1Overview
MP.L2-3.8.6 protects digital CUI while media moves. It requires cryptographic mechanisms to protect the confidentiality of CUI on digital media during transport, unless the media is otherwise protected by alternative physical safeguards, so that data on a device in transit is unreadable if the device is lost or taken. It is a one-point requirement and may be deferred on a plan of action.
A digital device in transport can be lost or stolen, and if the CUI on it is not protected, whoever ends up with the device has the data. This control requires that the confidentiality of CUI on digital media be protected during transport, most commonly through encryption, so that a lost or stolen device yields no readable CUI. The requirement allows alternative physical safeguards where those provide equivalent protection, but encryption is the usual and most practical mechanism.
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.
The requirement is to protect the confidentiality of CUI on digital media during transport, with cryptographic mechanisms as the default and alternative physical safeguards as an option where they provide equivalent protection. Encryption means the data on the device is unreadable without the key, so losing the device does not expose the CUI. The single assessment objective is that this confidentiality protection is in place during transport.
2The Assessment Objective
NIST SP 800-171A frames 3.8.6 as a single objective: protect the confidentiality of CUI on digital media during transport.
The confidentiality of CUI stored on digital media during transport is protected using cryptographic mechanisms or alternative physical safeguards. CUI on media in transit is unreadable if the media is lost.
The single objective is confidentiality protection during transport. The common failure is an unencrypted device carrying CUI off-site, so a loss exposes the data. The assessor looks for encryption or equivalent physical protection of CUI on digital media in transport.
3Failure Patterns
The failures are about unprotected CUI on media in transit.
Unencrypted devices in transport
A laptop or drive carrying unencrypted CUI off-site exposes the data if the device is lost or stolen. Encrypting the media protects the confidentiality regardless of the device's fate.
Encryption not applied to all transported media
Where some transported media is encrypted and some is not, the unencrypted media remains a risk. The protection has to cover all digital media carrying CUI in transport.
Weak or absent physical alternative
Relying on physical safeguards that do not actually provide equivalent protection leaves CUI exposed. Where encryption is not used, the physical safeguards have to genuinely protect the confidentiality.
4Ownership
This is an IT-owned technical control tied to encryption of transported media.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Implements encryption on digital media carrying CUI in transport. Owns the technical evidence. |
| Security or compliance lead | Confirms confidentiality protection covers all transported media, by encryption or equivalent safeguards. |
| Program lead | Includes transport encryption in media practice and retains the evidence. |
5Tooling
The control is delivered by encryption of digital media carrying CUI in transport.
| Objective | Tooling | What it provides |
|---|---|---|
| encrypt | Full-disk or media encryption | CUI on transported media unreadable without the key. |
| alternative | Equivalent physical safeguards | Confidentiality protection where encryption is not used. |
The caveat is that the protection has to cover all digital media carrying CUI in transport, and physical alternatives have to be genuinely equivalent. Encryption is the usual, most reliable mechanism, and partial coverage leaves the unencrypted media exposed. The assessor examines whether transported CUI is protected, so encryption or equivalent safeguards have to be complete.
6Evidence
The satisfied version of 3.8.6 shows CUI on transported media protected.
| Evidence | What it demonstrates |
|---|---|
| Encryption configuration | The objective. CUI on transported digital media encrypted. |
| Transport protection practice | The objective. Confidentiality protected during transport. |
The evidence should show CUI on digital media protected during transport, by encryption or equivalent safeguards, across all such media. The encryption configuration and transport practice are the clearest demonstration of the control.
A lost device should not be a lost secret
Digital media in transport is easily lost or stolen, and unencrypted CUI on it is exposed the moment the device is gone, so this control asks for encryption during transport. Encrypting media that carries CUI off-site is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.6. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.6. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov