Practical guide

How to Perform a Physical CUI Facility Walk-down: 50-Point CMMC Inspection Guide

CUI can be exposed during a meeting even when no file is downloaded or document leaves the room. Learn how defense contractors can protect Controlled Unclassified Information displayed on screens, discussed aloud, written on whiteboards, printed for attendees and temporarily used in conference rooms.

September 28, 2026 CUI Supply resource

How to Perform a Physical CUI Facility Walk-down Before a CMMC or NIST 800-171 Assessment

Your System Security Plan says CUI printers are controlled.

Go look at them.

Your asset inventory says 47 devices are part of the CUI environment.

Find them.

Your visitor procedure says visitors are escorted.

Walk from the front door to engineering and see what a visitor can actually encounter.

Your media-protection procedure says removable media containing CUI is securely stored.

Open the approved storage location.

Your physical-security policy says unauthorized personnel cannot access systems handling CUI.

Stand in the hallway and look at the monitors.

This is the purpose of a physical CUI facility walkdown:

Verify that the real facility matches the documented CUI environment.

For defense contractors, this can be one of the most productive exercises performed before a NIST SP 800-171 assessment or CMMC assessment.

It does not replace a formal cybersecurity assessment.

It does something different.

It exposes the physical gaps that spreadsheets, network diagrams, policies, and SSP narratives can easily miss.

What is a physical CUI facility walkdown?

A physical CUI facility walkdown is a structured inspection of the real-world locations, equipment, media, documents, access points, and workflows through which Controlled Unclassified Information is handled.

The goal is to answer four questions:

1. Where does CUI physically exist or become visible?

2. Who can physically reach or observe it?

3. Do the physical controls match the organization's documented procedures?

4. Can employees tell what they are supposed to do without guessing?

This is not a formal term created by NIST or NARA.

It is a practical implementation method.

And it aligns naturally with what assessors actually examine.

For example, NIST SP 800-171A assessment guidance for Media Protection identifies physical control and secure storage of both paper and digital CUI media as assessment objectives. Potential assessment objects include media-protection policies, storage procedures, access-control procedures, the SSP, media-storage facilities, access-control records, and other relevant evidence.

In other words:

The written procedure matters.

The physical environment matters.

And they should agree.

Why perform a CUI walkdown now?

There are two especially relevant reasons in September 2026.

First, on September 2, ISOO issued ISOO Notice 2026-07, revising Executive Agent guidance for implementation of the CUI Program. The notice says increasing cyber threats, foreign-intelligence collection, and unauthorized-disclosure risks require consistent and comprehensive protection of sensitive government information.

NARA remains the CUI Executive Agent, and 32 CFR Part 2002 establishes government-wide policy addressing designation, safeguarding, dissemination, marking, decontrol, and disposal of CUI.

Second, DoW suspended CMMC Phase II on July 13, 2026, but explicitly kept Phase I self-assessment requirements in place. Its current CMMC guidance says that during the review, the Department is enforcing NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments.

So this is an excellent time to stop thinking only about future certification dates and ask a simpler question:

What would someone physically see if they walked through our CUI environment today?

Who should participate in the walkdown?

Do not make this exclusively an IT exercise.

Physical CUI crosses organizational boundaries.

A useful team may include representatives from:

  • cybersecurity or IT;
  • compliance;
  • facility/security management;
  • engineering;
  • quality;
  • manufacturing;
  • document control;
  • HR or reception;
  • shipping/receiving;
  • executive management.

A small contractor may only need two or three people.

The important part is having someone who understands the documented CUI environment and someone who understands how work actually happens on the floor.

Those are not always the same person.

Before walking: print the asset inventory

Start with the organization's existing inventory.

NIST SP 800-171 Rev. 2 requirement 3.4.1 requires organizations to establish and maintain baseline configurations and inventories of organizational systems, including hardware, software, firmware, and documentation. NIST's discussion says useful hardware inventory information includes manufacturer, device type, model, serial number, physical location, system association, and component owner.

NIST SP 800-171A goes further from an assessment perspective: it asks whether the system inventory is established, includes the required component types, and is maintained throughout the system lifecycle.

For the physical walkdown, bring whatever inventory your organization actually uses.

Then verify it.

Important: an inventory requirement is not a sticker requirement

This distinction matters.

NIST requires an inventory.

It does not say every asset must have one particular commercial barcode label attached to it.

