Media Protection
That CUI on physical and digital media is protected, controlled in transit, and sanitized or destroyed before reuse.
The 9 requirements, in plain language.
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Limit access to CUI on system media to authorized users
Sanitize or destroy system media containing CUI before disposal or release for reuse
Mark media with necessary CUI markings and distribution limitations
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards
Control the use of removable media on system components
Prohibit the use of portable storage devices when such devices have no identifiable owner
Protect the confidentiality of backup CUI at storage locations
One owner across the whole family — built, run, and proven.
Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.
See all fourteen families →Not sure which families your contract puts in scope?
A readiness check maps your environment to all 110 controls and tells you exactly where you stand.