CUI Encryption
Practice statement
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.13.11.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
FIPS-validated cryptography is employed to protect the confidentiality of CUI.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
SC.L2-3.13.11CUI Encryption
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
[a]
FIPS-validated cryptography is employed to protect the confidentiality of CUI.
Org-approved crypto module list; BitLocker and TLS configured to approved modes
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses all FIPS-validated cryptography objectives claimed for in-scope systems in this pattern.
Approved modules. Maintain an inventory of cryptographic modules in use (OS FDE, TLS libraries on reverse proxies, VPN) with FIPS 140-2/140-3 validation references where the org asserts FIPS mode. Engaging a new crypto product requires security review against this list.
Endpoint. BitLocker with XTS-AES; group policy / MDM sets encryption method and requires TPM+PIN or TPM+password for boot where policy demands. FIPS mode enabled for CUI devices when required by contract; test pack validates that banned algorithms are refused.
In transit. External TLS terminators require TLS 1.2+ with an approved cipher suite list; TLS 1.0/1.1 disabled. VPN uses approved IPsec/IKE suites only.
Maintenance. Quarterly check that module versions still match CMVP certificates (or plan upgrade). After OS feature updates, re-run the crypto test pack on a canary ring before broad rollout.
Accepted gap. One vendor SaaS used for proposals does not offer a customer-controlled FIPS mode. CUI is not stored there; contracts language and DLP block CUI upload to that tenant.
What the evidence looks like
- Crypto module inventory with validation refs / config baselines
- BitLocker / MDM encryption settings export
- TLS configuration scan output (cipher suites)
- VPN crypto proposal config
- SaaS exception with compensating control
Environment
Windows endpoints + cloud SaaS; cryptography used for FDE, TLS in transit, and VPN.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.