Encrypt CUI on Mobile
Practice statement
Encrypt CUI on mobile devices and mobile computing platforms.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.19.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and
1 example covers this
- [b]
encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.19Encrypt CUI on Mobile
Encrypt CUI on mobile devices and mobile computing platforms.
[a]
mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and[b]
encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.
Encrypt CUI containers on phones; no local unmarked copies
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Encrypt CUI on Mobile objectives.
Encryption. CUI is opened only in managed apps with encryption-at-rest for app data. Save-as to unmanaged local storage is blocked. Device-level encryption (platform) is required by compliance policy.
Maintenance. Quarterly confirm Open-in / save-as restrictions still apply after app updates.
Accepted gap. Offline maps app used in the field cannot be managed; it is banned from devices that have enclave apps installed (separate personal device).
What the evidence looks like
- App protection policy showing encrypt / save-as restrictions
- Device compliance requiring encryption
- Test of blocked save to unmanaged storage
Environment
Intune-managed mobiles accessing labeled SharePoint/OneDrive.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.