DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.3
The CMMC Guide · Media Protection Family

MP.L2-3.8.3  Sanitize or Destroy Media

Sanitize or destroy system media containing CUI before disposal or release for reuse.

Family
Media ProtectionMP, 9 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

MP.L2-3.8.3 is the family's first five-point requirement and it governs the end of media's life. It requires that the organization sanitize or destroy system media containing CUI before disposal or release for reuse, so that CUI does not leave the organization on discarded or repurposed media. It is a five-point requirement that cannot be deferred on a plan of action.

Media outlives its use, and when it is thrown away or handed on, any CUI still on it goes too. A discarded drive, a returned lease device, a disk passed to another user, each can carry recoverable CUI to someone who should not have it. This control requires that media be sanitized or destroyed before disposal or reuse, so the data is gone before the media leaves the organization's control or changes hands. Its five-point weight reflects that improper media disposal is a direct and irreversible way CUI is lost.

The requirement · NIST SP 800-171 Rev 2, 3.8.3

Sanitize or destroy system media containing CUI before disposal or release for reuse.

The requirement covers two end-of-life paths. Before disposal, media is sanitized or destroyed so discarded media carries no recoverable CUI. Before release for reuse, media is sanitized so the next user cannot access the previous CUI. Sanitization means removing the data so it cannot be recovered; destruction physically renders the media unusable. Deleting files is not sufficient, because deleted data is often recoverable, so the method has to genuinely remove or destroy the CUI.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.8.3 into two objectives: sanitize or destroy before disposal, and sanitize before reuse.

[a]

System media containing CUI is sanitized or destroyed before disposal. Discarded media carries no recoverable CUI.

MeetsMedia is sanitized or destroyed before disposal, so discarded media holds no recoverable CUI.
FailsMedia with CUI is thrown away with the data still recoverable.
[b]

System media containing CUI is sanitized before it is released for reuse. Reused media carries no previous CUI.

MeetsMedia is sanitized before reuse, so the next user cannot access previous CUI.
FailsMedia is reassigned with the previous CUI still on it.

The two objectives cover disposal and reuse. The common gap is treating deletion as sufficient, since deleted data is often recoverable, so media disposed of or reused after only a file deletion still carries CUI. The assessor looks for genuine sanitization or destruction before media leaves or changes hands.

3Failure Patterns

The failures are about recoverable CUI on disposed or reused media.

Deletion mistaken for sanitization

Deleting files leaves data that is often recoverable, so media disposed of after only a deletion still carries CUI. Sanitization has to remove the data so it cannot be recovered, or the media has to be destroyed.

Media reused without sanitization

Reassigning media to a new user without sanitizing it hands them the previous CUI. Sanitization before reuse prevents this.

Discarded drives not destroyed

Drives thrown away or returned without destruction or sanitization carry recoverable CUI out of the organization. Destruction or effective sanitization before disposal closes this.

No disposal and reuse process

Without a defined process for sanitizing or destroying media at end of life, media leaves ad hoc with CUI intact. A process tied to disposal and reuse closes the gap.

The common root
This control fails when deletion is mistaken for removal. Deleted data lingers recoverably, so media disposed of or reused after a simple delete still carries CUI out of the organization, irreversibly. Genuine sanitization or destruction is what actually removes it.

4Ownership

This is an IT-owned control tied to the disposal and reuse process.

RoleResponsibility for this control
IT and system administratorSanitizes or destroys media containing CUI before disposal or reuse. Owns the sanitization evidence.
Security or compliance leadConfirms the method genuinely removes or destroys CUI and covers both disposal and reuse.
Program leadTies sanitization to the media lifecycle and retains the records.
See also: This control completes the media lifecycle begun in MP.L2-3.8.1 and relates to the off-site maintenance sanitization of MA.L2-3.7.3.

5Tooling

The control is delivered by sanitization and destruction methods applied before disposal or reuse.

ObjectivesToolingWhat it provides
[a] destroyPhysical destruction, shredding, degaussingIrreversible destruction of media before disposal.
[a], [b] sanitizeSecure wipe to a recognized standardRemoval of CUI so it cannot be recovered.
ProcessMedia disposal and reuse procedureA required sanitization or destruction step at end of life.

The caveat is that the method has to genuinely remove or destroy the CUI, not merely delete it, and cover both disposal and reuse. A secure wipe to a recognized standard or physical destruction is what satisfies the control. The assessor examines whether media is sanitized or destroyed before it leaves or is reused, so the method has to be effective and the process required.

6Evidence

The satisfied version of 3.8.3 shows media sanitized or destroyed before disposal or reuse.

EvidenceWhat it demonstrates
Sanitization and destruction recordsObjectives [a], [b]. Media sanitized or destroyed before disposal and reuse.
Media disposal procedureObjectives [a], [b]. A required step at end of life.

The evidence should show media containing CUI sanitized or destroyed before disposal and sanitized before reuse, by an effective method. The sanitization and destruction records with the disposal procedure are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

Deleted is not the same as gone

Media outlives its use, and deleted data lingers recoverably, so this five-point control requires genuine sanitization or destruction before disposal or reuse. Building an effective media end-of-life process is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.8.3[a] and 3.8.3[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MP.L2-3.8.3 among the five-point basic security requirements. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.2 · Limit Access to CUI on Media
Next in Media Protection →
MP.L2-3.8.4 · Mark Media
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.3 · Edition 2026.1 · Last reviewed July 12, 2026