field note

CMMC physical security requirements for cameras

CMMC physical security requirements for cameras come from NIST SP 800-171 family 3.10. Cameras are not mandated. What 3.10 asks, and how to prove they ran.

2026-09-05

CMMC physical security requirements for cameras are the Physical Protection family in NIST SP 800-171 Revision 2, which CMMC Level 2 assesses as practices PE.L2-3.10.1 through PE.L2-3.10.6. The program does not mandate cameras. It requires you to limit physical access to the systems that hold Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), protect and monitor the facility those systems sit in, escort visitors, keep physical access logs, and manage the keys and readers. Cameras show up as one listed way to do the monitoring. They fail that job when they go dark and nobody can show they were watching.

The CMMC Program itself is 32 CFR part 170. Level 2 is still 800-171 Rev 2, even though NIST later published Rev 3. Assessment objectives come from NIST SP 800-171A (June 2018), which part 170 incorporates by reference.

What 3.10 actually requires

The currently assessed Physical Protection family is six requirements. Only one of them names cameras, and it names them as an example.

Practice800-171 requirementWhat it asksWhere cameras show up
PE.L2-3.10.1Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individualsWho may enter the rooms that hold those systemsLocks, badges, and a list of authorized people. Cameras are not the lock
PE.L2-3.10.2Protect and monitor the physical facility and support infrastructure for organizational systemsThe facility and the cabling, power, and closets that serve the systems are both protected and monitoredThis is the camera job, if the plan uses cameras. Guards and sensors are listed the same way
PE.L2-3.10.3Escort visitors and monitor visitor activityVisitors do not walk the CUI rooms aloneCameras can support monitoring. They do not replace an escort
PE.L2-3.10.4Maintain audit logs of physical accessA record of who entered, at which point, whenBadge logs and sign-in sheets are enough. Footage inherits this job only if video is the log
PE.L2-3.10.5Control and manage physical access devicesKeys, locks, combinations, and card readers are identified, controlled, and managedNot a camera rule
PE.L2-3.10.6Enforce safeguarding measures for CUI at alternate work sitesCUI taken to a government site or a residence still has safeguardsNot a camera catalog for every kitchen table. The system security plan (SSP) defines the site

800-171 Rev 2 discussion for 3.10.2 says monitoring of physical access, including publicly accessible areas, can be accomplished by guards, sensor devices, or video surveillance equipment such as cameras. The CMMC Assessment Guide for Level 2 repeats that discussion and uses cameras at entrances as an example of objectives [c] and [d]: the facility is monitored, and the support infrastructure is monitored. An example is not a mandate. A contractor that can prove guards, sensors, and reviewed access logs, and that documented why cameras were not used, has a 3.10.2 answer. A contractor that wrote “cameras cover the CUI closet” and cannot show those cameras were up is missing the control it claimed.

Level 1 is narrower. It assesses the basic safeguarding requirements in FAR 52.204-21: limit physical access, escort visitors, keep access logs, and manage access devices. It does not include 3.10.2. FCI-only work does not pick up the “protect and monitor the facility” requirement that is where cameras usually land. Do not copy a Level 2 camera program onto a Level 1 contract that never asked for it, and do not skip 3.10.2 on a CUI contract because Level 1 did not mention cameras.

Where cameras land in the plan

CMMC Physical Protection as a chain. Limit who may enter the rooms that hold FCI or CUI. Monitor the facility, which is where cameras live if the plan uses them. Log physical access. A dark camera at a CUI door means the monitoring the SSP claimed is not operating, even when locks and badge logs still exist. CMMC 3.10, if the SSP uses cameras limit 3.10.1 access monitor 3.10.2 cameras escort 3.10.3 visitors log 3.10.4 retain camera dark monitor not operating escort and log have a hole 800-171 names cameras as one way to monitor. It does not require them. a dark camera on a CUI door is a failed 3.10.2, not a facilities ticket
Limit, monitor, escort, log. Cameras do the monitor step when the SSP puts them there. Locks and badge logs can still be perfect while the monitoring control is dark.

Start with scope. 3.10.1 applies to areas that have not been designated as publicly accessible: the rooms, closets, and operating environments that hold the contractor information systems processing FCI or CUI. A lobby camera is not a CMMC physical protection control unless the SSP put that lobby on the path to those systems. A parking-lot dome is the same.

Support infrastructure in 3.10.2 is the other half of that practice: distribution, transmission, and power lines, wiring closets, spare jacks, cabling in conduit. Cameras can watch a closet door. They do not replace a lock on that closet.

If video recording is the method that logs physical access, that footage is the 3.10.4 log. 800-171 does not set a day count. The Assessment Guide says retain access records for the period the company has defined. Write the period in the SSP. Keep the files for that period. Do not quote a 30-day camera rule that does not exist in 3.10.

Visitor monitoring in 3.10.3 can use cameras, guards, or a review of the area after the visitor leaves. The escort is still required. A recording of an unescorted walk is evidence the escort failed.

