Skip to content
ControlVerdict
MP.L2-3.8.3CMMC Level 2Level 2

Media Disposal [CUI Data]

Practice statement

Sanitize or destroy system media containing CUI before disposal or release for reuse.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.8.3.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    system media containing CUI is sanitized or destroyed before disposal; and

    1 example covers this

  2. [b]

    system media containing CUI is sanitized before it is released for reuse.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    MP.L2-3.8.3Media Disposal [CUI Data]
    Sanitize or destroy system media containing CUI before disposal or release for reuse.
    • [a]

      system media containing CUI is sanitized or destroyed before disposal; and
    • [b]

      system media containing CUI is sanitized before it is released for reuse.

    Full-disk encryption plus cryptographic erase; destroy when CE cannot be verified

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all media sanitization objectives for this practice.

    Prerequisite. All in-scope endpoints use full-disk encryption with keys escrowed to the directory/MDM. Removable media that may hold CUI must use hardware-encrypted drives issued by IT; consumer USB is blocked by MDM.

    Decision matrix (SOP).

    • Reuse inside org, CE verified: Cryptographic erase — destroy/wipe recovery keys in escrow, confirm device cannot unlock, then redeploy.
    • Leaving org control, or CE not verified (failed TPM, unknown prior ownership): Physical destruction via approved vendor; certificate of destruction required.
    • Paper / optical: Cross-cut shred to policy particle size; bin logs retained.

    SSD note. Do not rely on a single “quick format.” Prefer CE on encrypted volumes; if a drive was never encrypted under org keys, treat as destroy or vendor purge with verification.

    Maintenance. Asset retirement tickets cannot close without sanitization method, operator, timestamp, and either key-destruction screenshot or CoD attachment. Quarterly sample: pick three retired assets and verify evidence completeness.

    Accepted gap. One CNC controller disk cannot run org FDE. It is air-gapped; at end of life it is always physically destroyed (no CE path).

    What the evidence looks like

    • Media sanitization SOP with 800-88 Clear/Purge/Destroy mapping
    • FDE policy + escrow configuration export
    • Closed retirement tickets with key-destruction proof or CoD
    • USB block MDM profile
    • Quarterly evidence sampling checklist

    Environment

    ~200 endpoints, removable media rare and discouraged; CUI primarily on encrypted volumes.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.