Uniqcli

CMMC control families

CMMC Media Protection (3.8 MP): 9 requirements, from encrypted drives to destruction

Nine requirements covering everything CUI travels on — paper and digital, in the building and outside it. This is the family with the most real product behind it: encrypted media and self-encrypting drives, the encryption-management licensing that governs them, and the lifecycle lane that handles what happens at the end.

Family
3.8 — Media Protection
Requirements
9 of the 110 Level 2 requirements
Level 1
In scope — basic requirements from this family
Boundary
The capability behind the control — never a certification we hold
Overview

Everything CUI travels on, and what happens to it at the end

Media protection carries nine requirements covering system media in both paper and digital form: protect and securely store it (3.8.1), limit access to authorized users (3.8.2), sanitize or destroy it before disposal or release for reuse (3.8.3), mark it with the CUI markings and distribution limitations it needs (3.8.4), maintain accountability during transport outside controlled areas (3.8.5), apply cryptographic mechanisms to protect CUI on digital media during transport unless alternative physical safeguards are in place (3.8.6), control the use of removable media on system components (3.8.7), prohibit portable storage devices with no identifiable owner (3.8.8), and protect the confidentiality of backup CUI at storage locations (3.8.9). More of this family is purchasable than any other in the standard — hardware-encrypted media and self-encrypting drives, the encryption-management licensing that enrolls and reports on them, and reverse logistics for the drives that come out at the end — and none of it closes a requirement on its own.

Levels

What each level asks of this family

Media protection is one of the six families Level 1 touches. The FAR 52.204-21 baseline at that level is about sanitizing or destroying media containing Federal Contract Information before disposal or release for reuse — the disposal end of the family, not the encryption end.

Level 2 is where the rest arrives, and the two requirements that drive procurement are 3.8.6 and 3.8.9: cryptographic protection of CUI on digital media in transport, and confidentiality of backup CUI at storage locations. Read 3.8.6 with 3.13.11 beside it — where cryptography is what protects CUI, the standard asks for FIPS-validated cryptography, and that is a fact about the module rather than about the marketing copy.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Encrypted media in transport (3.8.6)

Hardware-encrypted portable drives are the clearest product answer in the whole standard. iStorage and Kanguru carry the deepest FIPS-titled line we stock, with Apricorn and Rocstor behind them and a thin Kingston presence. Our stock carries BOTH 140-2 and 140-3 wording across those rows, so we write FIPS-validated (CMVP-listed) rather than claiming a version across a brand list — ask for the CMVP certificate on any line where the module is the point and we confirm it on request before you commit.

Removable media you can actually control (3.8.7, 3.8.8)

3.8.8 prohibits portable storage with no identifiable owner, which in practice means issued, inventoried drives rather than whatever came in a conference bag. Hardware-encrypted USB drives are quoted per unit with the enrollment and management the model supports, and the ordinary flash-drive category is there for the non-CUI half of the estate.

Self-encrypting drives at rest (3.8.9)

For backups and endpoints, self-encrypting drives are a separate story from the FIPS-titled portable line and should not be folded into the same sentence. Axiom carries by far the deepest in-stock SED and OPAL line on the hub, with Samsung, Micron and Western Digital alongside. These are encryption-capable drives — where the CMVP listing is the point, say so on the RFQ and we source against that instead.

Encryption management licensing (3.8.6, 3.8.7)

Issued drives that nobody enrolled are not a controlled estate. Device-encryption management is licensing rather than hardware: Sophos Central Device Encryption is the deepest line in our catalog here, with Trend Micro's and Bitdefender's encryption modules alongside, quoted per seat against your term. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Destruction and disposal (3.8.3) — the honest answer

We do not stock destruction equipment. There are no degaussers in our catalog at all, and shredder availability is thin enough that it is a quote-only line rather than a shelf. Buying a machine is rarely the cheapest way to evidence this requirement. Where the drives are coming out as part of a refresh, our logistics lane already runs reverse logistics with certified data sanitization or destruction for data-bearing drives and disposition records that satisfy both the security office and the asset-management system — scoped with the refresh, not sold as a standalone service.

Limits

What stays yours to run

Marking media under 3.8.4 and maintaining accountability during transport under 3.8.5 are records and handling discipline — a courier log, a marking convention, a chain of custody. An encrypted drive does not mark itself, and it does not tell you where it went. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.

One dated fact worth planning around: every remaining FIPS 140-2 certificate moves to the CMVP Historical list on September 21, 2026, with FIPS 140-3 as the successor program. A device does not stop working that day, but a Historical certificate is weaker ground when an assessor asks how 3.13.11 is being met. If you are refreshing encrypted media anyway, it is worth asking which certificate a line actually holds before you buy it.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Media protection questions

Does CUI on a USB drive have to be encrypted?

3.8.6 requires cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport outside of controlled areas, unless otherwise protected by alternative physical safeguards. Where cryptography is what protects it, 3.13.11 asks for FIPS-validated cryptography. Hardware-encrypted drives are the common answer because the validation question is answerable on the product rather than on the laptop it was plugged into.

What does NIST 800-88 require for media sanitization?

NIST SP 800-88 Rev 1 describes three levels of sanitization — Clear, Purge and Destroy — chosen against the confidentiality of the data and whether the media will be reused or leave your control, with verification and documentation expected. 800-171's 3.8.3 requires you to sanitize or destroy media containing CUI before disposal or release for reuse; 800-88 is the guidance most programs cite for how.

How do you destroy hard drives that held CUI?

Through a documented process, evidenced. We do not stock destruction equipment — no degaussers appear in our catalog and shredders are a quote-only line — so the honest route is either an in-house process built on NIST SP 800-88 or a vendor who returns a certificate. Where the drives are coming out as part of a refresh we manage, our logistics lane handles reverse logistics with certified sanitization or destruction and disposition records; that is scoped with the refresh rather than sold on its own. What we can always quote is the replacement drive, and the screening on it.

Is media protection required at CMMC Level 1?

Yes. It is one of the six families Level 1 touches, though the Level 1 basic requirement is the disposal end — sanitizing or destroying media containing Federal Contract Information before disposal or release for reuse. The encryption and transport requirements arrive at Level 2 with the rest of the 110.

Get a CMMC estimate — CMMC Media Protection (3.8 MP)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Media Protection (3.8 MP)

Talk to us about encrypted media

Send the quantity, the capacity and whether the CMVP certificate is the point on that line. A Uniqcli specialist replies with an estimate for the media, any encryption-management licensing alongside it and the disposal leg if a refresh is driving this — FIPS-validated (CMVP-listed) options confirmed on request, availability stated honestly, TAA and §889 screening performed before it goes out.