DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.8
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.8  Encrypt CUI in Transit

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

SC.L2-3.13.8 protects CUI as it moves across the network. It requires that cryptographic mechanisms be implemented to prevent unauthorized disclosure of CUI during transmission, unless the CUI is otherwise protected by alternative physical safeguards. It is a three-point requirement that cannot be deferred on a plan of action.

CUI in transit crosses network paths where it can be intercepted, and once intercepted, unencrypted CUI is disclosed. This control requires protecting CUI during transmission, and it offers two acceptable means: cryptographic mechanisms, encrypting the data in transit, or alternative physical safeguards, such as a protected distribution system, where the physical path itself prevents interception. The organization identifies which mechanisms and safeguards it will use and then implements one or the other to protect transmitted CUI. The three assessment objectives cover identifying the cryptographic mechanisms, identifying any alternative physical safeguards, and implementing protection during transmission.

The requirement · NIST SP 800-171 Rev 2, 3.13.8

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

The requirement is to prevent unauthorized disclosure of CUI during transmission through cryptographic mechanisms, with alternative physical safeguards as an accepted substitute. The assessment objectives split this into identifying the cryptographic mechanisms intended for this purpose, identifying any alternative physical safeguards, and implementing either the cryptographic mechanisms or the physical safeguards to protect CUI in transit. In most environments this means encrypting CUI whenever it crosses the network.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.8 into three objectives: identify cryptographic mechanisms, identify alternative physical safeguards, and implement one to protect CUI in transit.

[a]

Cryptographic mechanisms intended to prevent unauthorized disclosure of CUI during transmission are identified. The encryption to use is chosen.

MeetsCryptographic mechanisms for protecting CUI in transit are identified.
FailsNo cryptographic mechanisms are identified.
[b]

Alternative physical safeguards intended to prevent unauthorized disclosure of CUI during transmission are identified. Any physical alternative is chosen.

MeetsAlternative physical safeguards, where used instead of encryption, are identified.
FailsNeither encryption nor a physical alternative is identified.
[c]

Either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. Protection is actually applied.

MeetsCUI in transit is protected by encryption or physical safeguards.
FailsCUI is transmitted without protection.

The three objectives are identifying the two means and implementing one. The common failure is at objective [c], where CUI is transmitted over paths that are not consistently encrypted. The assessor looks for the mechanisms identified and protection actually implemented for CUI in transit.

3Failure Patterns

The failures are about CUI transmitted without protection.

Unencrypted transmission paths

CUI sent over paths that are not encrypted can be intercepted and disclosed. Implementing encryption on those paths protects it.

Encryption on some paths only

Protecting CUI on some transmission paths while leaving others in the clear leaves gaps. Protection has to cover the CUI in transit.

Mechanisms not identified

Without identifying the cryptographic mechanisms or physical safeguards to use, implementation is ad hoc. Identification is the basis for consistent protection.

The common root
This control fails where transmission is assumed safe. CUI crosses network paths that may be shared or untrusted, and unencrypted data on those paths is exposed to interception, so protection cannot be left to assumption. Implementing encryption or physical safeguards on the paths CUI travels is what prevents disclosure. Note that this control pairs with the FIPS-validation requirement that governs the strength of the cryptography used.

4Ownership

This is an IT and network-owned technical control.

RoleResponsibility for this control
IT and networkImplements encryption on CUI transmission paths. Owns the encryption configuration.
Security or compliance leadIdentifies the mechanisms and confirms CUI in transit is protected.
Program leadDocuments the transmission protection in the system security plan.
See also: This control pairs with the FIPS-validation requirement of SC.L2-3.13.11 and the key management of SC.L2-3.13.10.

5Tooling

The control is delivered by encryption of CUI in transit, or physical safeguards where used.

ObjectivesToolingWhat it provides
[a]TLS, VPN, encrypted protocolsIdentified cryptographic mechanisms for transit.
[b]Protected distribution systemIdentified physical alternative where used.
[c]Encryption implemented on transmission pathsCUI protected in transit.

The caveat is that protection has to cover the paths CUI actually travels, and the cryptography should meet the FIPS-validation requirement that accompanies this control. Encryption on some paths but not others, or non-validated cryptography, leaves exposure. The assessor examines identification and implementation, so all three objectives have to hold.

6Evidence

The satisfied version of 3.13.8 shows CUI protected in transit.

EvidenceWhat it demonstrates
Identified mechanisms and safeguardsObjectives [a], [b]. The means chosen.
Encryption configurationObjective [c]. CUI protected in transit.

The evidence should show identified cryptographic mechanisms or physical safeguards and their implementation on CUI transmission paths. The identified mechanisms together with the encryption configuration are the clearest demonstration, and because this control cannot sit on a plan of action, the protection has to be real at the time of assessment.

CUI in transit is exposed unless it is protected

Data crossing the network can be intercepted, so this three-point control asks that CUI be protected in transit by encryption or physical safeguards. Implementing that protection on the paths CUI travels is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.8. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.8[a] through 3.13.8[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SC.L2-3.13.8 among the three-point derived security requirements. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.7 · Prevent Split Tunneling
Next in System and Communications Protection →
SC.L2-3.13.9 · Terminate Network Connections
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.8 · Edition 2026.1 · Last reviewed July 12, 2026