What Does CMMC Media Protection Require?


Organizations that handle Controlled Unclassified Information need to protect that information even when it moves beyond the systems where it was created. CMMC media protection addresses how physical and digital media containing CUI is accessed, stored, transported, reused, and disposed of.
The scope extends across a substantial contractor ecosystem. A 2026 U.S. Government Accountability Office review reported that the Department of Defense relies on approximately 200,000 defense industrial base companies, many of which use and store sensitive information in their systems. For organizations handling CUI, protection can extend to paper records, USB drives, external storage, backup media, and other formats. Knowing where that information resides and how employees handle it provides a practical starting point for applying the appropriate safeguards.
What Is CMMC Media Protection?
CMMC media protection focuses on preventing unauthorized access to CUI stored on physical or digital media. Media can include paper documents and printouts as well as flash drives, removable hard drives, backup tapes, discs, and other storage devices.
The requirements extend protection beyond computers and networks. When CUI is printed, copied, transferred, or backed up, organizations still need appropriate controls for that information. Businesses working toward CMMC 2.0 Compliance Arizona should account for these media practices as part of their broader compliance preparation.
What Are the CMMC Media Protection Requirements?
CMMC media protection requirements address several stages of media handling. Organizations need to consider where CUI-containing media is kept, who can interact with it, how it moves between locations, and what happens when the media is no longer required.
Physically Control and Securely Store CUI Media
Physical and digital media containing CUI should be stored in areas that prevent unauthorized access. Depending on the media, this can include locked cabinets, controlled storage rooms, or other secured locations. Organizations should also know what media they maintain and who is responsible for it.
Restrict Access to CUI Media
Access should be limited to personnel authorized to handle the information. An employee having access to a workplace or general IT resources does not necessarily mean that person should have access to every document, drive, or backup containing CUI.
Sanitize or Destroy Media
Media should be properly sanitized or destroyed before disposal or reuse when it has contained CUI. Simply deleting files may not adequately remove recoverable information. The appropriate method depends on the media and can include clearing, purging, cryptographic erase, or physical destruction.
This area received updated federal guidance in 2025. In September, NIST published Special Publication 800-88 Revision 2, replacing guidance that had been in place since 2014. The revised publication places greater emphasis on establishing an organization-wide media sanitization program, validating sanitization, and addressing storage in modern environments such as cloud infrastructure.
Mark Media Containing CUI
Applicable CUI markings and distribution limitations help employees recognize protected information and understand handling restrictions. Clear identification also supports consistent procedures when documents or storage devices move between authorized personnel.
Protect Media During Transport
Organizations should maintain control and accountability when CUI media leaves controlled areas. Transportation procedures can address authorized personnel, destination, physical protection, and records showing who is responsible for the media during movement.
Control Removable Media
USB drives and other portable storage devices require defined controls. Organizations should determine which devices are approved, who can use them, and whether unidentified portable storage is permitted on systems processing CUI.
Protect Digital Media During Transport
Digital media containing CUI may require cryptographic protection during transport unless alternative physical safeguards provide the required protection. Encryption should complement appropriate handling procedures rather than replace accountability for the device itself.
Protect Backup Media Containing CUI
CUI remains protected information when copied into backups. Organizations should account for where backups are stored, who can access them, and how their confidentiality is maintained. This consideration also matters when evaluating cloud solutions in Phoenix that may store or process business information.
What Does CMMC Media Protection Look Like in Practice?
A printed CUI document may need controlled access during use, secure storage afterward, and appropriate destruction when no longer needed. A USB drive can require approval, defined ownership, protection during transport, and sanitization before reuse.
The same principles extend to backups and other copies. Consistent procedures matter because CUI can move through several formats during normal operations. Having reliable IT support can help businesses maintain the technical processes that support these controls across systems and devices.
How Can Organizations Manage CUI Media Throughout Its Lifecycle?
Managing media as a lifecycle helps connect individual requirements into a repeatable process. Organizations can identify where CUI exists, establish who is responsible for it, and maintain controls as information moves between formats and locations. A practical approach includes:
Identify: Document where CUI exists across paper records, removable devices, backups, and other storage formats so protected information is not overlooked when applying media controls.
Control: Define who is authorized to access, copy, remove, transport, or otherwise handle media containing CUI and establish responsibilities for each activity.
Protect: Apply physical safeguards and technical protections appropriate to the type of media, where it is stored, and how authorized personnel use it.
Track: Maintain accountability when protected media moves between employees, facilities, or controlled areas so the organization can identify who is responsible for it.
Sanitize: Use approved sanitization or destruction procedures before media is disposed of or reused to prevent CUI from remaining accessible or recoverable.
Organizations using managed IT services in Scottsdale AZ can incorporate these practices into broader technology management rather than treating media protection as a separate activity.
How Should Businesses Prepare for a CMMC Media Protection Assessment?
Assessment preparation should address both implementation and evidence. Organizations may need documentation demonstrating how media is stored, accessed, transported, sanitized, and controlled, along with records showing those procedures are followed.
Relevant evidence can include media protection policies, inventories, access records, sanitization records, transport procedures, removable media controls, and System Security Plan documentation. Companies using IT outsourcing in Phoenix should also understand which responsibilities remain internal and which involve external providers.
Newer workflows deserve the same review. When considering AI Services in Arizona, organizations should determine whether CUI could enter AI-enabled processes and how existing information protection requirements apply before those tools are used.
Strengthen CMMC Media Protection Before an Assessment
Preparation starts with knowing where CUI resides and comparing current media handling practices with applicable CMMC requirements. Gaps may involve physical storage, removable devices, documentation, transport procedures, or evidence showing that established controls are consistently followed.
Blue Fox Group can help organizations evaluate their technology environment, identify areas that require attention, and connect media protection with broader CMMC readiness before an assessment.
FAQ's
Does CMMC Media Protection Apply to Paper Documents?
Yes. CUI printed on paper remains protected information, so organizations need appropriate controls for access, storage, transport, and disposal.
Can USB Drives Be Used With CUI Under CMMC?
Removable media can be subject to organizational restrictions and CMMC requirements. Organizations should define which devices are authorized and how they can be used.
Does CMMC Require Encryption for Removable Media?
Cryptographic protection can be required when digital media containing CUI is transported unless appropriate alternative safeguards satisfy the applicable requirement.
How Should Media Containing CUI Be Destroyed?
The method should make CUI inaccessible and unrecoverable as required. Depending on the media, this may involve approved clearing, purging, cryptographic erase, or physical destruction procedures.
Do CMMC Media Protection Requirements Apply to Backups?
Yes. Backup copies containing CUI require confidentiality protections appropriate to the information they contain.
What Evidence Is Needed for CMMC Media Protection?
Evidence can include policies, media inventories, access records, sanitization documentation, transportation procedures, removable media controls, and relevant system security documentation.








