There is a category of CMMC compliance failure that doesn’t involve a network breach, a compromised credential, or a misconfigured cloud environment. It involves a hard drive in a box being donated to a local school, a USB drive going home in an employee’s pocket, or a leased multifunction printer being returned to the vendor with every document ever scanned to it sitting intact on an internal storage drive that nobody thought to wipe.
Media protection is the CMMC domain that addresses exactly these scenarios — and it’s one of the domains where the gap between documented policy and operational practice is widest across the defense industrial base. Not because the requirements are technically demanding. They aren’t. But because media handling is unglamorous, easy to deprioritize against more visible security work, and dependent on operational discipline from people who aren’t always thinking about compliance when they’re boxing up old equipment or grabbing a USB drive from the supply cabinet.
When an assessor evaluates the Media Protection domain, they’re not just looking for a sanitization policy. They’re looking for evidence that sanitization actually happens — records showing which devices were processed, what method was used, who performed the sanitization, and what was done with the media afterward. Organizations that have policies and no records, or records that cover only certain device types and not others, consistently find this domain generates more findings than they expected from what seemed like a straightforward requirement.
What CMMC Requires Under Media Protection
The Media Protection domain in CMMC Level 2 contains six practices drawn from NIST SP 800-171. Together they establish a framework for controlling how CUI-containing media is accessed, marked, stored, transported, sanitized, and destroyed. Each practice addresses a specific point in the media lifecycle where CUI can be exposed if controls aren’t in place.
Practice 3.8.1 requires protecting system media containing CUI, both paper and digital, during transport using cryptographic mechanisms or physical safeguards. Practice 3.8.2 requires limiting access to CUI on system media to authorized users. Practice 3.8.3 is the sanitization requirement — sanitizing or destroying information system media before disposal or reuse. Practice 3.8.4 requires marking media with necessary CUI markings and distribution limitations. Practice 3.8.5 requires controlling access to media containing CUI and maintaining accountability for media during transport. Practice 3.8.6 requires implementing cryptographic mechanisms to protect CUI during transport unless alternative physical safeguards are employed.
Of these six practices, 3.8.3 — the sanitization requirement — generates the most assessment findings. Not because the others don’t matter, but because sanitization is the most operationally demanding practice in the domain. It requires an ongoing process that touches every endpoint refresh cycle, every equipment return, every USB drive disposal, and every printer replacement. Organizations that have a sanitization policy but haven’t built sanitization into their operational workflows discover during the assessment that the policy describes what should happen and the records don’t show that it did.
The NIST SP 800-88 Guidelines for Media Sanitization is the authoritative technical reference for satisfying 3.8.3. It defines the sanitization methods applicable to different media types — clear, purge, and destroy — and specifies which method is appropriate based on the sensitivity of the information the media contained and the planned disposition of the media. CMMC assessors evaluate sanitization practices against the 800-88 standard, and organizations whose sanitization procedures aren’t grounded in that methodology are working from an incomplete reference.

Understanding the Three Sanitization Methods
Before building a media sanitization program, it’s important to understand what NIST 800-88 means by each method — because “wiping a drive” means different things in different contexts, and not all of them satisfy CMMC requirements for CUI.
Clear applies logical techniques to sanitize data in all user-addressable storage locations. For a hard drive, this typically means overwriting all storage locations with a defined pattern using software tools. Clear is appropriate for media that will be reused within the same security domain — for example, a workstation hard drive that will be reimaged and redeployed to another user in the same CUI environment. It addresses normal data storage locations but may not reach areas of storage that are inaccessible through standard interfaces, such as bad blocks or hidden areas on certain storage devices.
Purge applies physical or logical techniques that render target data recovery infeasible using state-of-the-art laboratory techniques. For magnetic hard drives, degaussing is a purge method. For SSDs and flash storage, cryptographic erase — if the device supports it with appropriate implementation — or specialized firmware-level overwrite can qualify as purge. Purge is appropriate for media that will leave the organization’s control — media being disposed of, sold, donated, or transferred outside the CUI environment. Because modern data recovery techniques can in some cases recover data from cleared media, purge is the appropriate method when the media will no longer be under the organization’s physical control.
