DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.16
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.16  Protect CUI at Rest

Protect the confidentiality of CUI at rest.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

SC.L2-3.13.16 closes the System and Communications Protection family by protecting CUI where it sits. It requires that the confidentiality of CUI at rest be protected, so that stored CUI, on servers, workstations, drives, and backups, is safeguarded against unauthorized disclosure. It is a one-point requirement and may be deferred on a plan of action.

Much of the family protects CUI in motion, at boundaries and in transit; this control protects it at rest. Stored CUI can be disclosed if a drive is stolen, a backup is lost, or storage is accessed without authorization, so its confidentiality has to be protected where it resides. This is commonly achieved through encryption of data at rest, though other protections may apply, so that stored CUI is not readable by those who should not have it. The single assessment objective is that the confidentiality of CUI at rest is protected.

The requirement · NIST SP 800-171 Rev 2, 3.13.16

Protect the confidentiality of CUI at rest.

The requirement is to protect the confidentiality of CUI at rest, wherever it is stored. In practice this most often means encrypting CUI on the media that hold it, servers, workstations, portable drives, and backups, so that access to the storage does not yield readable CUI. The single assessment objective is that this confidentiality is protected. Where encryption is used, its strength is governed by the FIPS-validation requirement.

2The Assessment Objective

NIST SP 800-171A frames 3.13.16 as a single objective: protect the confidentiality of CUI at rest.

The confidentiality of CUI at rest is protected. Stored CUI is safeguarded against unauthorized disclosure.

MeetsCUI at rest is protected, typically by encryption of the storage.
FailsStored CUI is readable by anyone who accesses the storage.

The single objective is protecting CUI at rest. The common gap is CUI stored on some media without protection, portable drives, backups, or workstations, even where servers are protected. The assessor looks for the confidentiality of CUI protected across the places it is stored.

3Failure Patterns

The failures are about stored CUI left readable.

Unencrypted storage

CUI stored without encryption is disclosed if the media is stolen or accessed. Encrypting the storage protects its confidentiality.

Backups and portable media overlooked

Protecting CUI on primary servers while leaving backups and portable drives unencrypted leaves those copies exposed. Protection has to cover all the places CUI is stored.

Non-validated encryption

Encrypting CUI at rest with cryptography that is not FIPS-validated does not fully satisfy the accompanying validation requirement. The encryption should be validated.

The common root
This control fails when protection follows CUI in motion but not at rest. Data crossing the network draws attention, while data sitting on a drive or backup is easy to forget, yet a stolen drive or lost backup discloses CUI just as surely as an intercepted transmission. Protecting CUI at rest, across all the media that hold it, closes that gap.

4Ownership

This is an IT and security-owned technical control.

RoleResponsibility for this control
IT and securityProtects CUI at rest, typically by encrypting storage. Owns the encryption evidence.
System administratorApplies storage encryption across servers, workstations, and media.
Security or compliance leadConfirms CUI at rest is protected across all storage locations.
See also: This control complements the transit protection of SC.L2-3.13.8, is governed by the FIPS-validation requirement of SC.L2-3.13.11, and connects to the media protection family.

5Tooling

The control is delivered by encryption of data at rest across storage.

ObjectiveToolingWhat it provides
servers and workstationsFull-disk and file encryptionProtected CUI on primary storage.
media and backupsEncrypted portable media and backupsProtected CUI on secondary storage.

The caveat is that protection has to cover all the places CUI is stored, and the encryption should be FIPS-validated. Encrypting servers while leaving backups or portable drives in the clear leaves those copies exposed. The assessor examines whether CUI at rest is protected, so coverage across storage has to hold.

6Evidence

The satisfied version of 3.13.16 shows CUI protected across storage.

EvidenceWhat it demonstrates
Storage encryption configurationThe objective. CUI at rest protected on servers and workstations.
Media and backup encryptionThe objective. CUI protected on portable media and backups.

The evidence should show the confidentiality of CUI at rest protected across the media that hold it. The storage encryption configuration together with media and backup encryption is the clearest demonstration of the control.

A stolen drive discloses CUI as surely as an intercepted message

Stored CUI is easy to overlook but just as exposed if the media is lost or accessed, so this control asks that its confidentiality at rest be protected across all storage. Encrypting CUI where it sits is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.16. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.16. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.15 · Protect Communications Session Authenticity
Next: System and Information Integrity →
SI.L2-3.14.1 · Identify, Report, and Correct Flaws
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.16 · Edition 2026.1 · Last reviewed July 12, 2026