DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.5
The CMMC Guide · Physical Protection Family

PE.L2-3.10.5  Manage Physical Access Devices

Control and manage physical access devices.

Family
Physical ProtectionPE, 6 requirements
Point Value
1Lower weight, but a named exclusion
POA&M Eligible
NoNamed exclusion, cannot be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

PE.L2-3.10.5 governs the keys to the building. It requires that physical access devices be identified, controlled, and managed, so that the badges, keys, and other devices that grant physical entry are themselves accounted for and governed. It is a one-point requirement, but it is one of the named exclusions that cannot be placed on a plan of action, so it has to be met at assessment.

Physical access limits depend on the devices that enforce them, the access cards, keys, fobs, and codes that open doors. If those devices are not tracked and governed, the access limits erode: a lost badge that is never deactivated, a key held by a departed employee, or an unaccounted-for fob each becomes an unmanaged path in. This control requires that physical access devices be identified, so the organization knows what exists; controlled, so their issue and use are governed; and managed, so they are maintained, reclaimed, and deactivated over their life. Though it carries a single point, it is named in the regulation as a requirement that cannot be deferred, and its three assessment objectives are identification, control, and management.

The requirement · NIST SP 800-171 Rev 2, 3.10.5

Control and manage physical access devices.

The requirement names control and management of physical access devices, and the assessment objectives add identification as the foundation. Identifying the devices means knowing which badges, keys, and codes exist and grant access; controlling them means governing how they are issued and used; managing them means maintaining them over time, including reclaiming and deactivating devices when access should end. Together these keep the devices that enforce physical access from becoming an unmanaged gap.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.10.5 into three objectives: identify, control, and manage physical access devices.

[a]

Physical access devices are identified. The organization knows which devices grant access.

MeetsPhysical access devices are identified, so the organization knows what exists.
FailsThere is no accounting of the badges, keys, and codes that grant access.
[b]

Physical access devices are controlled. Their issue and use are governed.

MeetsAccess devices are controlled, so issue and use are governed.
FailsAccess devices are issued and used without governance.
[c]

Physical access devices are managed. They are maintained, reclaimed, and deactivated over their life.

MeetsAccess devices are managed, including reclaiming and deactivating them when access should end.
FailsLost or departed-employee devices remain active.

The three objectives are identify, control, and manage. The common gap is at objective [c], management, where devices are issued but never reclaimed or deactivated, so lost badges and departed-employee keys stay live. The assessor looks for all three across the devices that grant physical access.

3Failure Patterns

The failures are about access devices that are unaccounted for or never deactivated.

Devices not tracked

Without knowing which badges, keys, and codes exist, the organization cannot govern them. Identifying the access devices is the basis for controlling and managing them.

Lost devices left active

A lost badge or key that is never deactivated remains a working path in. Managing devices includes deactivating them when they are lost or should no longer grant access.

Departed-employee devices not reclaimed

Access devices held by people who have left continue to open doors if not reclaimed or deactivated. Management ties device status to the person's access needs.

The common root
This control fails when access devices are issued and then forgotten. The badge or key enforces the physical limit, but if it is never reclaimed or deactivated when access should end, the limit it enforced quietly persists in the wrong hands. Identifying, controlling, and managing the devices keeps them tied to actual access needs.

4Ownership

This is a facilities and security-owned control tied to the access device lifecycle.

RoleResponsibility for this control
Facilities and securityIdentifies, controls, and manages physical access devices over their life. Owns the device inventory and records.
Human resourcesNotifies of departures so devices can be reclaimed or deactivated.
Security or compliance leadConfirms devices are identified, controlled, and managed, including deactivation.
See also: This control enforces the access limits of PE.L2-3.10.1 and connects to the personnel-action access removal of PS.L2-3.9.2.

5Tooling

The control is delivered by an access device inventory and a lifecycle process.

ObjectivesToolingWhat it provides
[a]Access device inventoryIdentification of the devices that grant access.
[b]Issue and use governanceControl over how devices are issued and used.
[c]Reclaim and deactivation processManagement of devices over their life.

The caveat is that management, especially deactivation, is where the control is proven. An inventory and issue process without a reliable way to reclaim and deactivate devices leaves live devices in the wrong hands. Because this control is a named exclusion, it cannot be deferred, so all three objectives have to hold at assessment.

6Evidence

The satisfied version of 3.10.5 shows access devices identified, controlled, and managed.

EvidenceWhat it demonstrates
Access device inventoryObjective [a]. Devices are identified.
Issue and governance recordsObjective [b]. Devices are controlled.
Reclaim and deactivation recordsObjective [c]. Devices are managed over their life.

The evidence should show physical access devices identified, their issue and use controlled, and their lifecycle managed including deactivation. The inventory together with the governance and deactivation records is the clearest demonstration, and because this control is a named exclusion that cannot sit on a plan of action, the practice has to be real at the time of assessment.

A badge no one reclaims is a door left open

The devices that enforce physical access have to be tracked and deactivated when access should end, or the limits they enforce persist in the wrong hands, so this control asks that they be identified, controlled, and managed, and as a named exclusion it cannot be deferred. Building an access device lifecycle is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.5[a] through 3.10.5[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, which names PE.L2-3.10.5 among the requirements that may not be placed on a plan of action. ecfr.gov
← Previous in Physical Protection
PE.L2-3.10.4 · Physical Access Logs
Next in Physical Protection →
PE.L2-3.10.6 · Safeguard CUI at Alternate Work Sites
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.5 · Edition 2026.1 · Last reviewed July 12, 2026