StealthTech365

A contractor spends eighteen months hardening firewalls, deploying endpoint detection, and rewriting incident response plans, then fails a Level 2 assessment over a server room door that doesn’t lock and a filing cabinet full of printed drawings sitting in an unlocked conference room. This happens more often than most compliance leads expect, because CMMC readiness programs are built almost entirely around network architecture and identity controls, while the Physical Protection domain gets a single afternoon of attention near the end of the project.

CUI doesn’t only travel across wires. It sits on desks, prints from shared machines, gets discussed in conference rooms with glass walls facing a parking lot, and lives on backup tapes stored in a closet next to the break room. An assessor working through the NIST SP 800-171 control set for Level 2 will walk your facility, not just your network diagram, and the gap between a company’s cybersecurity maturity and its physical security maturity is usually the widest gap in the entire assessment.

Where CUI Actually Lives Inside Your Facility

Most scoping exercises start and end with the network. Teams identify which servers touch CUI, which endpoints connect to the enclave, and which cloud tenant handles email, then call the scoping boundary complete. That approach misses the physical footprint entirely. A defense contractor’s engineering team prints drawings for shop floor reference. A manufacturing client keeps work orders taped to machines. A program manager takes handwritten notes into a status meeting that includes technical data covered under DFARS.

None of that shows up in a network scoping document, but all of it falls inside the CUI boundary the moment it contains covered information. Getting this right starts with the same discipline used for asset categorization under CMMC scoping — except instead of sorting servers and endpoints, you’re sorting physical spaces: which rooms, cabinets, printers, and storage areas ever come into contact with CUI, and which don’t. Skipping this step means your physical security controls end up protecting the wrong rooms while the actual CUI touchpoints go unmanaged.

protect a cyber security from hacker attacks

The Physical Protection Domain: What Level 2 Actually Requires

The Physical Protection family under 800-171 breaks into a handful of specific obligations: limiting physical access to organizational systems, equipment, and operating environments to authorized individuals; escorting visitors and monitoring their activity; maintaining audit logs of physical access; controlling and managing physical access devices; and safeguarding the physical facility and infrastructure supporting organizational systems.

The wording sounds general, but assessors interpret it literally during a Level 2 assessment prepared through CyberAB-registered channels. They want evidence — badge logs, visitor sign-in sheets with escort documentation, a device inventory showing who has keys or access cards to server rooms, and physical safeguards around anything hosting the CUI environment. A written policy stating “visitors must be escorted” without a corresponding log proving it happens is treated the same as having no policy at all. The gap between documented intent and demonstrated practice is exactly where physical security controls tend to fail, in the same way a configuration management program fails when it exists only in someone’s head rather than as a maintained baseline.

Visitor Control and the Escort Problem Nobody Solves Properly

Every contractor we work with has a sign-in sheet at the front desk. Almost none of them can produce evidence that visitors were actually escorted while inside the CUI boundary. A sign-in sheet proves someone entered the building. It says nothing about whether that person walked unsupervised past a server room, a print station, or a conference room with drawings still on the screen from the last meeting.

The fix isn’t complicated, but it requires discipline that most front-office staff aren’t trained to maintain. Visitor badges need to visually distinguish escorted guests from employees. Escort responsibility needs to be assigned to a specific person by name, not “whoever is around.” And that assignment needs to be logged alongside the visit, because an assessor pulling a sample of visitor records expects to match each entry to an escort. Companies that treat this as an administrative afterthought consistently underestimate how much weight assessors put on it, particularly given how frequently supply chain and nation-state actors rely on physical access as an initial foothold, a pattern CISA’s guidance on nation-state cyber threats documents repeatedly across sectors handling sensitive government data.

Badging, Access Logs, and the Audit Trail Assessors Want to See

Badge systems solve half the problem and create a false sense of completeness around the other half. A modern badge reader logs entry events cleanly, but most systems don’t automatically flag when someone’s access privileges should have been revoked, when a badge is used outside normal working hours without a corresponding justification, or when a terminated employee’s credentials remain active past their last day.

This is where physical access control needs to mirror the logic already applied to network account management. Just as a mature program treats audit logging as a retention obligation with a defined timeline rather than a checkbox, physical access logs need the same retention discipline. Assessors will ask how long badge logs are kept, who reviews them, and how anomalies get escalated. A badge system nobody reviews is functionally identical to no badge system, because the control exists to detect unauthorized access, not merely to record it.

Print Stations, Shared Devices, and the CUI That Walks Out the Door on Paper

Digital controls get most of the investment, but paper remains one of the easiest ways for CUI to leave a controlled environment unnoticed. A shared printer in an open area, a fax machine still connected for a legacy customer requirement, or a scanner that automatically emails documents to a personal address all create physical exposure that no firewall rule touches.

A few practices consistently separate contractors who pass this part of the assessment from those who don’t:

  • Printers and scanners handling CUI are physically located inside access-controlled areas, not in open hallways or shared common spaces.
  • Print jobs containing CUI require a badge tap or PIN release at the device itself, so documents don’t sit in an output tray unattended.
  • Shredding and destruction of CUI-marked paper follows a documented process, with cross-cut shredders or a certified destruction vendor rather than standard recycling.
  • Devices that combine print, scan, and fax functionality are inventoried the same way as endpoints, since many of them run embedded operating systems capable of storing document images internally.

