authorized users, so the restriction and the definition of authorization both have to hold.

6Evidence

The satisfied version of 3.8.2 shows CUI on media restricted to authorized users.

EvidenceWhat it demonstrates
Media access controlsThe objective. CUI on media limited to authorized users.
Authorization definitionThe objective. Who is authorized for the CUI.

The evidence should show access to CUI on media limited to authorized users, backed by a definition of who is authorized. The access controls and authorization definition are the clearest demonstration, and because this control cannot sit on a plan of action, the restriction has to be real at the time of assessment.

Physical protection is not the same as access control

Keeping media in place does not restrict the CUI on it to authorized users, and this three-point control asks for that access limit. Restricting access to CUI on media through access controls is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.2. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.2 among the three-point basic security requirements. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.1 · Protect Media
Next in Media Protection →
MP.L2-3.8.3 · Sanitize or Destroy Media
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.2 · Edition 2026.1 · Last reviewed July 12, 2026