Requirements / Media Protection (MP)
MP.L2-3.8.6
Portable Storage Encryption
Official Source Material
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.
Determine if:
- [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
This requirement gives you two ways to meet its one objective, and encryption is the better one.
CUI, controlled unclassified information, on digital media in transport is either encrypted or wrapped in physical safeguards such as a locked container under authorized custody. Encryption is cheaper, does not depend on anyone's vigilance, and keeps protecting the data after the physical safeguard fails. Reserve the physical route for media that genuinely cannot be encrypted.
Use FIPS-validated cryptography, because the assessor will ask.
The assessment guide's considerations ask whether the cryptographic mechanisms comply with FIPS 140-2, the federal standard for encryption modules. SC.L2-3.13.11 requires FIPS-validated cryptography wherever encryption is what protects CUI confidentiality. A hardware-encrypted drive with a FIPS 140 validation certificate is the clean answer: buy it, record the certificate number, and issue it through your MP.L2-3.8.1 inventory.
This requirement is the backstop for MP.L2-3.8.5.
Accountability tells you a drive is missing. Encryption decides whether that matters. The guide states the intent directly: protect against the situation where control of the media fails through loss. Treat the two as one procedure: sign out the encrypted drive and log the transport.
Backups leaving the building count as transport.
Tapes or drives couriered to offsite storage carry CUI outside your controlled areas. Enable your backup software's encryption for anything sent offsite, and confirm the mechanism is FIPS-validated rather than assuming it.
What falls short
- Encryption that is not FIPS-validated, with no physical safeguard in place. The confidentiality of CUI rests on validated cryptography under SC.L2-3.13.11, so an unvalidated mechanism alone leaves [a] exposed.
Edge cases
- Media moved between rooms inside your own controlled facility is not in transport outside controlled areas, so the requirement does not bite there. Encrypt it anyway, because the drive that never leaves the building eventually does.