DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.3
The CMMC Guide · Physical Protection Family

PE.L2-3.10.3  Escort and Monitor Visitors

Escort visitors and monitor visitor activity.

Family
Physical ProtectionPE, 6 requirements
Point Value
1Lower weight, but a named exclusion
POA&M Eligible
NoNamed exclusion, cannot be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

PE.L2-3.10.3 governs how visitors are handled. It requires that visitors be escorted and their activity monitored, so that people who are not authorized for unaccompanied access do not move through the facility unwatched. It is a one-point requirement, but it is one of the named exclusions that cannot be placed on a plan of action, so it has to be met at assessment.

A visitor is, by definition, someone without authorized unaccompanied access, and letting one move freely through a facility where systems and CUI reside undoes the physical access limits around them. This control requires two things: escorting visitors, so an authorized person accompanies them, and monitoring their activity, so what they do is observed. Though it carries a single point, it is named in the regulation as a requirement that cannot be deferred, reflecting that unescorted visitors are a direct physical access gap. Its two assessment objectives are the escort and the monitoring.

The requirement · NIST SP 800-171 Rev 2, 3.10.3

Escort visitors and monitor visitor activity.

The requirement is short and has two parts: visitors are escorted, and visitor activity is monitored. Escorting means an authorized individual accompanies the visitor throughout their time in the facility; monitoring means the visitor's activity is observed, whether by the escort or by other means. Together they ensure a visitor is never both unaccompanied and unwatched in the controlled space.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.10.3 into two objectives: escort visitors and monitor visitor activity.

[a]

Visitors are escorted. An authorized person accompanies visitors.

MeetsVisitors are escorted by an authorized individual throughout their visit.
FailsVisitors move through the facility unaccompanied.
[b]

Visitor activity is monitored. What visitors do is observed.

MeetsVisitor activity is monitored during the visit.
FailsVisitors' activity is unobserved.

The two objectives are the escort and the monitoring. The common failure is a visitor signed in and then left to move about, escorted at the door but not throughout. The assessor looks for both continuous escort and monitored activity.

3Failure Patterns

The failures are about visitors who become unaccompanied or unobserved.

Escort at the door only

Meeting a visitor at reception and then letting them proceed alone leaves them unaccompanied in the controlled space. The escort has to continue throughout the visit.

Activity not monitored

An escort who is present but not attentive, or a visit that is otherwise unobserved, fails the monitoring objective. Visitor activity has to be actually watched.

No visitor process

Without a defined process for receiving and escorting visitors, handling is inconsistent and some visitors go unescorted. A visitor process applies both escort and monitoring uniformly.

The common root
This control fails on the assumption that a signed-in visitor is a controlled one. Signing in records the visit, but it does not escort or monitor; a visitor left to move about is an unauthorized person inside the physical access limits. Escort and monitoring are what keep the visit controlled throughout.

4Ownership

This is an operations and security-owned control that involves everyone who hosts visitors.

RoleResponsibility for this control
Reception and securityReceives visitors and ensures they are escorted and monitored. Owns the visitor process.
All staff hosting visitorsEscort their visitors throughout and monitor their activity.
Security or compliance leadConfirms visitors are escorted and monitored, not just signed in.
See also: This control supports the physical access limits of PE.L2-3.10.1 and parallels the supervision of unauthorized maintainers at MA.L2-3.7.6.

5Tooling

The control is procedural, delivered by a visitor escort and monitoring process.

ObjectivesToolingWhat it provides
[a]Visitor escort processAn authorized escort throughout the visit.
[b]Attentive escort, visitor monitoringObservation of visitor activity.

The caveat is that escort and monitoring have to be continuous and real, not limited to sign-in. Because this control is a named exclusion, it cannot be deferred, so the escort and monitoring have to be a genuine practice at assessment. The assessor examines whether visitors are escorted and monitored throughout, so the process has to hold for the whole visit.

6Evidence

The satisfied version of 3.10.3 shows visitors escorted and monitored throughout.

EvidenceWhat it demonstrates
Visitor escort processObjective [a]. Visitors are escorted throughout.
Visitor monitoring practiceObjective [b]. Visitor activity is monitored.

The evidence should show visitors escorted and their activity monitored throughout their visits. The escort process and monitoring practice are the clearest demonstration, and because this control is a named exclusion that cannot sit on a plan of action, the practice has to be real at the time of assessment.

A signed-in visitor is not a controlled one

A visitor left to move about is an unauthorized person inside your physical access limits, so this control asks that they be escorted and monitored throughout, and as a named exclusion it cannot be deferred. Building a real visitor escort and monitoring practice is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.3[a] and 3.10.3[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, which names PE.L2-3.10.3 among the requirements that may not be placed on a plan of action. ecfr.gov
← Previous in Physical Protection
PE.L2-3.10.2 · Protect and Monitor the Facility
Next in Physical Protection →
PE.L2-3.10.4 · Physical Access Logs
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.3 · Edition 2026.1 · Last reviewed July 12, 2026