Physical asset labels are an implementation tool.

CUI Supply's CMMC Control Asset Labels are designed to help organizations visually identify assets in categories such as CUI-authorized, VDI-only, restricted, specialized, security-protection, CRMA, and out-of-scope devices.

CUI Supply explicitly distinguishes these inventory labels from SF-902 and Generic SF-905 media labels.

That is the correct way to think about them:

Inventory determines the asset's documented status.

The asset label communicates that status physically.

Do not reverse that sequence.

Stop 1: Begin outside the building

Do not start in the server room.

Start where a visitor starts.

Walk toward the facility.

Ask:

  • Which entrances can someone use?
  • Are employee and visitor entrances different?
  • Are loading docks accessible?
  • Are side doors controlled?
  • Can someone enter production through shipping?
  • Are doors propped open?
  • Can exterior windows expose monitors or documents?
  • Can someone see whiteboards from outside?

The point is not to turn every facility into a fortress.

It is to identify paths that bypass the physical controls described in your procedures.

Stop 2: Walk through reception like a visitor

Now enter the building.

Do not mentally skip to the security process you know is supposed to happen.

Observe what actually happens.

Can a visitor:

  • walk past reception?
  • enter a hallway unnoticed?
  • reach engineering?
  • reach production?
  • see CUI on a receptionist's monitor?
  • see documents on desks?
  • see through glass into controlled workspaces?
  • enter a conference room containing CUI?

NIST SP 800-171 Rev. 2 requirement 3.10.1 requires organizations to limit physical access to organizational systems, equipment, and operating environments to authorized individuals. Its discussion explicitly includes employees, credentialed individuals, and visitors.

Requirement 3.10.3 separately requires organizations to escort visitors and monitor visitor activity.

The walkdown question is:

Does the facility make those procedures practical?

Stop 3: Follow the normal visitor route

Do not inspect only the official controlled room.

Follow the route a customer, vendor, job candidate, delivery driver, maintenance technician, or auditor actually travels.

Look left and right.

What can they see?

Check:

  • computer monitors;
  • printer trays;
  • engineering drawings;
  • production travelers;
  • whiteboards;
  • inspection paperwork;
  • open filing cabinets;
  • parts bins;
  • removable media;
  • conference-room screens.

You may discover that the highest-risk CUI exposure is not inside the controlled room.

It is on the route to it.

Stop 4: Inspect controlled-area boundaries

Now find every location your organization considers physically controlled for CUI purposes.

At each boundary, ask:

Where exactly does the controlled environment begin?

Can an employee tell?

Can a visitor tell?

What changes when someone crosses the boundary?

Is access actually controlled?

Clear physical identification can support the process.

CUI Supply provides CUI Restricted Area Signs and other facility-marking products that can visibly communicate where restricted-access procedures apply.

But remember:

The sign does not create the access restriction.

It communicates a restriction that should already exist in policy and practice.

Stop 5: Compare the asset inventory to the actual room

This is where the walkdown becomes especially valuable.

Pick an area.

Find every:

  • laptop;
  • desktop;
  • monitor;
  • server;
  • printer;
  • scanner;
  • copier;
  • network device;
  • production terminal;
  • test system;
  • CNC controller;
  • external drive.

Then ask:

Is it authorized to process CUI?

Is this device in the inventory?

Is its physical location correct?

Does its documented role match what employees actually use it for?

Who owns it?

Is it VDI-only?

Is it supposed to be out of scope?

If the inventory says a device is in Room 104 and it moved to production six months ago, fix the inventory.

If the inventory says a computer is out of scope but employees routinely download controlled drawings to it, you have discovered a much larger problem.

Stop 6: Look for mystery/ghost devices.

Every facility has them.

The old laptop under a desk.

The spare scanner.

The engineering computer nobody wants to replace.

The test stand running Windows from another era.

The shared shop-floor terminal.

The PC attached to a CNC machine.

The old external drive in a drawer.

Ask:

Can it access CUI?

Does it store CUI?

What is this?

Who owns it?

Is it inventoried?

Why is it here?

A physical walkdown often finds assets that never appear in an architecture diagram because everyone has simply forgotten about them.

Stop 7: Check whether physical asset labels match reality

If your organization uses physical asset classification labels, test them.

Do not simply confirm that stickers exist.

Ask whether the label is true.