Destroy renders the media completely unusable and the data irretrievable. Shredding, disintegration, pulverization, incineration — physical destruction methods that produce no recoverable media. Destroy is appropriate when purge is not technically feasible for the media type, when the media is damaged or malfunctioning in ways that prevent reliable purge, or when the organization’s risk posture warrants the highest assurance level for a particular disposition decision. For organizations that handle especially sensitive CUI categories, destruction may be the policy-mandated method for all disposed media regardless of whether purge would technically suffice.
Choosing the right method for each media type and disposition scenario is a policy decision that needs to be made deliberately — not left to whoever happens to be handling a piece of equipment on the day it’s being retired. The policy should specify which method applies to which scenarios, and the records should confirm which method was used for each piece of media processed.
Hard Drives: The Device Most Organizations Handle Worst
Hard drives and solid-state drives are where media sanitization failures are most consequential and most common. A hard drive that contained CUI and leaves the organization’s control without proper sanitization is a data exposure event — not a potential one, an actual one. The CUI is on that drive until it’s sanitized or destroyed, and wherever the drive goes, the CUI goes with it.
The hard drive sanitization challenge has several dimensions that organizations often underestimate.
The first is volume. A defense contractor that has been operating for several years and has gone through one or more equipment refresh cycles has generated a significant number of drives that need sanitization records. Organizations that haven’t been tracking media sanitization discover this when they try to produce records for the assessment — either they don’t have records, or the records are incomplete, or they discover drives in storage that should have been sanitized but weren’t.
The second is media type complexity. Magnetic hard drives and solid-state drives require different sanitization approaches, and the SSD challenge is specific and worth understanding. Standard overwrite methods that work reliably for magnetic drives don’t necessarily sanitize all data on SSDs due to how flash storage manages writes — wear leveling algorithms distribute writes across the storage medium in ways that can leave data in areas that standard overwrite tools don’t reach. NIST 800-88 specifically addresses this, and organizations whose sanitization procedures don’t account for SSD-specific methods may be applying a technique that provides less assurance than they believe.
The third is equipment that contains drives but isn’t obviously a “storage device.” Workstations and servers are the obvious cases. Laptops, including personally owned laptops if they were used to access CUI, are another. Network-attached storage devices and backup appliances are often overlooked. Servers being returned to a cloud colocation facility. Virtual machine host systems where VMs processed CUI. And the device category that generates perhaps the most overlooked hard drive sanitization gap in defense contractor environments — the multifunction printer.
Printers: The Forgotten Media Sanitization Risk
Most defense contractors know they need to sanitize computer hard drives. Significantly fewer have thought carefully about the hard drives inside their multifunction printers, copiers, and scanners — and this is exactly the kind of gap that assessors find during Media Protection evaluations.
Modern multifunction printers — the kind that copy, scan, print, and fax — contain internal hard drives that store document images. Every document that gets copied, scanned, or printed is written to that internal storage. Many printers retain this data as a recoverable image on the internal drive indefinitely unless the device is specifically configured to overwrite it after each job, or until the drive is sanitized before the device leaves the organization’s control.
A leased multifunction printer that processed CUI documents over a three-year lease period, returned to the vendor at lease end without the internal drive sanitized, has delivered those document images to the vendor along with the device. The vendor may remarket the device, which delivers it to another customer. Whether that customer has the technical capability to recover those images is a risk that the defense contractor created when they returned the device without addressing the internal storage.
The sanitization options for multifunction printer drives include running the device’s built-in data overwrite function if one is available and documented as meeting an appropriate standard, having the drive removed and sanitized separately before the device is returned, or physically destroying the drive before return. The right approach depends on what the device supports and what the lease agreement allows — some vendors explicitly prohibit removing internal components, which means the organization needs to either negotiate data sanitization terms into the lease at contract signing or plan to run the device’s built-in sanitization function before return.
