DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.4
The CMMC Guide · Physical Protection Family

PE.L2-3.10.4  Physical Access Logs

Maintain audit logs of physical access.

Family
Physical ProtectionPE, 6 requirements
Point Value
1Lower weight, but a named exclusion
POA&M Eligible
NoNamed exclusion, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

PE.L2-3.10.4 creates the record of who came and went. It requires that audit logs of physical access be maintained, so that physical entries to the facility are recorded and can be reviewed after the fact. It is a one-point requirement, but it is one of the named exclusions that cannot be placed on a plan of action, so it has to be met at assessment.

Limiting and monitoring physical access controls entry in the moment; logging it creates the record that supports investigation later. This control requires that audit logs of physical access be maintained, so that who entered, and when, is captured. Those logs are what allow the organization to reconstruct physical access during an investigation, confirm that the access limits held, or spot a pattern of concern. Though it carries a single point, it is named in the regulation as a requirement that cannot be deferred, and its single assessment objective is that the physical access logs are maintained.

The requirement · NIST SP 800-171 Rev 2, 3.10.4

Maintain audit logs of physical access.

The requirement is to maintain audit logs of physical access. In practice these are the records of entry to the facility and controlled areas, whether captured by an electronic access system, a visitor log, or another record, kept over time so they are available for review. The point is that physical access leaves a durable, reviewable trail rather than passing without record.

2The Assessment Objective

NIST SP 800-171A frames 3.10.4 as a single objective: maintain audit logs of physical access.

Audit logs of physical access are maintained. Physical entries are recorded and kept.

MeetsAudit logs of physical access are maintained and available for review.
FailsPhysical access is not logged, so there is no record of who entered.

The single objective is maintaining the physical access logs. The common failure is physical access controlled but not recorded, or recorded and then not retained. The assessor looks for physical access logs that are maintained and available.

3Failure Patterns

The failures are about physical access that leaves no durable record.

Access not logged

Where physical entry is controlled but not recorded, there is no trail to review after an incident. Maintaining access logs captures who entered and when.

Logs not retained

Access records that are captured but discarded quickly cannot support later investigation. The logs have to be maintained over time.

Partial coverage

Logging entry to some controlled areas but not others leaves gaps in the record. Physical access logging has to cover the controlled access points.

The common root
This control fails when physical access is controlled but not recorded. Entry controls act in the moment, while logs preserve the history, and without them an investigation has no way to reconstruct who was physically present. Maintaining the access logs is what creates that record.

4Ownership

This is a facilities and security-owned control.

RoleResponsibility for this control
Facilities and securityMaintains the physical access logs, whether electronic or manual. Owns the access log evidence.
Security or compliance leadConfirms logs are maintained across controlled access points and retained.
Program leadSets retention for physical access logs and includes them in review.
See also: This control records access limited under PE.L2-3.10.1 and parallels, in the physical domain, the audit logging of the audit and accountability family.

5Tooling

The control is delivered by physical access logging, electronic or manual, with retention.

ObjectiveToolingWhat it provides
captureElectronic access system, visitor and entry logsRecords of physical entry.
retainLog retentionPhysical access records kept over time for review.

The caveat is that the logs have to be both captured and retained, across the controlled access points. Because this control is a named exclusion, it cannot be deferred, so the logging has to be a real, maintained practice at assessment. The assessor examines whether physical access logs are maintained, so capture and retention both have to hold.

6Evidence

The satisfied version of 3.10.4 shows maintained physical access logs.

EvidenceWhat it demonstrates
Physical access logsThe objective. Physical entries are recorded.
Log retention practiceThe objective. Logs are maintained over time.

The evidence should show audit logs of physical access maintained and retained across controlled access points. The physical access logs and their retention are the clearest demonstration, and because this control is a named exclusion that cannot sit on a plan of action, the practice has to be real at the time of assessment.

Controlling access is not the same as recording it

Entry controls act in the moment, but only maintained logs let you reconstruct who was physically present, so this control asks for physical access audit logs, and as a named exclusion it cannot be deferred. Building maintained, retained physical access logging is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.4. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.10.4. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, which names PE.L2-3.10.4 among the requirements that may not be placed on a plan of action. ecfr.gov
← Previous in Physical Protection
PE.L2-3.10.3 · Escort and Monitor Visitors
Next in Physical Protection →
PE.L2-3.10.5 · Manage Physical Access Devices
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.4 · Edition 2026.1 · Last reviewed July 12, 2026