The six requirements

RequirementIn plain EnglishAlso at Level 1?
3.10.1Limit physical access to systems, equipment and operating environments to authorized peopleYes
3.10.2Protect and monitor the facility and its support infrastructureNo
3.10.3Escort visitors and monitor what they doYes
3.10.4Keep audit logs of physical accessYes
3.10.5Control and manage physical access devices: keys, badges, combinationsYes
3.10.6Enforce safeguarding measures for CUI at alternate work sites, such as home officesNo

This guide follows NIST SP 800-171 Rev. 2, which the CMMC program rule references. We are not a C3PAO and do not perform certification assessments. Your assessor decides what evidence satisfies each requirement.

What an assessor tends to look at

  • A defined list of who may enter areas where CUI is processed or stored, and an access control system or key log that matches it.
  • Visitor procedures that are actually followed: sign-in, badge, escort, sign-out.
  • Physical access logs that exist, are retained and are reviewed.
  • An inventory of keys, badges and lock combinations, with a record of changes when people leave.
  • A policy for remote work with CUI, and evidence people know it.

Where small contractors usually fall short

  • Shared office space where the landlord controls the front door and nobody controls the room with the CUI.
  • Keys and combinations that have not changed in years, through several staff departures.
  • Badge technology that can be copied in seconds. See can prox cards be cloned.
  • Visitor logs that exist at reception but not at the door that matters.

How we test it

Our compliance physical controls testing tests each PE requirement on site before your assessment and maps every finding to the requirement it affects, with a price range on each.

Last reviewed October 7, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.