System Security Plan language for NIST 800-171 media protection (3.8.1 to 3.8.9 and 3.7.3)
Vendor-neutral, paste-ready implementation statements for the NIST SP 800-171 media protection family and the off-site maintenance requirement, written for a CMMC self-assessment or C3PAO assessment. Each control block gives the requirement, a first-person implementation statement with bracketed fields, the evidence to keep, and the 800-171A objectives it satisfies. A categorization statement elects the High level for sanitization on grounds an assessor cannot dispute.
Version 1.2, reviewed 2026-09-22. Free under CC BY 4.0. Not legal or assessment advice.
Who it is for
Defense contractors and suppliers writing or updating a System Security Plan under DFARS 252.204-7012 and CMMC, and the consultants who help them. It assumes the organization destroys CUI media rather than wiping and reselling it; if you purge for reuse, the 3.8.3 block has a paragraph for that too.
What is inside
- How to use the document, and why every statement must match what you actually do
- A categorization statement for the SSP's system description: Moderate is the floor under 32 CFR 2002.14(g); the organization elects High for sanitization under 2002.14(a)(2) and 2002.14(f)(2)(ii); methods follow NIST 800-88 and NSA guidance as DCSA's 2022 destruction guidance directs; Rev. 2 applied as the successor to the Rev. 1 DCSA cites
- Ten control blocks: 3.8.1 physical control and storage, 3.8.2 access, 3.8.3 sanitization and destruction, 3.8.4 marking, 3.8.5 transport accountability, 3.8.6 cryptography or physical safeguards in transport, 3.8.7 removable media, 3.8.8 ownerless devices, 3.8.9 backups, 3.7.3 off-site maintenance
- The DCSA contracted-destruction considerations written into 3.8.1, 3.8.3, and 3.8.5
- A supply-chain note for describing the destruction vendor, outside the control statements
- References
The categorization statement, in short
CUI is protected at no less than the Moderate confidentiality impact level, as 32 CFR 2002.14(g) requires. As an internal risk-management decision, the organization applies the High level to the sanitization and destruction of media that has held CUI. This exceeds the floor and is expressly permitted: 32 CFR 2002.14(a)(2) provides that safeguards used for classified information are sufficient for CUI, and 2002.14(f)(2)(ii) accepts any destruction method approved for classified national security information. Methods follow NIST SP 800-88 and NSA media destruction guidance, the references named in DCSA's Guidance for Destroying CUI; where that guidance cites SP 800-88 Rev. 1, Rev. 2 is applied as its successor. The election governs sanitization only and does not alter the categorization assigned by the designating agency.
What 3.8.3 states
Media that has held CUI is not reused outside the organization and is not released for disposal until destroyed: magnetic media degaussed and then shredded or deformed, solid-state media disintegrated to 2 mm or smaller, hybrid boards separated and disintegrated; particle size follows the DCSA principle of reasonable assurance in proportion to confidentiality; destroyed material is mixed before recycling; paper CUI is destroyed to the DCSA and ISOO specification. Destruction is performed by the named vendor on NSA/CSS EPL-listed equipment, witnessed, verified, and validated, with a signed certificate and a serial-level log carrying the SP 800-88 Rev. 2 section 4.6 fields; devices found empty are logged as “none found”; every step from removal to recycling is documented.
How to adapt it
Replace [Organization], [Title], [location], and [destruction vendor] throughout.
Delete any sentence that describes something you do not do; an assessor tests the statement against practice.
Attach the CUI Media Disposal Record and your Media Protection Policy as the evidence the statements cite.
If you purge media for internal reuse, keep the last paragraph of 3.8.3 and list your tools; if you do not, delete it.
Choose Rev. 2 or Rev. 3 numbering to match your assessment scope; both are given.
What it rests on
- 32 CFR 2002.14(a)(2), (f)(2), and (g)Classified safeguards sufficient for CUI; approved destruction methods; Moderate as the floor.
- NIST SP 800-171 Rev. 2 and Rev. 3; NIST SP 800-171AThe requirements and the assessment objectives quoted in each block.
- NIST SP 800-88 Rev. 2Sections 3.1, 4.5, and 4.6.
- DCSA, Guidance for Destroying Controlled Unclassified Information (July 2022); ISOO CUI Notice 2019-03Contracted-destruction considerations, media methods, and paper particle sizes.
- NSA/CSS Policy Manual 9-12 and the Evaluated Products ListsTechnique selection and listed equipment.
Primary sources are linked on the Standards page.
Questions
Does DCSA require the High categorization for CUI?
No. The regulation sets Moderate as the minimum, and DCSA's guidance names methods rather than a categorization. The template states High as the organization's own election, cites the two clauses of 32 CFR 2002 that permit exceeding the floor, and names DCSA's guidance for the methods. That is the defensible way to say it.
Why is the vendor a placeholder?
So the statements can be adopted by any organization with any vendor without editing a name out. A separate supply-chain note at the end shows how to describe your vendor, with example language.
CMMC assessments use Rev. 2 numbering. Why include Rev. 3?
Some organizations have moved their SSP to Rev. 3, and DFARS 252.204-7012 still points at Rev. 2. Both numbers appear in each heading so the block can be filed under either.
More answers on the FAQ.
