A locked office door is not enough to prove CMMC Level 2 compliance. I regularly see small contractors protect their space reasonably well, yet struggle to show who had access, when access changed, or how visitors were controlled.
A practical CMMC physical security checklist turns everyday safeguards into evidence an assessor can review. It also keeps physical controls aligned with the systems and rooms that handle Controlled Unclassified Information, or CUI.
Key Takeaways
- CMMC Level 2 maps to the 110 security requirements in NIST SP 800-171 Rev. 2, including six Physical Protection requirements.
- I treat written procedures, access records, and interviews as equally important forms of evidence.
- Small contractors should define the CUI environment before collecting facility evidence.
- Visitor logs, key inventories, access lists, escort records, and training acknowledgments can support a Level 2 assessment.
- Optional practices, such as cameras and alarm monitoring, can strengthen operations but do not replace required control evidence.
Start With the Physical Boundaries of Your CUI Environment
Before I build evidence folders, I identify where CUI is created, received, stored, discussed, or printed. That area may be a dedicated office, a locked records room, a secured cabinet, or a limited set of authorized remote workspaces.
CMMC Level 2 physical protection requirements are found in the 3.10 control family of NIST SP 800-171 Rev. 2. The DoD CMMC program resources help contractors track the current model and assessment expectations.
For a small office, the CUI boundary may include:
- A locked suite entrance and the rooms inside it where staff use CUI systems.
- Locked filing cabinets containing printed technical data, contract records, or export-controlled material.
- Server closets, network cabinets, and storage areas holding backup media.
- Home offices where approved staff handle CUI under documented alternate-worksite rules.
I avoid claiming the entire building is a CUI environment unless it truly is. An overly broad boundary creates more doors, people, rooms, and records to control. A well-defined scope reduces cost and gives assessors a clear story.
Your evidence should show that physical access to CUI is limited, monitored, and managed throughout the employee lifecycle.
A floor plan can help, even if it is simple. Mark controlled rooms, exterior entry points, badge readers, locked cabinets, visitor sign-in areas, and shared spaces. Keep the diagram current when you move offices or change the CUI workflow.
Required CMMC Level 2 Physical Security Evidence
I organize physical security artifacts by the applicable NIST requirement. Each folder should include a policy or procedure, operational records, and proof that staff follow the process.
| NIST Requirement | What You Must Show | Useful Evidence |
|---|---|---|
| 3.10.1 | Physical access to systems, equipment, and operating environments is limited to authorized people | Authorized access list, badge roster, door-code authorization record, facility access procedure |
| 3.10.2 | Physical facilities and systems are protected and monitored | Facility inspection records, maintenance tickets, alarm tests, photographs of secured cabinets or server closets |
| 3.10.3 | Visitors are escorted and visitor activity is recorded | Visitor log, escort procedure, signed visitor rules, sample escort records |
| 3.10.4 | Physical access audit logs are maintained | Badge-reader reports, key sign-out sheets, visitor logs, retained access records |
| 3.10.5 | Physical access devices are controlled and managed | Key inventory, key issuance forms, badge return checklist, lost-key or lost-badge incident record |
| 3.10.6 | CUI is safeguarded at alternate work sites | Remote-work policy, home-office acknowledgment, secure storage instructions, employee training records |
A policy by itself will not carry the assessment. If your policy says a manager approves keys, I expect to see who has keys, when each key was issued, and how you recover them after termination.
Similarly, if your office uses a keypad, record the people authorized to know the code. Change it after a relevant employee departure. Keep the change record, but do not store active codes in the evidence repository.
For badge-controlled offices, retain a current access list and a sample of access audit logs. A small contractor may not need expensive enterprise access-control software. However, the available records must show that access is traceable.
Build an Evidence Package an Assessor Can Follow
I recommend one controlled evidence folder for each physical protection requirement. Name files clearly, include dates, and limit access to the people maintaining compliance records. An assessor should not have to guess whether a spreadsheet is current.
For example, a key inventory can include the key identifier, lock or door location, holder name, issue date, approving manager, return date, and status. Avoid listing a physical address or lock combination when a less sensitive reference will work.
Visitor management deserves special attention because it often breaks down during busy days. Your visitor process should require sign-in, identification of the host, the purpose of the visit, entry and exit times, and an escort where the visitor may enter a controlled area.
