Equipment Sanitization
Practice statement
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.7.3.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
MA.L2-3.7.3Equipment Sanitization
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
[a]
equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.
Nothing goes out for RMA until the disk is pulled or cryptographically erased
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses the Equipment Sanitization objective: equipment removed from organizational spaces for off-site maintenance is sanitized of CUI first.
Trigger. Any ticket whose resolution involves equipment leaving our physical control — warranty return, depot repair, lease return, or vendor bench work — is flagged at intake and cannot proceed to shipping without a completed sanitization step. The shipping desk will not release a flagged asset without the signed form, which puts the enforcement point at the door rather than in a policy.
Preferred path: remove the storage. For laptops and servers, the drive is removed and retained. The device ships without storage and the vendor is told so in the RMA notes; every vendor we use accepts this. The retained drive is either reinstalled on return or destroyed at end of life under the media disposal procedure.
Alternate path: cryptographic erase. Where the storage is soldered or the warranty requires it in place, we rely on full-disk encryption under our keys: confirm the device was encrypted, destroy the escrowed recovery key, and record the key destruction. If encryption cannot be confirmed for the full life of the device, cryptographic erase is not accepted and the device is either destroyed or repaired on site.
Copiers and embedded storage. Multifunction devices are the case people forget. Lease returns require the vendor's disk sanitization service with a certificate, or we purchase the drive out of the lease and destroy it ourselves — which is what we now do by default after discovering the scan-to-file cache on a returning unit.
Verification. The sanitization form records the asset tag, the method, the operator, the date, and the verification step (drive photographed out of the chassis, or key destruction confirmed). A second person signs for assets that held CUI.
Maintenance. Quarterly sample of three shipped assets against the form and the shipping record. Annual review of vendor RMA terms to confirm drive retention is still accepted.
Accepted gap. One legacy test instrument stores calibration data in a proprietary module we cannot read or erase. The vendor performs its maintenance on site under escort; the instrument does not leave the building.
What the evidence looks like
- Sanitization SOP covering drive removal, cryptographic erase, and the copier case
- Completed sanitization forms for recent off-site maintenance events
- Shipping desk procedure requiring the signed form before release
- Key destruction record for a cryptographic erase case
- Copier lease return certificate or destruction record
Environment
~200 endpoints plus multifunction copiers. Warranty returns to the laptop vendor and copier lease returns are the main paths by which equipment leaves the building.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.