Requirements / System and Communications Protection (SC)
SC.L2-3.13.16
Data at Rest
Official Source Material
Protect the confidentiality of CUI at rest.
Determine if:
- [a] the confidentiality of CUI at rest is protected.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Encryption and physical protection both satisfy this requirement.
Objective [a] asks that the confidentiality of CUI (Controlled Unclassified Information) at rest is protected, not that it is encrypted. A server that never leaves an access-controlled room can rest on physical protection. The assessment guide's own example accepts a sign-out and locked-closet procedure for devices that cannot be encrypted.
Encrypt anyway. The argument is worth less than the checkbox.
Full-disk encryption is built into the operating systems you already run and removes the burden of proving the physical story asset by asset. Reserve the physical justification for equipment that genuinely cannot encrypt.
Anything that leaves the protected area is encrypted, not argued.
Laptops, phones, portable drives, and backup media are outside your physical safeguards the moment they move. AC.L2-3.1.19 and MP.L2-3.8.6 make encryption explicit for mobile devices and transported media, and the validation question for that encryption belongs to SC.L2-3.13.11.
Components that never store CUI meet this by keeping it that way.
A device that only processes or relays CUI, with administrative controls keeping CUI from being written to it, has no CUI at rest to protect. Document the control that keeps storage off the asset. If CUI lands on it anyway, it is a storage asset and needs the protection.
Edge cases
- Equipment that cannot support encryption gets a custody procedure: signed out when needed, kept in the borrower's possession, locked away on return, and audited. The assessment guide's example describes exactly this.