CMMC Level 2 · NIST SP 800-171
How physical systems support the protection requirements
CMMC Level 2 uses the 110 requirements in NIST SP 800-171 Revision 2. The six physical protection requirements below are one part of that broader program. Confirm the current contract, CUI boundary and assessment requirements with your compliance lead; NIST's newer Revision 3 publication is not interchangeable with this CMMC baseline.
PE · 3.10.1
Restrict physical access
Limit access to organizational systems, equipment and operating environments to authorized individuals. Door readers, restricted-area permissions and locked network racks support your documented authorization process.
PE · 3.10.2
Protect & monitor the facility
Protect and monitor the physical facility and supporting infrastructure. Cameras, door monitoring, intrusion detection and protected cabling can support this outcome; no particular camera, alarm or LPR brand is mandated by this requirement.
PE · 3.10.3
Escort & monitor visitors
Escort visitors and monitor their activity. Temporary credentials and video coverage can support oversight, but they do not replace your visitor authorization, escort procedures and staff responsibilities.
PE · 3.10.4
Maintain physical access logs
Maintain audit logs of physical access. Electronic access events can support these records when the system is properly configured and your team manages log review, retention, time settings and access to records.
PE · 3.10.5
Manage physical access devices
Control and manage physical access devices, including keys, badges and credentials. Issuance, approved permissions, lost-badge response and prompt revocation remain part of the customer's operating procedures.
PE · 3.10.6
Safeguard alternate work sites
Enforce safeguarding measures for controlled unclassified information (CUI) at alternate work sites. A main-facility installation does not resolve remote-work protections; your team must define and implement those measures separately.
Your organization defines authorized personnel, maintains visitor procedures, manages credentials and reviews evidence. Fireside supplies the contracted physical systems and installation records; your assessor evaluates the implementation and overall compliance.
Official references: DoD CMMC documentation and Level 2 assessment guide · NIST SP 800-171 Revision 2