Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Practical Defense

Media Protection: The Cheapest Control to Fail

Media sanitization means removing data from storage devices so it cannot be recovered. NIST SP 800-171 requires this if you manage Controlled Unclassified Information. One overlooked hard drive or lost USB stick can undermine all your other security measures. This is often the easiest control to miss and the most obvious when a mistake happens.

What does the Media Protection (MP) family require?

The MP family in NIST SP 800-171 Rev 2 includes nine Level 2 practices. These controls focus on how you manage physical and digital media containing CUI. The requirements cover marking, transport, access, reuse, disposal, and especially the sanitization of media before it leaves your control.

Marking means labeling media that contains CUI so anyone handling it knows exactly what it is. Transport covers how you move media between locations or send it offsite. Sanitization is the process of securely erasing or destroying media so CUI cannot be recovered.

If you are a defense contractor subject to DFARS 252.204-7012, you are required to implement all nine MP controls if you handle CUI. This is enforced through self-assessment, SPRS score posting, and annual senior official affirmation, even with the CMMC third party certification requirement currently suspended.

Why is media sanitization so important for compliance?

Media sanitization is the last line of defense against accidental CUI leaks. If a hard drive, USB stick, or backup tape leaves your building without being wiped, everything else you do to protect CUI can be undone in an instant.

NIST SP 800-171 Rev 2 requires that you sanitize or destroy media before disposal or release for reuse, so that CUI cannot be reconstructed. Failing to do this is not a technical gap, it is a visible, physical failure that exposes your organization to False Claims Act risk if you have certified compliance. As recent False Claims Act cases show, the government is willing to pursue contractors and even their ownership for inadequate control execution, including missing or incomplete implementation of 800-171 controls.

How do you mark, transport, and sanitize media that contains CUI?

You must have a documented process that covers:

  • Marking all media containing CUI clearly so it is never mistaken for non-sensitive data.
  • Physically protecting and controlling access to CUI media at all times.
  • Securely transporting media, whether across the building or to another site, to prevent unauthorized access or loss.
  • Sanitizing (securely erasing) or destroying media before it is disposed of, reused, or leaves your environment.

Your policy should define your intent. Your procedures must describe exactly how you achieve this, step by step. Actual system-generated records, such as logs of media sanitization, transport forms, or destruction certificates, are the evidence that proves you are following your process.

What happens if you fail media sanitization?

If a drive or device containing CUI leaves your facility unwiped, you have failed a core NIST SP 800-171 requirement. This is an easy gap for a government assessor or whistleblower to spot. The controls in the MP family are directly observable and not easy to explain away with technical complexity.

When you submit your annual self-assessment and senior official affirmation, your signature is the only assurance the government has. With third party CMMC certification suspended, this increases your exposure under the False Claims Act for any inflated or inaccurate claims about your compliance.

What evidence do you need to prove you are sanitizing media?

It is not enough to have a policy or checklist. You must keep real, timestamped records showing:

  • Which devices or media were sanitized or destroyed.
  • When the process happened.
  • Who performed or witnessed the sanitization or destruction.
  • How the process was carried out (for example, using a specific wiping tool or a physical shredder).

This evidence will be requested during a government-led assessment or if your compliance is challenged. Documentation alone is not enough, actual execution, backed by records, is required.

How do you scope media protection requirements in your environment?

Under CMMC scoping guidance, only assets considered CUI Assets are assessed against all 110 controls, including all MP practices. Security Protection Assets and Specialized Assets may have limited requirements, but if CUI ever touches a device, it is in scope for full media protection controls.

This means that any computer, server, or portable device that stores or processes CUI must be covered by your media protection procedures. Out of Scope Assets are not assessed, but you must be able to justify their separation with diagrams and user lists.

Common questions

What is media sanitization under NIST SP 800-171? Media sanitization is the process of securely erasing or destroying media so that CUI cannot be reconstructed or recovered, as required by NIST SP 800-171 Rev 2.

Do I need to mark every USB drive and hard drive that contains CUI? Yes, all media containing CUI must be clearly marked so that it is not mistaken for non-sensitive data.

What kind of records should I keep for media sanitization? You should keep timestamped records identifying the media, the sanitization or destruction process used, and the personnel involved.

Where to find more information

For official guidance on media protection and sanitization, see NIST SP 800-171 Rev 2.

How Should Defense Contractors Secure Media

Media sanitization is one of the simplest but most critical controls in NIST SP 800-171. It only takes one misstep to fail this requirement and undermine your compliance posture. If you are unsure whether your media protection processes are sufficient or want a clear picture of your overall readiness, consider applying for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more or apply at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

More on Defense

Defense · 5 min MFA: What Actually Satisfies IA.L2-3.5.3

Understand what counts as multifactor authentication CMMC compliance, why SMS is weak, and how to meet requirements for privileged and non-privileged accounts.