DKDavid Koran& Associates
Home The CMMC Guide Part III · Physical Protection PE.L2-3.10.6
The CMMC Guide · Physical Protection Family

PE.L2-3.10.6  Safeguard CUI at Alternate Work Sites

Enforce safeguarding measures for CUI at alternate work sites.

Family
Physical ProtectionPE, 6 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

PE.L2-3.10.6 closes the Physical Protection family by extending safeguards beyond the facility. It requires that safeguarding measures for CUI be enforced at alternate work sites, so that CUI handled away from the main facility, at home offices or remote locations, is protected there too. It is a one-point requirement and may be deferred on a plan of action.

Work no longer happens only at the primary facility. Employees handle CUI at home, at satellite offices, and at other alternate work sites, all beyond the physical protections built into the main location. This control requires that safeguarding measures for CUI be both defined for those alternate sites and enforced there, so that CUI does not lose its protection simply because it left the building. The two assessment objectives are the definition of the safeguards and their enforcement.

The requirement · NIST SP 800-171 Rev 2, 3.10.6

Enforce safeguarding measures for CUI at alternate work sites.

The requirement is to enforce safeguarding measures for CUI at alternate work sites, and the assessment objectives split this into defining the measures and enforcing them. Defining the safeguards means deciding what protection CUI requires at alternate sites, such as securing devices and documents and controlling access in the home or remote setting. Enforcing them means those measures are actually applied where the work happens. The point is that CUI carries its protections to wherever it is handled.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.10.6 into two objectives: define the safeguards for alternate sites and enforce them.

[a]

Safeguarding measures for CUI are defined for alternate work sites. The protection CUI requires away from the facility is specified.

MeetsSafeguarding measures for CUI at alternate work sites are defined.
FailsNo safeguards are defined for CUI handled away from the facility.
[b]

Safeguarding measures for CUI are enforced for alternate work sites. The defined protections are actually applied.

MeetsThe defined safeguards are enforced at alternate work sites.
FailsSafeguards exist on paper but are not applied where remote work happens.

The two objectives are define and enforce. The common gap is at objective [b], where safeguards are written into policy but not actually applied at home offices and remote sites. The assessor looks for both defined measures and their enforcement at alternate work sites.

3Failure Patterns

The failures are about CUI that loses its protection away from the facility.

No safeguards defined for remote work

Where the protection CUI requires at alternate sites is never defined, remote handling is ungoverned. Defining the safeguards is the basis for enforcing them.

Policy not enforced at home offices

Safeguards written into policy but not applied at home or remote sites leave CUI unprotected where the work actually happens. Enforcement makes the definition real.

Alternate sites not considered

Treating protection as a facility-only concern overlooks the CUI handled elsewhere. The safeguards have to extend to wherever CUI is worked on.

The common root
This control fails when protection is treated as tied to the building. CUI handled at an alternate site is the same controlled information, but the physical protections of the main facility do not follow it automatically, so unless safeguards are defined and enforced there, remote work becomes a gap. Extending the protections to the work site closes it.

4Ownership

This is a security and operations-owned control that involves remote workers.

RoleResponsibility for this control
Security or compliance leadDefines the safeguarding measures for CUI at alternate work sites. Owns the remote work safeguards.
Remote and alternate-site workersEnforce the defined safeguards where they handle CUI.
Program leadConfirms the safeguards are enforced, not just defined, and retains the policy.
See also: This control extends the physical protection of PE.L2-3.10.1 to remote settings and works with the media transport controls of MP.L2-3.8.5.

5Tooling

The control is delivered by defined remote-work safeguards and their enforcement.

ObjectivesToolingWhat it provides
[a]Alternate work site safeguarding policyDefined protection for CUI away from the facility.
[b]Enforcement at remote sites, worker practiceApplication of the safeguards where the work happens.

The caveat is that the safeguards have to be enforced, not just defined. A remote-work policy that no one applies at home offices leaves the CUI unprotected. The assessor examines both the definition and the enforcement at alternate sites, so both objectives have to hold.

6Evidence

The satisfied version of 3.10.6 shows defined and enforced safeguards at alternate sites.

EvidenceWhat it demonstrates
Alternate work site policyObjective [a]. Safeguards defined for remote work.
Enforcement practiceObjective [b]. Safeguards applied where CUI is handled.

The evidence should show safeguarding measures for CUI defined for alternate work sites and enforced there. The alternate work site policy and the enforcement practice are the clearest demonstration of the control.

CUI should carry its protections wherever it goes

Work happens beyond the main facility, and CUI handled at home or remote sites is the same controlled information, so this control asks that safeguards be defined and enforced there. Extending real protection to alternate work sites is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.6[a] and 3.10.6[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Physical Protection
PE.L2-3.10.5 · Manage Physical Access Devices
Next: Risk Assessment →
RA.L2-3.11.1 · Assess Risk
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PE.L2-3.10.6 · Edition 2026.1 · Last reviewed July 12, 2026