Requirements / Media Protection (MP)
MP.L2-3.8.3
Media Disposal
Official Source Material
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
Determine if:
- [a] system media containing FCI is sanitized or destroyed before disposal; and
- [b] system media containing FCI is sanitized before it is released for reuse.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Sanitize everything that held FCI or CUI, and do not parse the wording for an exemption.
Federal Contract Information is the information provided by or generated for the government under a contract and not intended for public release. The requirement text says Federal Contract Information because MP.L2-3.8.3 carries the Level 1 practice forward into Level 2. The CUI on your media, the controlled unclassified information you must protect, is contract information too. The practical scope is every item of media that held either. This is also a five-point requirement under 32 CFR 170.24. Under 32 CFR 170.21, its point value bars it from any POA&M, the plan of action and milestones that lets certain gaps be closed after assessment. Have the process working before the assessment rather than promising it after.
Anchor your methods to NIST SP 800-88 and pick by destination.
The assessment guide points to NIST SP 800-88, Guidelines for Media Sanitization, and its techniques of clearing, purging, cryptographic erase, and destruction. Use clear-level sanitization for media reused inside the organization, and purge or destroy anything leaving your control. Write the chosen method for each media type into your procedure so nobody improvises at the recycling bin. You do not need government-grade destruction services for CUI. A method that makes the information unrecoverable is what the requirement asks for.
Understand what your erase button actually does before you rely on it.
A factory reset or a vendor wipe utility qualifies only if it sanitizes all user-addressable storage. Cryptographic erase works only if the encryption key on the drive itself is destroyed. Deleting recovery keys from where you store them does not touch the key on the drive. For each device type you dispose of, keep the vendor documentation that says what the sanitization function does, or destroy the media instead.
Keep a destruction log. The process is invisible without it.
Record the date, the media or asset identifier, the method, and who performed or witnessed it. A certificate of destruction from a shredding vendor is a ready-made entry. When an assessor asks how you meet [a], a log with entries is the difference between a described process and a demonstrated one.
Paper is in scope, and shredding is the answer.
The requirement covers non-digital media, and the guide names removal, redaction, and destruction as sanitization for paper. Cross-cut shredding before disposal or recycling, with the habit written into your procedure, closes [a] for paper. Boxes of intact CUI paper handed to a recycler close nothing.
What falls short
- Drives, phones, or disks dropped in the trash or handed to a recycler unsanitized. That is precisely the disposal [a] exists to prevent.
- A factory reset you have not verified. If you cannot show what the reset sanitizes, you cannot show the media was sanitized before reuse, and [b] is unmet.
- Deleting BitLocker recovery keys from your management console as a claimed cryptographic erase. The media encryption key still lives on the drive, so the data remains recoverable and [a] and [b] are unmet.
- A vendor's verbal assurance that a leased device was wiped. Without documentation of the method, there is no evidence for [a].
Edge cases
- Copiers, printers, and scanners with internal storage are system media. At end of lease or life, get the vendor's written confirmation that its wipe meets NIST SP 800-88, or have the storage removed and destroyed.
- A drive whose contents you cannot reconstruct gets sanitized as if it held CUI. A purge-level method such as the drive's built-in sanitize command settles the question regardless of what was on it or whether it was encrypted.