When the camera is itself in scope

Most CMMC cameras do not process CUI. They watch the room that does. Under 32 CFR 170.19, assets that provide security functions or capabilities to the assessment scope are Security Protection Assets, whether or not they process, store, or transmit CUI. A camera the SSP uses to satisfy 3.10.2 belongs in the asset inventory, in the SSP, and on the network diagram. It is assessed against the Level 2 requirements that are relevant to the capability it provides.

That is why a dark dome is not only a failed monitoring control. It is an in-scope asset that stopped doing the job the SSP assigned it. A camera that shares a segment with CUI systems, or that is reachable from where it should not be, is also a computer on that boundary. Unique credentials, current firmware, valid certificates, and closed management are camera hardening. Treat the device as a computer either way.

A camera that actually processes CUI, for example by recording screens that display it, may be a CUI asset or a Specialized Asset. That is an SSP scoping decision. It does not cancel 3.10.2 for the rooms the camera was meant to watch.

3.10.6 covers CUI at alternate work sites, including residences. The organization may define different safeguards by site type. It is not an instruction to put a dome over a kitchen table.

What you cannot put on a POA&M

32 CFR 170.21 limits which Level 2 practices may sit on a Plan of Action and Milestones. Three Physical Protection practices cannot: PE.L2-3.10.3 (escort visitors), PE.L2-3.10.4 (physical access logs), and PE.L2-3.10.5 (manage physical access devices). If the SSP uses cameras as the visitor-monitoring or access-log method, those cameras have to be working for the assessment. You cannot score them NOT MET and promise a truck next quarter.

DFARS 252.204-7012 still requires implementation of 800-171 Rev 2 on covered contractor information systems. CMMC is how the Department verifies that. A pause in third-party certification does not pause 3.10.

Phase 2 is suspended

CMMC Phase 1, in effect from 10 November 2025 under the published rule, allowed Level 1 (Self) and Level 2 (Self) status in contracts. Phase 2 would have added Level 2 (C3PAO) certification assessments on 10 November 2026.

Department of War memorandum 26-P-1023 (13 July 2026) suspended that Phase 2 transition. During the suspension, requiring activities may designate Level 1 (Self) or Level 2 (Self) only. They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Self-assessment against 800-171 Rev 2, and the annual affirmation in SPRS, remain. Select government-led assessments remain. The 3.10 family does not change because the assessor is currently you.

Procurement for those cameras still has to survive NDAA Section 889 where those rules apply. Named manufacturers in that statute are a poor fit for a CUI closet. MentatNOC’s supported camera brands are Axis, Bosch, and Hanwha.

What assessors and self-assessors ask to see

A C3PAO, DCMA DIBCAC, or a contractor scoring its own SPRS submission walks the same five gates as what auditors actually ask about camera systems. On a CMMC Physical Protection review the requests look like this.

  1. Show the inventory of cameras named in the SSP for 3.10.2, and how you know it is complete. Security Protection Assets belong in that list. A commissioning spreadsheet of every dome on campus is not that list.
  2. For the rooms that hold FCI or CUI systems, show that monitoring was operating on dates in the assessment period. Not a live view today. History. Outages happen. Undetected outages are a NOT MET on 3.10.2[c] or [d].
  3. Show visitor escort and visitor monitoring. Badges and an escort log. Cameras support that story. They do not replace it. This practice cannot sit on a POA&M.
  4. Show physical access logs for the period the SSP defined, identifying the person and the time. If video is the log, that footage has to be retrievable for that period. This practice cannot sit on a POA&M.
  5. Show that keys, locks, combinations, and readers are identified, controlled, and managed. A camera covering the door is not that list. This practice cannot sit on a POA&M.

Timestamps have to be trustworthy. A camera whose clock has drifted makes 3.10.4 logs hard to correlate with a badge event, which is the kind of gap an assessor can spend the rest of the day on.

Doing this across 500 cameras

At one office the SSP is a binder and a known set of closet doors. Across a defense contractor with several plants, a headquarters, and a lab, the CUI rooms multiply, landlord lobby coverage gets confused with the contractor’s own 3.10.2, cameras get added for workplace safety and never enter the Security Protection Asset inventory, and a dark dome on a CUI closet is filed as a facilities ticket. Access logs live in a badge system that does not know which cameras are CMMC controls. The annual SPRS affirmation is current. The operating evidence is not.

MentatNOC keeps per-camera health and inventory current for the devices you put under management, records detections and repairs as they happen, and assembles a period into an evidence pack an organization seeking assessment can hand to a C3PAO, to DCMA DIBCAC, or to its own affirming official. Staged firmware and credential work stay in the same trail. It monitors device health, not video. MentatNOC helps you prove your controls operated. It does not certify anyone, and no platform makes an organization CMMC compliant on its own. The evidence shape is on compliance and proof, and a sample pack runs in the live platform demo.