Skip to content
ControlVerdict
AC.L2-3.1.19CMMC Level 2Level 2

Encrypt CUI on Mobile

Practice statement

Encrypt CUI on mobile devices and mobile computing platforms.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.19.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and

    1 example covers this

  2. [b]

    encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.19Encrypt CUI on Mobile
    Encrypt CUI on mobile devices and mobile computing platforms.
    • [a]

      mobile devices and mobile computing platforms that process, store, or transmit CUI are identified; and
    • [b]

      encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.

    Encrypt CUI containers on phones; no local unmarked copies

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Encrypt CUI on Mobile objectives.

    Encryption. CUI is opened only in managed apps with encryption-at-rest for app data. Save-as to unmanaged local storage is blocked. Device-level encryption (platform) is required by compliance policy.

    Maintenance. Quarterly confirm Open-in / save-as restrictions still apply after app updates.

    Accepted gap. Offline maps app used in the field cannot be managed; it is banned from devices that have enclave apps installed (separate personal device).

    What the evidence looks like

    • App protection policy showing encrypt / save-as restrictions
    • Device compliance requiring encryption
    • Test of blocked save to unmanaged storage

    Environment

    Intune-managed mobiles accessing labeled SharePoint/OneDrive.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.