1Overview
MP.L2-3.8.3 is the family's first five-point requirement and it governs the end of media's life. It requires that the organization sanitize or destroy system media containing CUI before disposal or release for reuse, so that CUI does not leave the organization on discarded or repurposed media. It is a five-point requirement that cannot be deferred on a plan of action.
Media outlives its use, and when it is thrown away or handed on, any CUI still on it goes too. A discarded drive, a returned lease device, a disk passed to another user, each can carry recoverable CUI to someone who should not have it. This control requires that media be sanitized or destroyed before disposal or reuse, so the data is gone before the media leaves the organization's control or changes hands. Its five-point weight reflects that improper media disposal is a direct and irreversible way CUI is lost.
Sanitize or destroy system media containing CUI before disposal or release for reuse.
The requirement covers two end-of-life paths. Before disposal, media is sanitized or destroyed so discarded media carries no recoverable CUI. Before release for reuse, media is sanitized so the next user cannot access the previous CUI. Sanitization means removing the data so it cannot be recovered; destruction physically renders the media unusable. Deleting files is not sufficient, because deleted data is often recoverable, so the method has to genuinely remove or destroy the CUI.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.8.3 into two objectives: sanitize or destroy before disposal, and sanitize before reuse.
System media containing CUI is sanitized or destroyed before disposal. Discarded media carries no recoverable CUI.
System media containing CUI is sanitized before it is released for reuse. Reused media carries no previous CUI.
The two objectives cover disposal and reuse. The common gap is treating deletion as sufficient, since deleted data is often recoverable, so media disposed of or reused after only a file deletion still carries CUI. The assessor looks for genuine sanitization or destruction before media leaves or changes hands.
3Failure Patterns
The failures are about recoverable CUI on disposed or reused media.
Deletion mistaken for sanitization
Deleting files leaves data that is often recoverable, so media disposed of after only a deletion still carries CUI. Sanitization has to remove the data so it cannot be recovered, or the media has to be destroyed.
Media reused without sanitization
Reassigning media to a new user without sanitizing it hands them the previous CUI. Sanitization before reuse prevents this.
Discarded drives not destroyed
Drives thrown away or returned without destruction or sanitization carry recoverable CUI out of the organization. Destruction or effective sanitization before disposal closes this.
No disposal and reuse process
Without a defined process for sanitizing or destroying media at end of life, media leaves ad hoc with CUI intact. A process tied to disposal and reuse closes the gap.
4Ownership
This is an IT-owned control tied to the disposal and reuse process.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Sanitizes or destroys media containing CUI before disposal or reuse. Owns the sanitization evidence. |
| Security or compliance lead | Confirms the method genuinely removes or destroys CUI and covers both disposal and reuse. |
| Program lead | Ties sanitization to the media lifecycle and retains the records. |
5Tooling
The control is delivered by sanitization and destruction methods applied before disposal or reuse.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] destroy | Physical destruction, shredding, degaussing | Irreversible destruction of media before disposal. |
| [a], [b] sanitize | Secure wipe to a recognized standard | Removal of CUI so it cannot be recovered. |
| Process | Media disposal and reuse procedure | A required sanitization or destruction step at end of life. |
The caveat is that the method has to genuinely remove or destroy the CUI, not merely delete it, and cover both disposal and reuse. A secure wipe to a recognized standard or physical destruction is what satisfies the control. The assessor examines whether media is sanitized or destroyed before it leaves or is reused, so the method has to be effective and the process required.
6Evidence
The satisfied version of 3.8.3 shows media sanitized or destroyed before disposal or reuse.
| Evidence | What it demonstrates |
|---|---|
| Sanitization and destruction records | Objectives [a], [b]. Media sanitized or destroyed before disposal and reuse. |
| Media disposal procedure | Objectives [a], [b]. A required step at end of life. |
The evidence should show media containing CUI sanitized or destroyed before disposal and sanitized before reuse, by an effective method. The sanitization and destruction records with the disposal procedure are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
Deleted is not the same as gone
Media outlives its use, and deleted data lingers recoverably, so this five-point control requires genuine sanitization or destruction before disposal or reuse. Building an effective media end-of-life process is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.8.3[a] and 3.8.3[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.3 among the five-point basic security requirements. ecfr.gov