Requirements / Media Protection (MP)
MP.L2-3.8.9
Protect Backups
Official Source Material
Protect the confidentiality of backup CUI at storage locations.
Determine if:
- [a] the confidentiality of backup CUI is protected at storage locations.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Start by listing every place a backup of CUI lands.
The list includes server images, file share snapshots, cloud tenant retention, the network storage box in the closet, the external drive someone rotates, and a line-of-business vendor's own backup. The requirement covers the confidentiality of backup CUI, the controlled unclassified information you protect, at each storage location. The location you forgot is the finding. If CUI is in a system, its backups hold CUI.
Encryption, access control, and physical security are all valid. Use encryption as the default.
The guide accepts cryptographic mechanisms or physical controls at the storage location. Encrypting backup data with a FIPS-validated mechanism, encryption the government has certified, answers the assessor's follow-up question before it is asked. A locked room plus tightly limited access is the alternative for on-premises media you cannot encrypt.
Cloud backup inheritance is real, but only as complete as your backup inventory.
If every backup of CUI lives inside your FedRAMP-authorized cloud environment, one the federal government has assessed and approved, the provider's protections can carry this requirement. The claim collapses the moment CUI is also backed up somewhere you did not account for. The inventory from the first lesson is what makes the inheritance defensible.
Inheritance is documented, not declared.
Get the provider's customer responsibility matrix, the document that splits security duties between the provider and you. Find the rows covering backup storage protection. Cite them in your system security plan, the document that describes how your system meets each requirement, next to what remains yours to do. A bare statement that the cloud handles everything is not evidence and invites the questions it cannot answer.
What falls short
- Unencrypted backup drives or tapes on an office shelf. Nothing protects the confidentiality of the backup CUI at that storage location, so [a] is unmet.
- A claim of full inheritance from a cloud provider while a local NAS also receives backups. The unaccounted location leaves [a] unmet regardless of how good the cloud story is.
Edge cases
- Backup media in transit to an offsite location is covered by MP.L2-3.8.5 and MP.L2-3.8.6, and this requirement picks up when the media arrives. Encrypting the backups once satisfies all three without separate mechanisms.
- In a Microsoft 365 tenant, platform retention and recycle mechanisms may be the only backup you have. If you add a third-party backup tool, its storage location becomes a CUI location that needs the same FedRAMP scrutiny as the tenant itself.