A device labeled:

CUI AUTHORIZED

should actually be authorized under the organization's architecture and procedures.

A device labeled:

VDI ONLY

should actually be governed so employees understand and follow the VDI-only workflow.

A device labeled:

CUI RESTRICTED

should not quietly be used to process CUI.

CUI Supply's CUI Authorized Control Asset Labels and CUI Restricted Asset Labels are designed to support visual asset identification and inventory management.

They should reflect the system inventory.

Not contradict it.

Stop 8: Do not confuse asset labels with CUI media labels

This deserves its own checkpoint.

An inventory/control asset label answers:

What role does this asset have in our environment?

A CUI media label answers a different question:

Does this media/device contain or handle CUI requiring identification under our applicable marking procedure?

NARA identifies SF-902 as the CUI media label used for media such as hard drives and SF-903 as the smaller USB-size media label.

CUI Supply's SF-902 CUI Computer and Digital Media Labels include “U.S. Government Property.”

For company-owned equipment where that wording would be inaccurate, CUI Supply offers Generic SF-905 CUI Digital Media Labels without the government-property language.

The physical walkdown should verify that your labels communicate what you actually intend them to communicate.

Stop 9: Inspect label placement

Even the correct label is less useful if nobody can see it.

Check whether labels are:

  • visible;
  • legible;
  • securely attached;
  • placed consistently;
  • not covering serial numbers;
  • not covering vents;
  • not blocking service panels;
  • not placed digitally on the monitor screen itself.

For monitors, labels should be applied to the physical monitor housing or bezel, not rendered as an image on the display.

For laptops, consider a consistent location employees and inventory personnel can quickly find.

For printers, scanners, servers, and equipment, choose a visible physical surface appropriate to the device.

Consistency makes a large facility much easier to understand.

Stop 10: Inspect workstations from the hallway

Do not sit in the employee's chair yet.

Stand where an unauthorized person might stand.

Can you read the monitor?

Can you see the engineering drawing?

Can you see a second monitor through the doorway?

Does the screen face a window?

Can someone waiting for a meeting see CUI?

NIST's physical-protection discussion identifies monitors among the equipment that organizations should physically protect from unauthorized access. It also identifies printers, copiers, scanners, external drives, networking devices, and computing devices.

A technically secure workstation can still have a poor physical sightline.

Stop 11: Sit at the workstation

Now look at the environment from the user's perspective.

Ask the employee:

What CUI does this computer handle?

Can you download files locally?

Can you use USB drives?

Which printer do you use for CUI?

Where do printed documents go when you leave?

What do you do with a bad print?

Where do you store physical CUI overnight?

You are testing whether the real employee workflow matches the written one.

If employees consistently give different answers, that is a process problem even if every computer is correctly configured.

Stop 12: Inspect every CUI printer

Printers deserve special attention because they convert protected electronic CUI into physical media.

For each printer used with CUI, ask:

  • Is it authorized for this use?
  • Is it in the documented environment?
  • Who can physically access it?
  • Can visitors reach the output tray?
  • Can print jobs sit unattended?
  • Is the device clearly distinguishable from non-CUI printers?
  • What happens to misprints?
  • Does the printer contain internal storage?
  • What happens when the device is serviced or replaced?

NIST's physical-protection discussion explicitly lists printers, copiers, and scanners among equipment subject to physical-access considerations.

This is why a printer should be treated as part of the CUI workflow—not office furniture.

Stop 13: Inspect scanners and copiers too

Scanners are easy to overlook because employees think about where the document is going rather than what device it passes through.

Ask:

Is this scanner approved for CUI?

Where does the scan go?

Does the device retain copies?

Who can use it?

Is it connected to email?

Does it have internal storage?

What happens at end of life?

A multifunction printer may simultaneously be:

printer + scanner + copier + network device + storage device.

Your physical inventory should reflect that reality.

Stop 14: Inspect removable media

NIST SP 800-171 Rev. 2 requirement 3.8.1 requires organizations to physically control and securely store system media containing CUI, both paper and digital. NIST's assessment objectives separately examine whether paper and digital media are physically controlled and securely stored.

Open the approved removable-media storage location.

Then look elsewhere.

Check:

  • desk drawers;
  • toolboxes;
  • laptop bags;
  • workbenches;
  • equipment carts;
  • server rooms;
  • quality labs.

