DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.6
The CMMC Guide · Media Protection Family

MP.L2-3.8.6  Encrypt CUI on Media in Transport

Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.

Family
Media ProtectionMP, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MP.L2-3.8.6 protects digital CUI while media moves. It requires cryptographic mechanisms to protect the confidentiality of CUI on digital media during transport, unless the media is otherwise protected by alternative physical safeguards, so that data on a device in transit is unreadable if the device is lost or taken. It is a one-point requirement and may be deferred on a plan of action.

A digital device in transport can be lost or stolen, and if the CUI on it is not protected, whoever ends up with the device has the data. This control requires that the confidentiality of CUI on digital media be protected during transport, most commonly through encryption, so that a lost or stolen device yields no readable CUI. The requirement allows alternative physical safeguards where those provide equivalent protection, but encryption is the usual and most practical mechanism.

The requirement · NIST SP 800-171 Rev 2, 3.8.6

Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.

The requirement is to protect the confidentiality of CUI on digital media during transport, with cryptographic mechanisms as the default and alternative physical safeguards as an option where they provide equivalent protection. Encryption means the data on the device is unreadable without the key, so losing the device does not expose the CUI. The single assessment objective is that this confidentiality protection is in place during transport.

2The Assessment Objective

NIST SP 800-171A frames 3.8.6 as a single objective: protect the confidentiality of CUI on digital media during transport.

The confidentiality of CUI stored on digital media during transport is protected using cryptographic mechanisms or alternative physical safeguards. CUI on media in transit is unreadable if the media is lost.

MeetsCUI on digital media is encrypted during transport, so a lost device yields no readable CUI.
FailsCUI on media in transport is unencrypted and unprotected.

The single objective is confidentiality protection during transport. The common failure is an unencrypted device carrying CUI off-site, so a loss exposes the data. The assessor looks for encryption or equivalent physical protection of CUI on digital media in transport.

3Failure Patterns

The failures are about unprotected CUI on media in transit.

Unencrypted devices in transport

A laptop or drive carrying unencrypted CUI off-site exposes the data if the device is lost or stolen. Encrypting the media protects the confidentiality regardless of the device's fate.

Encryption not applied to all transported media

Where some transported media is encrypted and some is not, the unencrypted media remains a risk. The protection has to cover all digital media carrying CUI in transport.

Weak or absent physical alternative

Relying on physical safeguards that do not actually provide equivalent protection leaves CUI exposed. Where encryption is not used, the physical safeguards have to genuinely protect the confidentiality.

The common root
This control fails when a device leaves with CUI unprotected. Devices in transport are easily lost or stolen, and unencrypted CUI on them is exposed the moment the device is out of hand, so encryption is what keeps a lost device from becoming a data breach.

4Ownership

This is an IT-owned technical control tied to encryption of transported media.

RoleResponsibility for this control
IT and system administratorImplements encryption on digital media carrying CUI in transport. Owns the technical evidence.
Security or compliance leadConfirms confidentiality protection covers all transported media, by encryption or equivalent safeguards.
Program leadIncludes transport encryption in media practice and retains the evidence.
See also: This control complements the transport accountability of MP.L2-3.8.5 and draws on the cryptographic protections of the system and communications protection family.

5Tooling

The control is delivered by encryption of digital media carrying CUI in transport.

ObjectiveToolingWhat it provides
encryptFull-disk or media encryptionCUI on transported media unreadable without the key.
alternativeEquivalent physical safeguardsConfidentiality protection where encryption is not used.

The caveat is that the protection has to cover all digital media carrying CUI in transport, and physical alternatives have to be genuinely equivalent. Encryption is the usual, most reliable mechanism, and partial coverage leaves the unencrypted media exposed. The assessor examines whether transported CUI is protected, so encryption or equivalent safeguards have to be complete.

6Evidence

The satisfied version of 3.8.6 shows CUI on transported media protected.

EvidenceWhat it demonstrates
Encryption configurationThe objective. CUI on transported digital media encrypted.
Transport protection practiceThe objective. Confidentiality protected during transport.

The evidence should show CUI on digital media protected during transport, by encryption or equivalent safeguards, across all such media. The encryption configuration and transport practice are the clearest demonstration of the control.

A lost device should not be a lost secret

Digital media in transport is easily lost or stolen, and unencrypted CUI on it is exposed the moment the device is gone, so this control asks for encryption during transport. Encrypting media that carries CUI off-site is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.6. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.5 · Control and Track Media in Transport
Next in Media Protection →
MP.L2-3.8.7 · Control Removable Media
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.6 · Edition 2026.1 · Last reviewed July 12, 2026