Practical Defense
Backups: The Control Nobody Documents Until They Need It
Missing the mark on backup compliance can mean failing audits or losing contracts. You need to show that your backups protect Controlled Unclassified Information and that restoration actually works. The MP.L2-3.8.9 control spells this out, yet documentation in this area often falls short in defense compliance efforts.
What does MP.L2-3.8.9 actually require for backup compliance?
MP.L2-3.8.9 requires you to protect the confidentiality of CUI at rest, specifically in backups. This means any backup containing CUI must have security controls that meet NIST SP 800-171 Rev 2 requirements. Your backup system must ensure that only authorized users can access the backup data and that the data is protected from unauthorized disclosure.
The CMMC Scoping and Assessment Guide Level 2 v2.13 makes it clear: all CUI assets must be covered by all 110 controls, including backup protection. Security Protection Assets, such as backup servers or storage, are assessed against controls relevant to their capability, which includes MP.L2-3.8.9 if they store CUI.
How do you prove you meet backup compliance requirements?
Having a backup is not enough. To meet MP.L2-3.8.9, you must document how you protect CUI in backups and be able to demonstrate, with evidence, that your process actually works.
The NIST SP 800-171A assessment guide breaks this down into assessment objectives. You need to show:
- You have documented policies and procedures for backing up CUI.
- Your technical controls (such as encryption and access restrictions) actually protect backup data.
- You can produce timestamped, system-generated evidence that backups are being created and protected as described.
- Most importantly, you must be able to demonstrate a successful restore of CUI from backup, to prove that your process works in practice.
Documentation alone is not proof. You need real, timestamped artifacts from your backup system and, ideally, records of a recent restore test.
Why is backup compliance so often missed in self assessments?
Most organizations focus on the existence of backups, not their protection or their ability to restore. According to the CMMC Scoping and Assessment Guide, fewer than half of Level 2 companies have completed their System Security Plan (SSP) or Plan of Action and Milestones (POA&M) documentation. The average SPRS score across the defense industrial base is about 60 out of the required 110, reflecting widespread gaps in meeting all assessment objectives, including those related to backups.
When you self-assess, it is easy to check a box for "backups exist" without going deeper. However, the current enforcement model places all the risk on the affirming senior official. With third-party CMMC certification suspended as of July 2026, your self-assessment and the evidence you keep are the only assurance the government has. This increases False Claims Act exposure for anyone who overstates their compliance, rather than reducing it.
What evidence do you need to show backup compliance?
To be ready for a government-led assessment or a False Claims Act inquiry, you should be able to produce:
- Your backup policy and procedures, showing intent and method.
- System-generated evidence that CUI backups are created, protected, and retained as required.
- Access control records showing only authorized users can access backup data.
- Evidence that CUI in backups is encrypted or otherwise protected at rest.
- Logs or reports from recent restore tests, showing that you can recover CUI from backup.
If your backup system cannot provide this evidence, or if your documentation does not match your technical reality, you are not meeting the MP.L2-3.8.9 requirement.
How does backup compliance fit into NIST SP 800-171 and CMMC self assessments?
Backup compliance is one of the 110 controls required for Level 2 under NIST SP 800-171 Rev 2. Self assessments must address every assessment objective for each control, as described in NIST SP 800-171A. If you cannot produce evidence for every objective, that control is not "MET" and your SPRS score must reflect the gap.
Since the Department of War suspended the third-party CMMC certification requirement in July 2026, enforcement relies on your self assessment, your SPRS score, and the annual affirmation by a senior official. This makes your documentation and evidence chain even more critical. The government can and does pursue False Claims Act cases for companies that falsely claim compliance, as seen in the Health Net Federal Services and MORSECORP cases. These cases involved failures to meet required controls and missing documentation.
For more on current requirements, see the NIST SP 800-171 Rev 2 publication.
Common questions
Do I need to encrypt all my backups for backup compliance?
MP.L2-3.8.9 requires you to protect the confidentiality of CUI at rest, which usually means encryption, but you could use other technical controls if they provide equivalent protection. The key is to document your method and prove it works.
Is a backup policy enough to meet MP.L2-3.8.9?
No. A policy only states your intent. You must also have procedures that describe how you perform backups, and you must produce evidence, such as system logs and restore test results, that show you are following your process.
If I outsource my backups, am I still responsible for backup compliance?
Yes. Even if a third party manages your backups, you are responsible for ensuring that CUI is protected and that you can provide evidence of compliance with MP.L2-3.8.9.
How Can You Strengthen Your Backup Compliance
If you are unsure whether your backup process meets all the requirements of MP.L2-3.8.9, now is the time to review your policies, procedures, and evidence. Remember, your self assessment and the evidence you keep are your only assurance if the government asks for proof.
If you are a qualifying defense contractor, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services. This assessment covers all 110 NIST SP 800-171 controls, including backup compliance, to help you identify and close any gaps before your next self assessment or government review. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.