For manufacturing organizations where printers in engineering areas may have processed technical drawings containing CUI, and for legal and finance departments where sensitive contract documents routinely pass through shared printers, the printer sanitization gap is a real and specific exposure. Building printer disposition into the media sanitization program — with the same documentation discipline applied to hard drives — addresses it.
USB Drives and Removable Media: Small Devices, Large Exposure
USB drives occupy a specific position in the CMMC Media Protection domain — they’re both a sanitization requirement and an access control challenge, and most organizations handle both aspects less rigorously than the assessment will expect.
The sanitization requirement for USB drives is straightforward: any USB drive that contained CUI and is being disposed of or transferred outside the organization needs to be sanitized or destroyed before it leaves. The challenge is that USB drives are small, portable, and easy to lose track of — organizationally and literally. Defense contractors who don’t maintain an inventory of USB drives in use, who don’t track which drives have been used to handle CUI, and who don’t have a recovery and sanitization process for drives that are being retired don’t have the information needed to satisfy 3.8.3 for this device class.
The access control challenge is the counterpart to the sanitization requirement. CMMC’s Media Protection practices require limiting access to CUI on system media to authorized users. If USB drives can be used freely by anyone on the network to copy CUI files to portable media that then leaves the building, the access control and transport protection requirements are both at risk. Organizations that allow unrestricted USB access on CUI systems — without data loss prevention controls, without logging of what’s written to USB devices, without restrictions on which users can use USB drives and for what purpose — have an access control gap that the Media Protection domain flags directly.
The policy question of whether to allow USB drives at all in the CUI environment deserves deliberate consideration. Some organizations disable USB mass storage on CUI workstations entirely and provision secure managed transfer alternatives for the legitimate use cases that previously required USB drives. This approach simplifies both the access control and the sanitization requirements — no USB drives in the CUI environment means no USB drives to sanitize when they’re retired. For organizations whose CUI environment has limited need for removable media, this is often the cleanest compliance path. Our cybersecurity program framework helps organizations evaluate these policy tradeoffs against their specific operational requirements.
![]()
Building a Media Sanitization Program That Generates Compliant Records
A media sanitization policy that describes what should happen is a starting point. A media sanitization program that actually produces sanitized media and documented records is what the assessment evaluates. Building the program means connecting the policy to operational processes that generate records automatically rather than requiring someone to remember to document what they did.
The program needs to cover the full inventory of media types in the CUI environment. Hard drives in workstations, servers, and laptops. SSDs in any device that processed CUI. USB drives and other removable media. Internal printer drives. Any other storage device — backup tapes, external drives, network storage appliances — that touched CUI. For each device type, the program specifies the sanitization method, the tool or process used to execute that method, and the record format that documents each sanitization event.
Sanitization records need to capture specific information to be useful at assessment time. The device identifier — serial number, asset tag, or other unique identifier. The date of sanitization. The method used — clear, purge, or destroy. The tool used if applicable, with version. The name of the person who performed the sanitization. The disposition of the device after sanitization — returned to service, disposed of, transferred, destroyed. And for destruction events, the method of destruction and how the resulting material was handled.
These records need to be maintained, accessible, and organized in a way that allows production during an assessment. A spreadsheet maintained by the IT team that tracks every media sanitization event since the program was established is a simple and effective format. A dedicated IT asset management system with sanitization workflow built in is more automated and scales better for larger organizations. What doesn’t work is informal email confirmations, verbal assurances that “drives get wiped when they’re retired,” or nothing at all.
The backup and data recovery architecture needs specific attention in the media sanitization context. Backup media — whether physical tapes, external drives, or cloud-adjacent storage appliances — contains CUI if the systems being backed up contain CUI. When backup media is retired, it goes through the same sanitization program as any other CUI-containing media. Organizations that have a rigorous workstation sanitization program but haven’t extended that program to backup media have an incomplete implementation that assessors will flag.
