The six requirements
| Requirement | In plain English | Also at Level 1? |
|---|---|---|
| 3.10.1 | Limit physical access to systems, equipment and operating environments to authorized people | Yes |
| 3.10.2 | Protect and monitor the facility and its support infrastructure | No |
| 3.10.3 | Escort visitors and monitor what they do | Yes |
| 3.10.4 | Keep audit logs of physical access | Yes |
| 3.10.5 | Control and manage physical access devices: keys, badges, combinations | Yes |
| 3.10.6 | Enforce safeguarding measures for CUI at alternate work sites, such as home offices | No |
This guide follows NIST SP 800-171 Rev. 2, which the CMMC program rule references. We are not a C3PAO and do not perform certification assessments. Your assessor decides what evidence satisfies each requirement.
What an assessor tends to look at
- A defined list of who may enter areas where CUI is processed or stored, and an access control system or key log that matches it.
- Visitor procedures that are actually followed: sign-in, badge, escort, sign-out.
- Physical access logs that exist, are retained and are reviewed.
- An inventory of keys, badges and lock combinations, with a record of changes when people leave.
- A policy for remote work with CUI, and evidence people know it.
Where small contractors usually fall short
- Shared office space where the landlord controls the front door and nobody controls the room with the CUI.
- Keys and combinations that have not changed in years, through several staff departures.
- Badge technology that can be copied in seconds. See can prox cards be cloned.
- Visitor logs that exist at reception but not at the door that matters.
How we test it
Our compliance physical controls testing tests each PE requirement on site before your assessment and maps every finding to the requirement it affects, with a price range on each.
Last reviewed October 7, 2026.