DKDavid Koran& Associates
Home The CMMC Guide Part III · Media Protection MP.L2-3.8.9
The CMMC Guide · Media Protection Family

MP.L2-3.8.9  Protect Backup CUI

Protect the confidentiality of backup CUI at storage locations.

Family
Media ProtectionMP, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MP.L2-3.8.9 closes the Media Protection family by protecting backups. It requires that the organization protect the confidentiality of backup CUI at storage locations, so that the copies of CUI kept for recovery are safeguarded as carefully as the originals. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

Backups are copies of the organization's data, made so that it can be recovered after loss, and backups of CUI are therefore copies of CUI. If those backups are stored without protection, they become an overlooked route to the very data the program protects: a backup drive in an unsecured location, or backup files anyone can read, exposes CUI just as surely as the primary copy would. This control requires that the confidentiality of backup CUI be protected at its storage locations, extending the same care given to primary data to the backups.

The requirement · NIST SP 800-171 Rev 2, 3.8.9

Protect the confidentiality of backup CUI at storage locations.

The requirement is to protect the confidentiality of backup CUI wherever it is stored. In practice this means the backups are encrypted, access-controlled, or physically secured at their storage locations, whether those are on-site, off-site, or with a backup service. The single assessment objective is that this confidentiality protection is in place for backup CUI at its storage locations, so the recovery copies are not a weaker link than the originals.

2The Assessment Objective

NIST SP 800-171A frames 3.8.9 as a single objective: protect the confidentiality of backup CUI at storage locations.

The confidentiality of backup CUI is protected at storage locations. Backups of CUI are safeguarded where they are stored.

MeetsBackup CUI is encrypted or otherwise protected at its storage locations.
FailsBackups of CUI are stored unprotected, readable by anyone with access to them.

The single objective is protecting backup CUI confidentiality at storage. The common failure is unprotected backups treated as an afterthought. The assessor looks for confidentiality protection of backup CUI wherever it is stored.

3Failure Patterns

The failures are about unprotected backups.

Unencrypted backups

Backup CUI stored without encryption is readable by anyone who reaches the backup media or files. Encrypting the backups protects their confidentiality at rest.

Backups in unsecured locations

Backup media kept in an unsecured location, on-site or off, is exposed to whoever can reach it. Securing the storage location protects the backups.

Backup service not verified

Relying on a backup service without confirming it protects the CUI leaves the confidentiality unverified. The protection has to hold wherever the backups are stored, including with a provider.

The common root
This control fails when backups are forgotten as a copy of the data. Attention goes to the primary systems, while the backups, which hold the same CUI, are stored with less care and become an overlooked path to it. Protecting backup confidentiality closes that path.

4Ownership

This is an IT-owned control tied to the backup process.

RoleResponsibility for this control
IT and system administratorProtects the confidentiality of backup CUI at its storage locations, through encryption and secured storage. Owns the technical evidence.
Security or compliance leadConfirms backups of CUI are protected wherever stored, including with providers.
Program leadIncludes backup protection in the backup process and retains the evidence.
See also: This control extends the media protection of MP.L2-3.8.1 to backups and draws on the cryptographic protections of the system and communications protection family.

5Tooling

The control is delivered by encryption and secured storage of backup CUI.

ObjectiveToolingWhat it provides
encryptBackup encryptionConfidentiality of backup CUI at rest.
secureSecured storage locations, access controlProtection of backups wherever they are kept.

The caveat is that the protection has to cover all backup storage locations, including off-site and provider-held backups. Backups protected in one location but not another leave the unprotected copies exposed. The assessor examines whether backup CUI confidentiality is protected at its storage locations, so the protection has to be complete.

6Evidence

The satisfied version of 3.8.9 shows backup CUI protected at storage.

EvidenceWhat it demonstrates
Backup encryption configurationThe objective. Backup CUI protected at rest.
Backup storage protectionThe objective. Storage locations secured.

The evidence should show the confidentiality of backup CUI protected at all its storage locations, through encryption and secured storage. The backup encryption configuration and storage protection are the clearest demonstration of the control.

A backup of CUI is still CUI

Backups hold the same controlled data as the primary systems, and if they are stored without protection they become an overlooked route to it, so this control asks that their confidentiality be protected at storage. Protecting backup CUI wherever it is kept is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.8.9. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.8.9. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Media Protection
MP.L2-3.8.8 · Prohibit Unowned Portable Storage
Next: Personnel Security →
PS.L2-3.9.1 · Screen Personnel
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MP.L2-3.8.9 · Edition 2026.1 · Last reviewed July 12, 2026