The Chain of Custody Requirement: Tracking Media in Transit
Practice 3.8.5 requires maintaining accountability for media during transport — a requirement that extends beyond the organization’s walls when media is being moved between facilities, sent to a third-party sanitization or destruction vendor, or transferred to another party under any circumstances.
Chain of custody for media in transit means documenting the handoff — who transferred the media, to whom, when, under what transport conditions, and what the receiving party’s responsibility for the media is. For media being sent to a third-party destruction vendor, this means getting a certificate of destruction from the vendor that identifies the specific media processed and the destruction method used. That certificate becomes part of the sanitization record and provides the documentation that someone other than the organization’s own personnel performed the destruction.
Third-party destruction vendors who provide documented chain of custody and certificates of destruction satisfy the accountability requirement when media is sent to them for destruction. Vendors who accept media without providing per-device documentation don’t — a generic “we destroyed a box of hard drives” confirmation doesn’t produce the record that maps specific media to a confirmed destruction event. When evaluating destruction vendors, the documentation they provide is as important as the security of their process.
For engineering firms with multiple offices who transfer CUI-containing equipment between locations, and for organizations that lease equipment that gets picked up by the lessor, the chain of custody requirement means documenting those transfers explicitly rather than treating them as routine logistics operations.

Marking Requirements: What CMMC Expects Before Media Leaves the Environment
Practice 3.8.4 requires marking media with necessary CUI markings and distribution limitations. This is the requirement that connects the Media Protection domain to the broader CUI identification and marking framework — and it’s the practice that most directly addresses physical media moving in and out of the CUI environment.
CUI media marking means that portable storage devices, printed documents, and physical media containing CUI are labeled in a way that makes their CUI status clear to anyone who handles them. A USB drive containing CUI design files should be labeled as CUI. A printed technical drawing should carry the appropriate CUI marking. A CD containing controlled software should be marked before it leaves the immediate workspace.
The marking requirement creates a practical operational challenge: how does marking actually happen consistently in an environment where CUI is being moved to physical media by multiple people for multiple purposes? The answer involves both policy — specifying what needs to be marked, how it should be marked, and who is responsible — and procedure — the specific steps someone takes when they’re preparing CUI for transfer to physical media. Training personnel on these procedures is part of the Awareness and Training domain requirements, but the Media Protection domain requires that the marking actually happens as a result of that training.
For organizations whose CUI arrives on physical media from prime contractors or government customers without appropriate marking, the procedure needs to address how received media gets marked within the organization’s environment before it’s handled and stored. Unmarked CUI media that’s treated as non-CUI because it wasn’t marked when received is a handling failure regardless of the external party’s marking oversight.
Our guide on CUI identification and marking covers the broader CUI marking framework that the Media Protection marking requirement fits within.
Paper Media: The Analog Compliance Gap
CMMC’s Media Protection requirements apply to both digital and paper media — a scope that organizations sometimes overlook when they focus primarily on electronic storage devices. Paper documents containing CUI require the same protection, marking, controlled access, and disposal discipline as digital media. When a paper document is no longer needed, it doesn’t go in the recycling bin. It gets shredded.
The paper media sanitization requirement is satisfied by cross-cut shredding at minimum — strip-cut shredding is considered insufficient for CUI protection. Some organizations use micro-cut shredders for higher assurance, and organizations with large volumes of CUI paper documents may use a certified document destruction service that provides certificates of destruction.
The record-keeping requirement for paper media destruction follows the same logic as for digital media — documenting what was destroyed, when, and by what method. For organizations that use a document destruction service, the service’s destruction certificates satisfy this requirement. For organizations that handle paper destruction internally, maintaining a log of shredding events — including the date, the description of what was destroyed, and who performed the shredding — creates the record that assessors will look for.
Paper media protection also extends to storage and access control. CUI documents that are in active use but not in someone’s hands need to be stored in a way that limits access to authorized users. Locked cabinets, secure rooms with controlled access, or clear-desk policies that require CUI documents to be secured when unattended all address the access control requirement for paper media at rest.
