There is a category of CMMC compliance failure that doesn’t involve a network breach, a compromised credential, or a misconfigured firewall rule. It involves a hard drive going into a dumpster, a USB stick going home in someone’s pocket, or a leased copier rolling out the loading dock door with a hard drive still holding six months of scanned proposals. Media protection failures are physical, they are mundane, and they are shockingly common in organizations that have otherwise built a defensible security program.
Most contractors preparing for a CMMC Level 2 assessment pour their energy into access control, multi-factor authentication, and vulnerability scanning. Those controls matter, and we’ve written at length about vulnerability management cadence and what assessors expect to see. But the Media Protection family — MP in the NIST SP 800-171 control set — gets treated as an afterthought, and that’s exactly why it shows up as a finding during readiness assessments more often than it should.
What CMMC’s Media Protection Family Actually Requires
Media Protection maps to a specific set of requirements inside NIST SP 800-171 Revision 3, and CMMC Level 2 pulls those requirements directly into its assessment scope. The intent isn’t complicated: any system component that stores Controlled Unclassified Information — a hard drive, a solid-state drive, a USB thumb drive, backup tape, or the internal storage inside a networked printer — has to be controlled from the moment it’s provisioned until the moment it’s destroyed or verifiably sanitized.
That lifecycle obligation is the part organizations miss. They’ll have decent access controls on active media, but the moment a device is retired, replaced under a refresh cycle, or returned at the end of a lease, the control discipline evaporates. An assessor evaluating against 800-171A procedures isn’t just asking whether you have a policy that mentions media sanitization. They’re asking for evidence — logs, certificates, signed forms — that ties a specific device serial number to a specific sanitization event on a specific date. If you can’t produce that paper trail, the control is scored as not met, regardless of how good your intentions were.
This is also where the compliance services conversation tends to shift for contractors who assumed CMMC was primarily an IT security exercise. Media protection sits at the intersection of IT, facilities, and procurement, which means the policy has to reach beyond the helpdesk.

The Difference Between Clear, Purge, and Destroy
Sanitization isn’t a single action — it’s a set of methods with different levels of assurance, and picking the wrong one for the media type and CUI sensitivity is one of the most common gaps we find. The framework organizations should be working from breaks sanitization into three tiers:
- Clear — overwriting storage with non-sensitive data using standard read/write commands, effective against basic data recovery tools but not sufficient for media that’s leaving your custody entirely.
- Purge — applying techniques like cryptographic erase or ATA Secure Erase commands that render data recovery infeasible even with laboratory-grade forensic tools, appropriate for media being reused within a lower-sensitivity environment or prepared for external transfer.
- Destroy — physical destruction through shredding, disintegration, or degaussing to the point that the media can no longer function as a storage device at all, which is the only acceptable method for drives that held CUI and are being decommissioned entirely.
The mistake we see most often is applying “clear” to media that should have been purged or destroyed — a quick format-and-reinstall on a laptop hard drive before it’s handed off to a leasing company, treated as equivalent to actual sanitization. It isn’t. Deleted files and even reformatted partitions remain recoverable with commodity forensic tools, which means that quick wipe doesn’t satisfy the control and doesn’t protect the CUI that was on that drive.
Hard Drives: The Asset Everyone Remembers Until the Lease Ends
Hard drive sanitization gets the most attention because it’s the most obvious risk, but attention doesn’t always translate into process. The failure pattern is predictable: a workstation refresh happens, IT images the new machines, and the old hard drives get pulled and set aside “to deal with later.” Later becomes six months, the drives migrate to a storage closet, and eventually someone without full context throws them in with general e-waste pickup.
The fix isn’t complicated, but it requires discipline that most internal IT teams don’t have bandwidth to maintain consistently, which is a big part of why managed IT services engagements increasingly build media disposition into the standard device lifecycle rather than treating it as a one-off project. Every drive pulled from service needs an inventory entry the moment it’s removed — serial number, source device, date pulled, and destination (destroy, purge-and-reuse, or return-to-vendor). That inventory entry doesn’t close until there’s a corresponding sanitization or destruction certificate attached to it.
Leased equipment adds a wrinkle that catches contractors off guard. Lease agreements for copiers, servers, and workstations frequently include return clauses that assume the equipment goes back to the leasing company in working condition — which is at odds with a “destroy the drive” policy. The right move is negotiating data destruction language into the lease terms up front, or budgeting for drive replacement at lease-end so you’re not stuck choosing between a contractual obligation and a CMMC requirement. This is a procurement conversation as much as an IT one, and it’s exactly the kind of cross-functional gap a vCIO engagement is built to catch before it becomes a scored finding.
USB Drives and Removable Media: The Control Nobody Enforces
If hard drive sanitization is under-resourced, USB drive control is often nonexistent. Removable media is cheap, ubiquitous, and easy to lose track of, which makes it one of the highest-risk categories in the entire media protection family — not because the sanitization process is technically harder, but because organizations frequently don’t know how many USB drives touched CUI in the first place.
The starting point has to be reducing the attack surface before worrying about sanitization at all. Group policy or endpoint management tooling should restrict USB storage device access to explicitly authorized hardware, ideally encrypted drives issued and tracked by IT rather than personal devices employees bring from home. This connects directly to the broader access control and endpoint hardening work covered under cybersecurity engagements, since unrestricted USB access is as much an exfiltration vector as it is a sanitization headache.
For the drives that are authorized and in circulation, the same lifecycle logic applies as with hard drives: each one gets a unique identifier, an owner of record, and a sanitization event logged the moment it’s retired, lost, or reassigned. Given how frequently small removable media gets misplaced, some contractors find it’s simpler to treat any USB drive as CUI-contaminated by default and require destruction rather than reuse — a stricter posture than the control technically demands, but one that removes the ambiguity that leads to findings.

