Mapped to NIST 800-171 Requirement: 3.13.9
CMMC Assessment Objective: SC.L2-3.13.9[a]
What This Control Means
You must clearly identify:
• Where CUI is stored across your systems
• How encryption is applied to protect CUI at rest
• Which tools, methods, or services provide that encryption
This includes internal and portable storage, whether on:
• Hard drives
• SSDs
• Mobile devices
• Cloud environments
• Backup systems
• External media like USB drives or removable disks
Why It Matters
If CUI is left unencrypted at rest:
• Physical theft of devices could expose sensitive data
• Insider threats could access stored CUI without detection
• Cloud misconfigurations could lead to public data exposure
• You’ll fail CMMC Level 2 or DFARS compliance assessments
Encrypting CUI at rest ensures protection even if systems are physically compromised.
How to Implement It
1. Inventory Systems Storing CUI
• Laptops, desktops, servers
• Mobile devices (phones, tablets)
• Cloud storage (e.g., AWS S3, Azure Blob Storage)
• Backup and disaster recovery systems
• Removable media
2. Identify Encryption Methods Used Examples:
• BitLocker for Windows laptops and servers
• FileVault for Mac devices
• AWS S3 server-side encryption
• Encrypted external drives
• Database encryption (e.g., TDE for SQL Server)
3. Document Cryptographic Tools and Protocols
• Note:
◦ Encryption algorithms (AES-256, RSA, etc.)
◦ FIPS 140-2 or FIPS 140-3 validation status
◦ Keys management practices (e.g., centralized key management)
4. Include in Your SSP
• Clearly describe where CUI is stored and how it is encrypted at rest
Evidence the Assessor Will Look For
• Inventory of systems with CUI at rest and their encryption status
• SSP entries describing encryption solutions
• Screenshots of encryption settings on devices or storage services
• System or cloud platform configuration files
• Validation that cryptographic modules meet NIST/FIPS standards
Common Gaps
• Systems store CUI at rest but encryption is not applied
• Encryption used but methods not documented
• Personal devices used for storage without encryption enforcement
• Cloud storage configured without encryption defaults
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Mapping where CUI is stored at rest across your environment
• Documenting encryption tools, protocols, and deployment coverage
• Linking storage assets to cryptographic protections in your SSP
• Verifying encryption compliance against NIST and FIPS standards
• Providing audit-ready evidence of CUI-at-rest protection
With Cuick Trac, encryption of CUI at rest isn’t optional—it’s documented, deployed, and provable.
Final CTA
If your CUI sits still, it should sit encrypted.
Schedule a Cuick Trac demo to identify, document, and protect all your CUI-at-rest with the right cryptography.