CMMCpedia Download

Requirements / Access Control (AC)

AC.L2-3.1.9

Privacy & Security Notices

Official Source Material

Provide privacy and security notices consistent with applicable CUI rules.

Determine if:

  1. [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category; and
  2. [b] privacy and security notices are displayed.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

A notice at initial logon carries this requirement.

Display the notice where human users log on, at or before authentication. A notice on every application and system behind that first logon is a risk-based choice, not a requirement. The underlying discussion says a secondary notification is something you consider, not something you owe. One well-placed banner beats twenty inconsistent ones.

Write your own text. Do not copy the DoD banner.

The standard DoD banner speaks for U.S. Government information systems and never mentions CUI, the controlled unclassified information your contract requires you to protect. Yours is a private system that handles government information. Cover the essentials: use may be monitored and recorded, use constitutes consent, unauthorized use is prohibited and carries penalties, and the system may contain CUI to be handled per your policy. Have counsel review it, because the banner's function is legal notice, not decoration.

A generic CUI statement is enough.

Objective [a] ties notices to CUI-specified rules, and few categories impose special notice requirements. Stating that the system may contain CUI and pointing to your handling policy satisfies the association. You do not need to enumerate CUI categories in the banner.

The display can take several forms.

A logon banner, a desktop background carrying the notice, a Terms of Use acknowledgment enforced at sign-in through conditional access, or printed notices posted where no screen exists all satisfy [b]. Pick what each platform supports, keep a screenshot of each, and note in the system security plan which form covers which system.

Edge cases

  • Microsoft Entra ID caps the sign-in page text well short of a full banner. Use a shortened notice there and enforce a full Terms of Use document through conditional access, which also produces a per-user acceptance record.
  • Phones and tablets rarely display logon banners, and nobody reasonably expects them to. Where mobile devices are kept out of the CUI path, say so, and where they are in it, a device management enrollment notice referencing your CUI handling policy fills the gap.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.