Printers, Copiers, and the Storage Nobody Thinks About
This is the gap that surprises even security-conscious IT leaders. Modern multifunction printers and copiers aren’t dumb peripherals — they’re networked computers with their own hard drives or flash storage, and every document scanned, copied, or faxed through them gets cached to that storage, sometimes for weeks depending on the device’s configuration. A printer that’s processed drawings, contracts, or technical data containing CUI has effectively become a CUI storage device, whether anyone in the organization thought of it that way or not.
The problem compounds because printers and copiers are almost always leased, refreshed on a different cycle than workstations, and managed by a facilities or procurement contact who has no visibility into CMMC scope at all. We’ve walked into readiness assessments where the client’s entire IT security program was solid, but the printer fleet — sourced through a completely separate vendor relationship — had never been evaluated as an in-scope asset. That’s a scoping failure as much as a sanitization failure, and it’s worth reading through how the five CMMC asset categories actually sort your environment if printers haven’t explicitly been mapped into your asset inventory yet.
Every networked printer or copier that has processed CUI needs to be inventoried the same way a workstation or server would be, with its internal storage sanitized or destroyed before the device leaves your custody — whether that’s an end-of-lease return, a trade-in, or disposal. Many enterprise-grade devices support a hard drive overwrite or “data erase” function built into the administrative firmware; if that feature exists, it needs to be run and documented before the unit leaves the building, not assumed to happen automatically as part of the vendor’s return process.
Chain of Custody: Proving Sanitization Happened
Doing the sanitization correctly is only half the requirement. The other half is being able to prove it happened, on demand, months or years after the fact. Assessors working from 800-171A procedures will ask to see documentation, and “we’re pretty sure we wiped that one” isn’t documentation.
A defensible chain of custody record for media sanitization includes the device or media serial number, the date and method of sanitization (clear, purge, or destroy, with the specific technique used), who performed it, and — for third-party destruction services — a certificate of destruction referencing the specific serial numbers processed in that batch. If you’re using an external e-waste or destruction vendor, that vendor’s certificate needs to tie back to your internal asset inventory by serial number, not just state that “a batch of drives” was destroyed on a given date. Generic certificates that don’t reference specific assets won’t satisfy an assessor asking for evidence tied to a specific device.
This is also where backup media deserves separate attention. Retired backup tapes and drives are subject to the same lifecycle requirements as production storage, and organizations relying on backup and data recovery infrastructure need retention and disposition schedules that explicitly address what happens to backup media once it ages out of the retention window — sanitization and destruction records should be maintained with the same rigor as the backups themselves.
Building a Media Protection Policy That Survives an Assessment
A written policy is the artifact assessors will ask for first, and it needs to do more than restate the control language. An effective media protection policy should specify:
- Which media types are in scope (hard drives, SSDs, USB drives, backup tape, printer and copier storage, mobile device storage)
- The required sanitization method for each media type based on its destination (reuse internally, transfer externally, or destroy)
- Who is authorized to perform or approve sanitization, and what training that role requires
- The documentation and retention requirements for sanitization and destruction records
- How leased equipment returns and third-party destruction vendors are handled contractually
That last point deserves its own emphasis, because it’s where policies written by IT teams alone tend to fall short — they cover workstation and server media well but never touch procurement contract language or facilities-managed equipment like copiers. Building that cross-functional coverage is exactly the kind of gap a co-managed IT arrangement is designed to close, layering compliance-specific process on top of an existing internal team rather than requiring a wholesale rebuild.
Where This Fits Into Your Broader CMMC Program
Media protection doesn’t exist in isolation — it’s connected to how CUI is marked and tracked throughout its lifecycle, which is worth reviewing alongside the complete CUI lifecycle from storage through disposal if your organization hasn’t formally documented that flow. It also intersects with physical security, since a lot of media protection failures are really physical security failures wearing a different label — physical security requirements for protecting CUI cover the access controls that should be preventing unauthorized removal of media in the first place.
It’s also worth checking whether your managed service provider’s role in handling these assets makes them an External Service Provider under CMMC’s definition — a distinction we break down in what counts as an ESP and what that means for your MSP, since sanitization performed by a third party needs to be accounted for in your assessment scope regardless of who physically handles the drive.
Defense manufacturers running production equipment with embedded storage face a version of this problem that’s easy to overlook entirely — CNC controllers, quality inspection systems, and shop-floor terminals often have local storage that never gets evaluated the way a laptop would, a gap worth reviewing if you’re serving the manufacturing sector under a CMMC-scoped contract. Engineering firms handling CAD files and technical drawings carry similar exposure through print servers and plotter devices, relevant to how CMMC touches engineering environments specifically.
Getting media protection right also feeds into a larger truth about defense contracting we’ve covered separately: a stronger cybersecurity posture wins more DoD contracts than a lower bid does. Contracting officers and primes increasingly treat a clean CMMC assessment as a proxy for overall organizational discipline, and media protection gaps are exactly the kind of finding that undermines an otherwise strong submission.

Conclusion
Media protection is unglamorous compared to firewall configurations and endpoint detection, which is precisely why it gets under-resourced until an assessor asks for a sanitization certificate that doesn’t exist. The fix isn’t exotic technology — it’s inventory discipline, a documented method for each media type, and a chain of custody record that ties every retired drive, USB stick, and printer hard drive back to proof that it was sanitized or destroyed before it left your control. Get that process built once, correctly, and it runs quietly in the background for every device refresh and lease return that follows.
If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.
