Requirements / Physical Protection (PE)
PE.L2-3.10.2
Monitor Facility
Official Source Material
Protect and monitor the physical facility and support infrastructure for organizational systems.
Determine if:
- [a] the physical facility where organizational systems reside is protected;
- [b] the support infrastructure for organizational systems is protected;
- [c] the physical facility where organizational systems reside is monitored; and
- [d] the support infrastructure for organizational systems is monitored.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Protect and monitor are two duties across two subjects.
Objectives [a] and [b] ask that the facility and the support infrastructure are protected: locks, barriers, controlled entry. Objectives [c] and [d] ask that both are monitored: some way of knowing who came near and when. Cover each pairing deliberately, because a locked closet nobody can account for fails the second half.
Support infrastructure means the cabling, closets, and panels your systems depend on.
Lock the wiring closet, run cable through conduit or trays where it crosses uncontrolled space, and keep spare network jacks disconnected or locked down. The requirement's discussion names exactly these measures, and they are cheap.
Monitoring does not mean cameras watched around the clock.
Badge logs with alerting on unauthorized attempts count as monitoring. So do an alarm system armed after hours, a reception desk during business hours, and a key sign-out log for the wiring closet. Cameras add coverage and timestamps, and a small office can meet [c] and [d] without them.
Scope stops at what you control.
The requirement does not extend to the power utility or the guards at a substation. It is also not about uptime: NIST SP 800-171 protects confidentiality, so redundant power and fire suppression are risk decisions, not obligations here. Ask of any proposed measure whether losing it would expose CUI, the Controlled Unclassified Information you protect, and spend accordingly.
Multi-tenant buildings are where this requirement fails.
A network closet shared with the landlord or other tenants, with your firewall in it and no way to tell who enters, is the recurring gap. Put your equipment in a locked cabinet inside the shared space, control that key, and get notification of building staff access written into the lease terms.
What falls short
- Pointing at network controls, such as 802.1x port authentication, as facility protection. Logical controls do not keep hands off hardware, so they answer nothing under [a] through [d].
Edge cases
- A home office that houses in-scope servers or network equipment is a facility for this requirement. A locked room, a locked cabinet inside it, and household alarm or camera coverage scale the controls down without waiving them.
- When the demarcation point, the carrier's handoff to your wiring, sits in a landlord-controlled room, document what you control, what the building controls, and how you would learn of access. Showing you addressed the space beats pretending it is out of scope.