Getting the marking and handling requirements right on the front end matters just as much as controlling the output. The National Archives’ CUI Marking Guidance lays out the specific banner and portion marking requirements that apply regardless of whether the document is digital or physical, and a contractor’s complete approach to the CUI lifecycle needs to account for printed material at every stage, not just electronic storage and transmission.

Remote Workers and the Home Office Blind Spot

Physical security gets dramatically harder to enforce once CUI leaves a controlled office and enters someone’s home. A program manager working from a spare bedroom might have a company laptop with full disk encryption and a VPN connection, but a family member walking past an open screen displaying a technical drawing represents exactly the kind of physical exposure the Physical Protection domain is meant to prevent.

This isn’t a hypothetical edge case anymore. Distributed and hybrid arrangements are now standard across the defense industrial base, and protecting CUI in remote and hybrid environments requires physical safeguards that look different from an office setting: privacy screens, locked storage for any printed material, dedicated workspace requirements written into remote work policies, and clear guidance on video call backgrounds during any meeting where CUI might appear on screen. Assessors increasingly ask how a company extends physical protection controls to remote employees, and “we trust our people” is not an acceptable control description.

Concept of internet business security information data

Data Centers, Server Rooms, and Environmental Controls

Even contractors who’ve moved their CUI environment into Microsoft GCC High or another compliant cloud tenant still have physical infrastructure on-premises that falls inside scope — network closets, on-site backup appliances, and any hardware supporting the connection between the local environment and the cloud boundary. Choosing between Microsoft 365 GCC and GCC High reduces some physical security burden by shifting data center responsibility to Microsoft, but it doesn’t eliminate the on-site footprint entirely.

Server rooms and network closets need locking doors with access limited to specific personnel, environmental monitoring for temperature and humidity where equipment could be damaged, and physical safeguards against tampering with switches or backup devices. This overlaps directly with backup and disaster recovery planning, since a backup appliance sitting in an unlocked closet undermines the integrity of the recovery process it’s meant to support. If that hardware can be physically accessed by an unauthorized person, the backup itself becomes an attack vector rather than a safeguard, a risk that compounds the resilience concerns raised in CISA’s broader guidance on organizational and supply chain resilience.

Aligning Physical Security With Your Broader Compliance Program

Physical security controls don’t exist in isolation, and treating them as a separate checklist from the rest of a CMMC program creates duplicated effort and inconsistent enforcement. The same governance structure that manages compliance across frameworks — policy ownership, review cadence, documented exceptions — should extend to physical controls rather than living in a separate binder maintained by facilities staff who’ve never seen the SSP.

This is also where a virtual CIO earns their keep on a compliance-driven account. Physical security decisions have budget implications — badge system upgrades, locked printer stations, secure destruction contracts — and those decisions need to be weighed against the same prioritization framework applied to zero trust architecture rollouts and other technical investments. A contractor treating physical security as an unfunded afterthought discovers the cost of that decision during the assessment, not before it.

Building the Physical Security Plan Assessors Actually Accept

A written physical security plan needs to do more than restate the control language from 800-171. Assessors want to see evidence that the plan reflects the actual facility, not a generic template. A strong plan typically includes:

  • A floor plan or facility diagram identifying every space where CUI is stored, discussed, printed, or transmitted, with access restrictions mapped to each area.
  • A visitor management procedure naming who assigns escorts, how escort assignments are logged, and how visitor badges are physically differentiated from employee credentials.
  • A device inventory covering every badge reader, lock, camera, and access-controlled printer, along with the individual responsible for maintaining each system.
  • A review cycle for badge logs and access lists, with a named owner and a defined frequency — monthly review is common, but the plan needs to state it explicitly rather than leaving it implied.
  • A destruction and disposal procedure for physical CUI, referencing the same marking standards found in the CUI Registry’s category-specific handling requirements.

This plan should live alongside the rest of your compliance documentation, reviewed on the same schedule as your incident response plan and configuration baselines rather than treated as a one-time deliverable produced right before an assessment window opens.

Where MSPs and Internal IT Teams Get This Wrong

Physical security often falls into a gap between the IT provider managing the network and facilities staff managing the building, with neither party clearly owning the intersection between the two. An MSP serving defense contractors needs to treat physical safeguards as part of the shared responsibility model just as seriously as patch management or endpoint monitoring, because an assessor doesn’t distinguish between a network control gap and a physical control gap when scoring the assessment — both are findings against the same organization.

This is also where managed IT services built around a compliance-first framework differ meaningfully from a general-purpose IT provider. Coordinating badge system logs with SIEM correlation, tying physical access events to the same audit retention schedule as network logs, and building destruction procedures into the same lifecycle management used for cloud transformation projects all require a provider who understands the assessment from the assessor’s perspective, not just from a technical implementation perspective.

Cyber security protects against breaches

Conclusion

CMMC assessments fail on physical security findings more often than most compliance programs anticipate, precisely because the effort goes into the network and the assumption is that a locked front door counts as adequate protection. It doesn’t. CUI moves through printers, sits in conference rooms, travels home with remote employees, and lives on backup hardware in closets that rarely get a second look. Closing that gap means treating physical protection with the same documentation discipline, review cadence, and ownership structure applied to every other control family under the DoD’s CMMC Program.

If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.

Scroll to Top