Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
PHYSICAL PROTECTION

CMMC Physical Protection: Facility Access, Visitor Logs, and Alternate Work Sites (3.10.x)

CMMC physical protection covers authorized facility access, visitor control, access logs, physical devices, and safeguards at alternate work sites.

Papercraft front door with a badge reader and visitor sign-in clipboard beside a small house shape, illustrating facility access control, visitor logs, and alternate work sites.

Physical protection under 3.10.x is not just a locked front door. It covers authorized physical access, monitoring, visitors, physical-access records, access devices such as badges or keys, and safeguards for alternate work sites.

A small defense contractor gets more value from asking a narrower question: where inside the FCI/CUI boundary does this requirement apply, who owns it day to day, and what evidence currently backs it up?

The rule in plain English

The contractor should know who can enter controlled spaces, how visitors are escorted or monitored, how access devices are issued, and what happens when credentials are lost or no longer needed.

3.10.6 extends protection to alternate work sites, which is why home offices and temporary locations need concrete safeguards when CUI is handled there.

How to implement it without overbuilding

Define controlled areas based on where in-scope systems, media, or security-protection assets are located. Use existing badge or key systems when they provide reliable authorization and records.

For alternate work, document expectations for device custody, screen privacy, printing, storage, visitors, and conversations where those risks are relevant.

What evidence to keep

Keep authorized-person lists, visitor logs, badge/key assignment records, physical-access logs, lost-badge actions, and alternate-site procedures.

Evidence should match the facility reality; a visitor log that nobody uses at a side entrance creates a policy/operation gap.

Where teams get into trouble

Over-scoping the whole building creates needless burden, while under-scoping server rooms, print areas, or CUI storage misses real exposure. Retained active badges for departed personnel are another common gap.

Small-contractor walkthrough

A small contractor occupies part of a shared industrial building. The physical-security story should identify the controlled suite, server/network closet, print and media locations, visitor path, after-hours access, and the safeguards used when engineers work from home.

  • Mark controlled areas.
  • Reconcile badge/key holders.
  • Use visitor escort/logging.
  • Review lost or unreturned access devices.

Decisions to document before assessment

Before marking this topic ready, make four decisions explicit: mark controlled areas; reconcile badge/key holders; use visitor escort/logging; and review lost or unreturned access devices. Assign an owner and an evidence location to each decision.

Manual deep review: trace physical access at the facility and an alternate work site

Start by identifying where in-scope systems, CUI media, printers, network equipment, backup media, and security-protection components physically exist. In a shared industrial building, the relevant boundary may include the leased suite, server/network closet, engineering area, print area, shop-floor terminals, records storage, and other places where unauthorized physical access could expose CUI or the systems that protect it. Side doors, loading docks, shared hallways, cleaners, landlord personnel, and unsecured closets can bypass a front-desk-only security design.

Define who is authorized for each controlled area and how physical access is limited and monitored. Reconcile badges, keys, access codes, and other physical-access devices to the current authorized-person list. Badge logs are useful, but they do not compensate for an active credential still assigned to a departed employee or a network closet that everyone in the building can enter.

For visitors, define identity verification, host approval, visible distinction from regular personnel, permitted areas, escort or monitoring, and entry/exit records. A sign-in sheet is only part of the control if visitors can later move through sensitive areas without restriction. Sample a real visitor record and follow the person's physical route.

For home or temporary work sites, decide what safeguards apply to visible screens, other household or visitor access, printed CUI, device storage, conversations, local printers, and equipment or media transport. If VDI prohibits local CUI storage and printing, test those restrictions. Before assessment, walk one facility path from entry to a CUI workstation and interview one remote worker about the actual alternate-site process.

  • Authorized-person list by controlled area.
  • Badge/key/access-device inventory.
  • Visitor entry/exit and escort records.
  • Facility monitoring evidence.
  • Alternate-work-site safeguards and user training.

Manual assessment cross-check

Sample one badge holder, one visitor, one returned or changed physical-access device, and one alternate-work-site user against the current procedure.

Use CMMC Physical Protection: Facility Access, Visitor Logs, and Alternate Work Sites (3.10.x) as an operating guide, not as a substitute for the controlling source. Before publication or assessment use, re-open the current NIST SP 800-171 Rev. 2 requirement, the corresponding NIST SP 800-171A assessment objectives, and the DoD CMMC Level 2 Assessment Guide. Confirm that every mandatory statement on the page maps to those sources or to a clearly labeled organizational implementation choice.

Additional objective-level implementation notes

Test places where office assumptions break: loading docks, shared hallways, telecom rooms, after-hours cleaning routes, printers near common space, shop-floor terminals, and equipment staged for repair or shipping. If a CUI printer or network closet can be reached from shared space, document the actual physical restriction or change the layout rather than relying on the front-door badge system.

Do not invent a universal retention period for visitor or badge records unless another requirement establishes one. Define the organization's retention rule and follow it. For alternate work sites, verify that the technical architecture matches the written rule—especially whether local download, printing, and unattended display of CUI are technically possible and operationally permitted.

Final manual spot check

For a final spot check, trace one visitor from arrival through departure and one employee from the office to an alternate work site. The visitor case should prove identity, host responsibility, movement restrictions, and recordkeeping. The remote-work case should prove how the device, screen, printed material, and local storage are protected outside the main facility. These two samples test the physical control family at both the primary site and the location most likely to be overlooked.

WORKING CHECKLIST

A short working check

  • Mark controlled areas.
  • Reconcile badge/key holders.
  • Use visitor escort/logging.
  • Review lost or unreturned access devices.
  • Document alternate-site safeguards.
  • Test side doors and after-hours access.

Common questions

Does every office need badge access?

No. The requirement is to limit and manage physical access to relevant systems, equipment, and operating environments.

Are visitor logs required?

Rev. 2 calls for physical-access audit logs and visitor control/monitoring; implementation method can vary.

Do home offices matter?

If users access CUI or in-scope systems from home, alternate-work-site safeguards should be addressed.

Can a reception sign-in sheet be enough?

It can be part of the evidence, but it does not replace escort, monitoring, and access-control practices.

Are cameras mandatory for CMMC physical protection?

No universal camera mandate applies. Use physical protection and monitoring controls appropriate to the actual environment and show they work.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.