Requirements / Access Control (AC)
AC.L2-3.1.19
Encrypt CUI on Mobile
Official Source Material
Encrypt CUI on mobile devices and mobile computing platforms.
Determine if:
- [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and
- [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
The requirement names two device classes. Cover both.
Mobile devices are phones and tablets. Mobile computing platforms are laptops. CUI is the controlled unclassified information your contract requires you to protect. Objective [a] is one inventory of everything in either class that processes, stores, or transmits CUI, and [b] is encryption on every entry. The phone-and-tablet list from AC.L2-3.1.18 plus your laptop inventory is the starting point.
Laptops get full-disk encryption with escrowed keys.
BitLocker or FileVault on every in-scope laptop, with recovery keys escrowed, stored centrally through Intune or your directory, covers [b]. It produces its own evidence, because the escrow report is the encryption status list. Run the platform in FIPS mode where the guide's discussion applies, and leave the module validation details to SC.L2-3.13.11. Linux laptops need full-disk encryption chosen at build time, because retrofitting practically means reinstalling. Plan for it rather than discovering it during remediation.
Phones and tablets get container or full-device encryption.
App protection policies encrypt CUI inside managed applications, which is the practical answer for personal devices. Full-device encryption enforced by the device management platform is the alternative for corporate-owned devices. Either way the enforcement policy, exported from the console, is the evidence for [b].
A laptop that never leaves the building is still a mobile computing platform.
The guide's own example encrypts all laptops with the operating system's full-disk encryption. Arguing that a docked laptop is really a desktop invites a finding and saves nothing, because the encryption it would exempt costs nothing to enable.
Devices with no path to CUI are outside this requirement's inventory.
When policy keeps CUI off a class of devices and no access path exists, those devices do not belong on the [a] list. No CUI mailbox, no SharePoint access, and no file sync means no path. You do not have to armor those devices against a spillage that is not your fault. Be ready to demonstrate the absence of the path, because the claim is only as good as its enforcement.
Edge cases
- Devices excluded from scope by policy alone sit in a gray zone, because an assessor may treat any that connect to the system as risk-managed assets needing documented handling. Add a technical barrier, such as conditional access blocking the class, to make the exclusion hold.