8.2 Physical Protection (PE): Level 1 FAR Requirements & Level 2 Mapping

Key Takeaways

  • Physical Protection contributes two of the 15 Level 1 FAR security requirements.
  • For assessment, the second PE requirement is split into three phrases, so Level 1 PE maps to four NIST rows: 3.10.1, 3.10.3, 3.10.4, and 3.10.5.
  • The full Level 2 PE family contains six NIST SP 800-171 requirements; 3.10.2 and 3.10.6 are the two additional Level 2 requirements.
  • The organization defines authorization, log content and retention, monitoring, and alternate-site measures; CMMC does not prescribe universal cameras, signatures, or retention days.
  • Evidence should connect rosters, badges and keys, visitor activity, access logs, facilities, and alternate-site safeguards to the actual scope.
Last updated: August 2026

8.2 Physical Protection (PE): Facilities, Visitors, Access Devices & Alternate Sites

Physical Protection prevents unauthorized physical access to systems, equipment, media, and operating environments. Under the current model, two PE security requirements are part of Level 1. The second includes three phrases that are assessed separately, creating four PE rows in the §170.15 NIST mapping. At Level 2, two additional NIST requirements complete the six-requirement PE family.

| CMMC requirement or mapped phrase | Treatment | NIST mapping | Core result | |---|---|---| | PE.L1-b.1.viii | Level 1 | NIST 3.10.1 | Limit physical access to authorized individuals | | PE.L1-b.1.ix, first phrase | Level 1 mapping | NIST 3.10.3 | Escort visitors and monitor visitor activity | | PE.L1-b.1.ix, second phrase | Level 1 mapping | NIST 3.10.4 | Maintain audit logs of physical access | | PE.L1-b.1.ix, third phrase | Level 1 mapping | NIST 3.10.5 | Control and manage physical-access devices | | PE.L2-3.10.2 | Level 2 only | NIST 3.10.2 | Protect and monitor the physical facility and supporting infrastructure | | PE.L2-3.10.6 | Level 2 only | NIST 3.10.6 | Enforce safeguarding measures at alternate work sites |

The rule therefore has two Level 1 PE security requirements, four Level 1 PE mapping rows, and six Level 2 PE NIST requirements. Keep the three counts distinct.

Authorized physical access

PE.L1-b.1.viii, mapped to NIST 3.10.1, requires the organization to identify who may enter relevant facilities or access in-scope systems and equipment. Evidence can include approved rosters, badge permissions, key assignments, room-access groups, onboarding and termination tickets, and observations of doors or enclosures. The requirement does not mandate one technology: a guarded site, badge system, keyed room, locked cabinet, or combination may be appropriate when the implemented safeguards achieve the result.

Access approval should match job duties and the scope. A general building badge does not necessarily authorize a server room. Emergency and maintenance access should be governed and reviewable. Lost cards, departed personnel, shared keys, and unmonitored mechanical-key copies are common evidence gaps.

Protect and monitor facilities

PE.L2-3.10.2 is additional at Level 2 and adds protection and monitoring of the physical facility and supporting infrastructure. The organization chooses measures based on its sites and risks: guards, alarms, cameras, environmental monitoring, locked telecommunications rooms, power and cooling protections, or periodic checks may contribute. CMMC does not universally require 24/7 video surveillance, biometrics, or a particular wall construction.

The assessment connects the organization's stated design to actual operation. An installed camera that is disabled or an alarm with no response procedure does not prove the claimed protection.

Visitors

The first phrase of PE.L1-b.1.ix, mapped to NIST 3.10.3, requires escorting visitors and monitoring their activity. The organization defines who is authorized for unescorted access. Contractors such as cleaners or technicians are not automatically visitors forever; they may receive formally authorized access through the organization's screening and approval process. If they are not authorized, the organization escorts and monitors them in relevant areas.

Evidence may include visitor procedures, temporary badges, host assignments, receptionist practice, access records, and observation. A nondisclosure agreement by itself does not provide physical authorization.

Physical-access logs

The second phrase of PE.L1-b.1.ix, mapped to NIST 3.10.4, requires audit logs of physical access. Logs may be electronic badge records, guard logs, visitor systems, paper records, or a controlled combination. The organization defines necessary fields and retention based on accountability, investigation, contract, and legal needs. CMMC does not universally require a handwritten signature, a particular departure-time field, or one fixed retention period.

The key questions are whether relevant access is recorded, attributable, protected from unauthorized change, retained as defined, and available for review. If a visitor enters an in-scope room and no record is created, the objective is not met merely because other visitors signed a book.

Access devices

The third phrase of PE.L1-b.1.ix, mapped to NIST 3.10.5, covers keys, badges, combinations, tokens, and other physical-access devices. Inventory them, issue them to authorized people, recover or disable them promptly, protect spares, change compromised combinations, and periodically reconcile records. Evidence should link the authorization roster to active access rights and show how loss or termination is handled.

Alternate work sites

PE.L2-3.10.6 is additional at Level 2 and applies defined safeguards to alternate work sites such as home offices, temporary project sites, or customer locations. Measures follow the data and risk: prevent unauthorized viewing, secure devices and paper, control printing and media, protect equipment in transit, use privacy and locking measures, and report loss. It is a Level 2 requirement, not one of the four Level 1 PE safeguards.

Assessment approach

Trace a representative authorization from approval through badge or key assignment and later revocation. Compare the roster to access-system records. Select focused visitor and after-hours events. Walk relevant spaces. Review alternate-site rules and interview users. Methods are chosen for adequate and sufficient evidence; there is no universal requirement to inspect every door or use two methods for every objective.

A Level 1 self-assessment evaluates the two FAR PE requirements through four mapped assessment rows. A Level 2 assessment evaluates all six NIST PE requirements. This difference changes both the requirement count and the evidence plan.

Test Your Knowledge

A visitor entered an in-scope server room, but the OSC created no physical-access record. Which NIST row mapped from the second Level 1 PE requirement is implicated?

A
B
C
D
Test Your Knowledge

Night cleaners have master access to the CUI area. When can they be unescorted?

A
B
C
D
Test Your Knowledge

Which PE requirement addresses alternate work sites at Level 2?

A
B
C
D