A useful physical security evidence package often includes:
- A facility access policy and a CUI area floor plan.
- Current employee, contractor, and vendor access lists.
- Visitor logs with completed entry and exit fields.
- Key, badge, and door-code authorization records.
- Employee termination and offboarding checklists showing access removal.
- Photos of locked CUI storage, server rooms, and restricted entry points.
- Maintenance records for locks, alarms, cameras, or badge readers.
- Physical security incident reports and corrective-action records.
- Training acknowledgments for visitors, staff, and approved remote workers.
Photographs should support a control, not replace records. A photo of a locked filing cabinet proves little if nobody can show who has the key or how the cabinet is used.
Separate Required Controls From Strong Operational Practices
I focus first on what CMMC Level 2 requires. Then I recommend improvements that reduce risk and make evidence easier to manage. This distinction matters when a small business has limited time and budget.
For example, CMMC requires you to protect and monitor physical access to facilities and systems. A lock, access restriction procedure, access records, and periodic review may satisfy the objective. A professionally monitored alarm, camera retention platform, and biometric reader can add protection, but CMMC does not require those products in every office.
The same principle applies to remote work. Requirement 3.10.6 calls for safeguarding CUI at alternate work sites. I document who may handle CUI remotely, where they may store it, and how they prevent household members or visitors from viewing it. A locked cabinet and privacy screen might be appropriate. The right answer depends on your defined environment and contract obligations.
Optional practices can include quarterly key reconciliations, annual door-code changes, alarm testing, camera reviews after incidents, clean-desk checks, and visitor badges with expiration dates. These practices create a stronger operating rhythm, especially where staff wear multiple hats.
Physical evidence also belongs in a wider Small Business IT program. I connect Cybersecurity Services, Endpoint Security, and Device Hardening with facility controls because an unlocked office can defeat otherwise strong technical safeguards.
Tie Physical Security to IT Operations and CUI Workflows
Physical protection cannot sit apart from technology decisions. A workstation holding CUI may be secured by multi-factor authentication, yet it still needs a controlled location, locked storage, and clear rules for visitors.
I include physical requirements in Cloud Infrastructure, Cloud Management, and Secure Cloud Architecture planning. Cloud services reduce the equipment stored onsite, but they do not eliminate printed CUI, laptops, network devices, backup media, or conversations in shared offices.
An Office 365 Migration may change where users access CUI. It can also increase remote access. Therefore, I update alternate-worksite acknowledgments, asset inventories, and remote handling procedures before moving regulated workloads.
The same connection applies to Data Center Technology and Infrastructure Optimization. If you keep a firewall, switch, network-attached storage device, or backup appliance onsite, restrict physical access and document who can reach it.
For firms that support multiple industries, such as Restaurant POS Support or Kitchen Technology Solutions, I separate DoD CUI operations from unrelated customer environments. A shared IT team can support both, but its access and documentation must remain controlled.
Keep the Evidence Current With Simple Review Cycles
Most physical security failures are administrative. Someone leaves, a key stays unreturned, a visitor log misses exit times, or a new storage cabinet never appears on the inventory.
I assign one owner for each record, even when that owner is also the operations manager or security lead. Monthly reviews work well for visitor logs, badge lists, and key records. Review the facility access list after every hire, termination, role change, office move, or reported loss.
A Business Technology Partner can help a small contractor connect compliance records with day-to-day operations. I use Technology Consulting to align physical controls with Managed IT for Small Business, rather than creating paperwork that nobody maintains.
That approach supports IT Strategy for SMBs, Digital Transformation, and Innovative IT Solutions without losing sight of the basics. Tailored Technology Services should fit the actual CUI boundary, staffing model, and contract requirements.
Evidence expectations can vary based on your defined CUI environment, DoD contract requirements, assessment scope, and assessor interpretation. I document the rationale for each control choice so the organization can explain its decisions with confidence.
Conclusion
A dependable CMMC physical security checklist turns routine office habits into defensible proof. I focus on controlled access, visitor oversight, access-device accountability, alternate-worksite safeguards, and records that show each process works.
Physical controls are part of Business Continuity & Security. When access lists, logs, procedures, and training records stay current, a small contractor can face a CMMC Level 2 assessment with evidence that matches its real operations.
Discover more from Guide to Technology
Subscribe to get the latest posts sent to your email.
