DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.1
The CMMC Guide · Physical Protection Family

PE.L2-3.10.1  Limit Physical Access

Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

Family
Physical ProtectionPE, 6 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FourPer NIST SP 800-171A

1Overview

PE.L2-3.10.1 opens the Physical Protection family with the core requirement to limit physical access. It requires that physical access to organizational systems, equipment, and their operating environments be limited to authorized individuals, so that the people who can physically reach the systems are the people who are supposed to. It is a five-point requirement that cannot be deferred on a plan of action.

Digital access controls mean little if anyone can walk up to a server and take it, unplug it, or connect to it directly. Physical access is its own attack surface, and this control closes it by limiting who can physically reach the systems, the equipment they run on, and the environments they sit in, to authorized individuals. That requires first knowing who is authorized, then enforcing the limit across systems, equipment, and operating environments alike. Its five-point weight reflects that physical access can bypass many of the technical protections layered above it.

The requirement · NIST SP 800-171 Rev 2, 3.10.1

Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

The requirement covers three things, all limited to authorized individuals: the systems themselves, the equipment they depend on, and the operating environments, the rooms and spaces where they reside. Limiting access begins with identifying who is authorized, then applying physical controls such as locks, access cards, or secured areas so that only those individuals can reach each. The four assessment objectives correspond to identifying authorized individuals and limiting access across systems, equipment, and environments.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.10.1 into four objectives: identify authorized individuals, then limit physical access to systems, equipment, and operating environments.

[a]

Authorized individuals allowed physical access are identified. The organization knows who may have physical access.

MeetsThe individuals authorized for physical access are identified.
FailsThere is no defined set of individuals authorized for physical access.
[b]

Physical access to organizational systems is limited to authorized individuals. Only authorized people can reach the systems.

MeetsPhysical access to systems is limited to the authorized individuals.
FailsAnyone can physically reach the systems.
[c]

Physical access to equipment is limited to authorized individuals. Only authorized people can reach the equipment.

MeetsPhysical access to equipment is limited to the authorized individuals.
FailsEquipment is physically accessible to anyone.
[d]

Physical access to operating environments is limited to authorized individuals. Only authorized people can enter the environments.

MeetsPhysical access to operating environments is limited to the authorized individuals.
FailsThe rooms and spaces housing systems are open to anyone.

The four objectives are identification plus the three-way limit. The common gap is at objective [a], where access is restricted in practice but the authorized set is never actually defined, so the limit has no clear basis. The assessor looks for a defined authorized set and enforced limits across systems, equipment, and environments.

3Failure Patterns

The failures are about physical access that is not actually limited.

Authorized set never defined

Without identifying who is authorized for physical access, the limit rests on nothing definite. Defining the authorized individuals is the basis for limiting access to them.

Systems in open areas

Servers or network equipment in unlocked, open areas can be reached by anyone in the building. Securing the environment limits access to authorized individuals.

Environment secured but equipment exposed

Limiting access to a room while leaving equipment reachable elsewhere, such as network gear in a shared closet, leaves a gap. The limit has to cover systems, equipment, and environments.

The common root
This control fails when physical access is treated as less important than digital. A locked account means little if the machine itself sits where anyone can reach it, and physical access can undo the technical protections above it. Limiting who can physically reach the systems is what keeps that surface closed.

4Ownership

This is a facilities and IT-owned control, coordinated so physical limits match the authorized set.

RoleResponsibility for this control
Facilities and securityImplements physical controls limiting access to systems, equipment, and environments. Owns the physical access evidence.
IT and system administratorIdentifies where systems and equipment reside and who needs physical access.
Security or compliance leadDefines the authorized individuals and confirms access is limited across all three.
See also: This control is the foundation of the Physical Protection family, working with the facility monitoring of PE.L2-3.10.2 and the access device management of PE.L2-3.10.5.

5Tooling

The control is largely physical: identifying authorized individuals and applying access controls to spaces and equipment.

ObjectivesToolingWhat it provides
[a]Authorized access listA defined set of individuals allowed physical access.
[b], [c]Locks, secured racks and cabinetsLimited physical access to systems and equipment.
[d]Access cards, secured roomsLimited physical access to operating environments.

The caveat is that the limit has to rest on a defined authorized set and cover all three subjects. Physical controls without a clear authorized list have no basis, and controls that secure the room but not the equipment leave a gap. The assessor examines identification and the limit across systems, equipment, and environments, so all four objectives have to hold.

6Evidence

The satisfied version of 3.10.1 shows a defined authorized set and physical limits across all three subjects.

EvidenceWhat it demonstrates
Authorized access listObjective [a]. Who is authorized for physical access.
Physical access controlsObjectives [b], [c], [d]. Access limited across systems, equipment, and environments.

The evidence should show a defined authorized set and enforced physical limits on systems, equipment, and operating environments. The authorized access list together with the physical controls is the clearest demonstration, and because this control cannot sit on a plan of action, the limits have to be real at the time of assessment.

A locked account means little if the machine is not

Physical access can bypass the technical protections above it, so this five-point control asks that access to systems, equipment, and environments be limited to authorized individuals. Defining the authorized set and securing the spaces and equipment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.1[a] through 3.10.1[d]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing PE.L2-3.10.1 among the five-point basic security requirements. ecfr.gov
← Previous: Personnel Security
PS.L2-3.9.2 · Protect CUI During Personnel Actions
Next in Physical Protection →
PE.L2-3.10.2 · Protect and Monitor the Facility
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.1 · Edition 2026.1 · Last reviewed July 12, 2026