DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.2
The CMMC Guide · Physical Protection Family

PE.L2-3.10.2  Protect and Monitor the Facility

Protect and monitor the physical facility and support infrastructure for organizational systems.

Family
Physical ProtectionPE, 6 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FourPer NIST SP 800-171A

1Overview

PE.L2-3.10.2 is the family's second five-point requirement and it adds protection and monitoring of the facility itself. It requires that the physical facility and the support infrastructure for organizational systems be both protected and monitored, so that the building and the utilities the systems depend on are safeguarded and watched. It is a five-point requirement that cannot be deferred on a plan of action.

Systems depend not just on their own security but on the facility around them and the infrastructure that supports them, the power, cooling, cabling, and communications lines that keep them running. This control requires two things applied to both the facility and that support infrastructure: protection, so they are safeguarded against harm, and monitoring, so problems or intrusions are detected. Protecting the facility without monitoring it leaves incidents unseen; monitoring without protection leaves the facility vulnerable. Its five-point weight reflects that the facility and its infrastructure underpin everything the systems do.

The requirement · NIST SP 800-171 Rev 2, 3.10.2

Protect and monitor the physical facility and support infrastructure for organizational systems.

The requirement pairs protection and monitoring across two subjects: the physical facility where systems reside, and the support infrastructure they depend on. Protection means safeguards such as secured entry and environmental controls; monitoring means the facility and infrastructure are watched, through surveillance, alarms, or oversight, so that intrusions or failures are noticed. The four assessment objectives correspond to protecting and monitoring each of the facility and the support infrastructure.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.10.2 into four objectives: protect and monitor the facility, and protect and monitor the support infrastructure.

[a]

The physical facility where organizational systems reside is protected. The building housing systems is safeguarded.

MeetsThe facility housing systems is protected with physical safeguards.
FailsThe facility has no meaningful physical protection.
[b]

The support infrastructure for organizational systems is protected. Power, cabling, and utilities are safeguarded.

MeetsThe support infrastructure, such as power and cabling, is protected.
FailsSupport infrastructure is exposed and unprotected.
[c]

The physical facility where organizational systems reside is monitored. The building is watched for problems and intrusions.

MeetsThe facility is monitored, so intrusions or problems are detected.
FailsThe facility is not monitored, so incidents go unseen.
[d]

The support infrastructure for organizational systems is monitored. The utilities the systems depend on are watched.

MeetsThe support infrastructure is monitored for failures or tampering.
FailsSupport infrastructure is unmonitored, so failures are noticed late.

The four objectives pair protection and monitoring across facility and infrastructure. The common gap is at objectives [c] and [d], monitoring, where the facility is protected but not actually watched, so an intrusion or failure is discovered only after the fact. The assessor looks for both protection and monitoring across both subjects.

3Failure Patterns

The failures are about facilities or infrastructure that are protected but not watched, or watched but not protected.

Protection without monitoring

A secured facility with no surveillance or oversight means intrusions and failures go unseen until damage is done. Monitoring the facility completes the protection.

Support infrastructure overlooked

Focusing on the systems while leaving power, cabling, and utilities exposed leaves the infrastructure they depend on vulnerable. Protecting and monitoring the support infrastructure is required alongside the facility.

Monitoring not acted on

Monitoring that produces alerts no one reviews is monitoring in name only. The facility and infrastructure have to be genuinely watched.

The common root
This control fails when the facility is treated as a static box rather than something to watch. Protection keeps threats out, but without monitoring, an intrusion or an infrastructure failure is discovered only by its consequences. Pairing protection with monitoring is what makes the facility both secured and observed.

4Ownership

This is a facilities-owned control with security oversight.

RoleResponsibility for this control
Facilities and securityProtects and monitors the facility and support infrastructure. Owns the physical protection and monitoring evidence.
IT and system administratorIdentifies the support infrastructure the systems depend on.
Security or compliance leadConfirms both protection and monitoring cover the facility and infrastructure.
See also: This control builds on the access limits of PE.L2-3.10.1 and works with the physical access logging of PE.L2-3.10.4.

5Tooling

The control is delivered by physical safeguards and monitoring of the facility and infrastructure.

ObjectivesToolingWhat it provides
[a], [b]Secured entry, environmental and infrastructure safeguardsProtection of the facility and support infrastructure.
[c], [d]Surveillance, alarms, environmental monitoringMonitoring of the facility and support infrastructure.

The caveat is that monitoring has to be real and acted on, and cover the infrastructure as well as the building. Cameras no one watches and alerts no one reviews do not satisfy monitoring, and infrastructure left out leaves a gap. The assessor examines protection and monitoring across both subjects, so all four objectives have to hold.

6Evidence

The satisfied version of 3.10.2 shows the facility and infrastructure both protected and monitored.

EvidenceWhat it demonstrates
Physical protection measuresObjectives [a], [b]. Facility and infrastructure protected.
Monitoring recordsObjectives [c], [d]. Facility and infrastructure monitored.

The evidence should show the physical facility and support infrastructure both protected and monitored. The protection measures together with the monitoring records are the clearest demonstration, and because this control cannot sit on a plan of action, both have to be real at the time of assessment.

A secured facility still has to be a watched one

The facility and the infrastructure the systems depend on underpin everything, and this five-point control asks that both be protected and monitored so intrusions and failures are seen. Pairing physical safeguards with real monitoring is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.2[a] through 3.10.2[d]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing PE.L2-3.10.2 among the five-point basic security requirements. ecfr.gov
← Previous in Physical Protection
PE.L2-3.10.1 · Limit Physical Access
Next in Physical Protection →
PE.L2-3.10.3 · Escort and Monitor Visitors
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.2 · Edition 2026.1 · Last reviewed July 12, 2026