1Overview
PE.L2-3.10.1 opens the Physical Protection family with the core requirement to limit physical access. It requires that physical access to organizational systems, equipment, and their operating environments be limited to authorized individuals, so that the people who can physically reach the systems are the people who are supposed to. It is a five-point requirement that cannot be deferred on a plan of action.
Digital access controls mean little if anyone can walk up to a server and take it, unplug it, or connect to it directly. Physical access is its own attack surface, and this control closes it by limiting who can physically reach the systems, the equipment they run on, and the environments they sit in, to authorized individuals. That requires first knowing who is authorized, then enforcing the limit across systems, equipment, and operating environments alike. Its five-point weight reflects that physical access can bypass many of the technical protections layered above it.
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
The requirement covers three things, all limited to authorized individuals: the systems themselves, the equipment they depend on, and the operating environments, the rooms and spaces where they reside. Limiting access begins with identifying who is authorized, then applying physical controls such as locks, access cards, or secured areas so that only those individuals can reach each. The four assessment objectives correspond to identifying authorized individuals and limiting access across systems, equipment, and environments.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.10.1 into four objectives: identify authorized individuals, then limit physical access to systems, equipment, and operating environments.
Authorized individuals allowed physical access are identified. The organization knows who may have physical access.
Physical access to organizational systems is limited to authorized individuals. Only authorized people can reach the systems.
Physical access to equipment is limited to authorized individuals. Only authorized people can reach the equipment.
Physical access to operating environments is limited to authorized individuals. Only authorized people can enter the environments.
The four objectives are identification plus the three-way limit. The common gap is at objective [a], where access is restricted in practice but the authorized set is never actually defined, so the limit has no clear basis. The assessor looks for a defined authorized set and enforced limits across systems, equipment, and environments.
3Failure Patterns
The failures are about physical access that is not actually limited.
Authorized set never defined
Without identifying who is authorized for physical access, the limit rests on nothing definite. Defining the authorized individuals is the basis for limiting access to them.
Systems in open areas
Servers or network equipment in unlocked, open areas can be reached by anyone in the building. Securing the environment limits access to authorized individuals.
Environment secured but equipment exposed
Limiting access to a room while leaving equipment reachable elsewhere, such as network gear in a shared closet, leaves a gap. The limit has to cover systems, equipment, and environments.
4Ownership
This is a facilities and IT-owned control, coordinated so physical limits match the authorized set.
| Role | Responsibility for this control |
|---|---|
| Facilities and security | Implements physical controls limiting access to systems, equipment, and environments. Owns the physical access evidence. |
| IT and system administrator | Identifies where systems and equipment reside and who needs physical access. |
| Security or compliance lead | Defines the authorized individuals and confirms access is limited across all three. |
5Tooling
The control is largely physical: identifying authorized individuals and applying access controls to spaces and equipment.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Authorized access list | A defined set of individuals allowed physical access. |
| [b], [c] | Locks, secured racks and cabinets | Limited physical access to systems and equipment. |
| [d] | Access cards, secured rooms | Limited physical access to operating environments. |
The caveat is that the limit has to rest on a defined authorized set and cover all three subjects. Physical controls without a clear authorized list have no basis, and controls that secure the room but not the equipment leave a gap. The assessor examines identification and the limit across systems, equipment, and environments, so all four objectives have to hold.
6Evidence
The satisfied version of 3.10.1 shows a defined authorized set and physical limits across all three subjects.
| Evidence | What it demonstrates |
|---|---|
| Authorized access list | Objective [a]. Who is authorized for physical access. |
| Physical access controls | Objectives [b], [c], [d]. Access limited across systems, equipment, and environments. |
The evidence should show a defined authorized set and enforced physical limits on systems, equipment, and operating environments. The authorized access list together with the physical controls is the clearest demonstration, and because this control cannot sit on a plan of action, the limits have to be real at the time of assessment.
A locked account means little if the machine is not
Physical access can bypass the technical protections above it, so this five-point control asks that access to systems, equipment, and environments be limited to authorized individuals. Defining the authorized set and securing the spaces and equipment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.1[a] through 3.10.1[d]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing PE.L2-3.10.1 among the five-point basic security requirements. ecfr.gov