Skip to content
ControlVerdict
PE.L2-3.10.6CMMC Level 2Level 2

Alternative Work Sites

Practice statement

Enforce safeguarding measures for CUI at alternate work sites.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.10.6.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    safeguarding measures for CUI are defined for alternate work sites; and

    1 example covers this

  2. [b]

    safeguarding measures for CUI are enforced for alternate work sites.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    PE.L2-3.10.6Alternative Work Sites
    Enforce safeguarding measures for CUI at alternate work sites.
    • [a]

      safeguarding measures for CUI are defined for alternate work sites; and
    • [b]

      safeguarding measures for CUI are enforced for alternate work sites.

    Home-office rules for CUI: privacy screen, locked drawer, and no printing

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Alternative Work Site objectives: safeguarding measures for CUI at alternate work sites are defined, and they are enforced.

    Defining the measures. A short addendum to the remote work agreement lists what is required, in language someone can actually follow: work in a room where the screen is not visible from a window or a shared space; lock the screen whenever you step away; use the issued privacy filter in any public or shared setting; keep any printed CUI in the issued lockable pouch or drawer and bring it back to the office for shredding; no printing of CUI at home or at a hotel business center; no personal devices for CUI work; no family members using the work laptop; and no discussing program details on a call where household members or strangers can hear. It also names the alternate work sites contemplated: employee residences, customer sites, and travel.

    Enforcing what technology can enforce. The endpoint carries the same baseline as an in-office device: full-disk encryption, short screen lock, no local administrator, and conditional access that requires a compliant device. Printing to any printer not on the managed print list is blocked, which turns the no-printing rule into a technical control rather than an honor system. Data loss prevention blocks copying labeled files to personal cloud storage or removable media. Because remote access requires a managed device, working from a home desktop is not possible even with valid credentials.

    Enforcing what technology cannot. Signed acknowledgment of the addendum before remote work is approved, and again annually. A short self-assessment at renewal asks about the specific measures — window sightlines, where printed material is kept, who else uses the space. Managers are trained to look for CUI visible in the background during video calls and to raise it privately, which has produced two corrections. Physical spot checks of homes are not performed; we say so rather than implying a control we do not exercise.

    Travel and customer sites. A travel briefing covers hotel rooms and business centers, use of the privacy filter in transit, keeping devices as carry-on, and not leaving equipment in a vehicle. At customer sites, CUI work happens only on our device over our remote access, never on customer-provided equipment.

    Maintenance. Annual re-acknowledgment and self-assessment; review of the addendum whenever the endpoint baseline changes; equipment issued for remote work (filters, pouches, locks) tracked so people actually have the means to comply.

    Accepted gap. We cannot verify the physical environment of a home office. Enforcement leans on technical controls that follow the device plus attestation and manager observation, and the residual risk is documented and accepted by leadership rather than papered over.

    What the evidence looks like

    • Remote work CUI addendum text with the defined safeguarding measures
    • Signed acknowledgments and completed annual self-assessments
    • Endpoint baseline and conditional access policies applied to remote devices
    • Print policy showing the managed printer allow-list
    • Issued equipment record for privacy filters and lockable pouches

    Environment

    Roughly 60% of staff remote at least part of the week, a few engineers regularly working from customer sites and hotels. Nobody has a company-built home office; the rules have to work in a spare bedroom.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.