For organizations in Boston, Tampa, or Sarasota where Stealth Technology Group operates, certified document destruction services are readily available — and building a relationship with a certified provider before the assessment, rather than after a finding, is the straightforward way to address the paper media destruction requirement with documented certificates.
Integrating Media Protection Into the Broader Compliance Program
Media protection doesn’t exist in isolation from the rest of the CMMC compliance program. It connects to several other domains in ways that a siloed approach to compliance misses.
The connection to the System Security Plan is direct — the SSP needs to describe the media protection program specifically: what types of media are in scope, what the sanitization methods are for each type, how records are maintained, and how the chain of custody requirement is satisfied for media in transit. A vague SSP description that says “media is sanitized before disposal in accordance with organizational policy” without specifics about media types, methods, tools, and records tells an assessor very little and will generate interview questions that a more specific description would have pre-empted.
The connection to Configuration Management is also direct — the configuration of CUI workstations determines whether USB mass storage is enabled or restricted, and the configuration management program should document that configuration decision and maintain it against baseline. A workstation baseline that restricts USB mass storage is a configuration control that directly supports media protection.
The connection to the System and Information Integrity domain appears through the monitoring requirements — organizations should have visibility into when media is being used to transfer CUI, whether through logging USB device connections on CUI workstations or through data loss prevention tools that monitor and log file transfers to removable media. That visibility both supports the access control requirements and produces audit evidence that the controls are functioning as described in the SSP.
A compliance program that treats Media Protection as an integrated domain rather than a standalone checklist builds controls that reinforce each other — configuration management restricts USB access, monitoring logs what USB access occurs, sanitization records document what happens when media is retired, and the SSP ties all of it together in a description that assessors can verify. A co-managed IT arrangement that includes media tracking and sanitization workflow as a defined service component makes this integration operational rather than theoretical.
What Assessors Actually Look For During Media Protection Evaluation
When a C3PAO assessor evaluates the Media Protection domain, they’re applying the examine, interview, and test methodology across all six practices. Understanding their specific lines of inquiry helps organizations prepare evidence that actually demonstrates compliance rather than hoping their documentation happens to address what the assessor cares about.
For sanitization specifically, assessors typically request the organization’s media sanitization records and evaluate them for completeness — whether all device types are covered, whether the methods documented align with NIST 800-88, whether records exist for the period since the last assessment or since the program was established. They’ll ask in interviews about the process — who performs sanitization, how they know a device needs to be sanitized, what tools they use, and where the records are kept. And they may verify technically by cross-referencing asset disposition records against sanitization logs to see whether devices that left the asset inventory have corresponding sanitization records.
For marking, assessors may ask to see examples of marked media and review the policy governing marking requirements. They’ll ask personnel whether they understand what needs to be marked and how — and they’ll listen for responses that reflect genuine operational understanding rather than recited policy language.
For access controls, assessors will look at workstation configurations to verify that USB mass storage restrictions are implemented as the SSP describes, and they may ask about how media access is logged and monitored.
The CMMC audit checklist covers the broader assessment preparation that Media Protection evidence fits within — and organizations that have completed the full assessment preparation process described there will find that Media Protection evidence is one component of a comprehensive evidence library rather than something assembled in isolation.
![]()
Conclusion: Media Protection Is Where Physical and Digital Security Meet
The Media Protection domain sits at the intersection of physical security discipline and digital compliance program management — and that intersection is exactly where defense contractor compliance programs most often have gaps. The controls are well-understood. The policy requirements are clear. But the operational discipline required to sanitize every device, mark every piece of removable media, document every transfer, and maintain records across the full lifecycle of every CUI-containing device is the kind of sustained operational work that compliance programs built for assessment purposes rather than program purposes consistently fail to sustain.
Defense contractors who build media sanitization into their equipment lifecycle processes — treating sanitization as a required step in device retirement the same way configuration is a required step in device deployment — produce compliant records naturally rather than scrambling to reconstruct them before the assessment.
If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.