Look for:

  • USB drives;
  • external SSDs;
  • external hard drives;
  • CDs/DVDs;
  • memory cards;
  • backup media.

Ask whether each item is accounted for and handled according to the organization's procedure.

Stop 15: Inspect physical CUI documents

Now look for paper.

Not only official drawings.

Look for:

  • printed emails;
  • engineering drawings;
  • specifications;
  • travelers;
  • inspection records;
  • handwritten notes;
  • meeting notes;
  • draft documents;
  • test results;
  • printed screenshots.

If the information contains CUI, the physical handling process matters.

NARA explains that an approved SF-901 cover sheet can identify CUI, alert observers that CUI is present, and act as a shield against inadvertent disclosure. If an agency chooses to use a coversheet, the approved form is SF-901.

CUI Supply provides SF-901 CUI Cover Sheets for organizations incorporating those cover sheets into their physical-document procedures.

Again:

SF-901 does not create CUI.

It helps identify and shield CUI that already exists.

Stop 16: Open the approved CUI storage location

Do not just ask whether one exists.

Inspect it.

NIST's Rev. 2 media-protection requirement specifically calls for physical control and secure storage of paper and digital media containing CUI.

Ask:

  • Is the storage actually used?
  • Who has access?
  • Is it locked when required?
  • Are keys controlled?
  • Is unrelated material mixed in?
  • Are employees leaving documents elsewhere because the approved cabinet is inconvenient?

Sometimes the official CUI cabinet is pristine because nobody uses it.

That is not necessarily good news.

Stop 17: Walk the manufacturing floor

Manufacturing environments often expose the difference between cybersecurity diagrams and physical reality.

Look at:

  • CNC controllers;
  • work instructions;
  • travelers;
  • inspection stations;
  • quality terminals;
  • test equipment;
  • shared shop computers;
  • printed drawings;
  • parts bins.

Ask where controlled technical information enters the process and where it leaves.

Does a controlled drawing travel with the part?

Is it covered?

Does an old revision get destroyed?

Can a visitor walking the aisle see it?

Does a CNC controller or any other production device retain controlled files?

These are physical-CUI questions even when the underlying information originated electronically.

Stop 18: Inspect server rooms and network equipment

NIST's physical-protection discussion specifically includes networking devices and supporting infrastructure.

Check:

  • server-room doors;
  • network closets;
  • spare network jacks;
  • switches;
  • routers;
  • racks;
  • backup devices;
  • physical access credentials.

Ask whether the physical access restrictions match the organization's documented policy.

A server room with a sign but an unlocked door tells a very different story from the SSP.

Stop 19: Check conference rooms

We recently covered CUI meetings in detail, but conference rooms belong in the walkdown because they are often forgotten between meetings.

Look for:

  • CUI left on whiteboards;
  • documents under notebooks;
  • abandoned handouts;
  • CUI still displayed on screens;
  • sticky notes;
  • flip charts;
  • windows facing uncontrolled spaces.

Then ask:

Could the next person scheduled to use this room safely walk in right now?

That is an excellent physical-security test.

Stop 20: Inspect trash, recycling, and destruction points

Go to the trash cans.

Go to recycling.

Then go to the approved CUI destruction collection point.

Look inside where appropriate under organizational procedures.

Are employees using the right one?

Is the secure destruction container clearly identifiable?

Is it protected from accessing or tampering with contents?

Are misprints appearing in ordinary trash or recycling?

A perfect written destruction procedure does not matter much if employees are throwing controlled drawings into the closest blue bin.

Stop 21: Check shipping and receiving

Shipping departments often sit outside the cybersecurity conversation but can handle:

  • controlled documentation;
  • technical paperwork;
  • returned equipment;
  • removable media;
  • parts associated with controlled programs.

Ask:

What happens when CUI arrives here?

How does shipping recognize it?

Who gets contacted?

Where is it held?

Can delivery drivers access controlled paperwork?

Physical CUI can enter or leave a facility through the loading dock just as easily as through engineering.

Stop 22: Check repair and quarantine areas

Where does broken equipment go?

An old CUI-authorized laptop may leave engineering and sit for two weeks on an IT repair shelf.

A printer may be staged for vendor pickup.

A hard drive may be placed in an electronics recycling box.

A CNC controller may wait for an outside technician.

The equipment has changed location.

The information risk may not have changed.

Make sure repair, surplus, quarantine, and disposition locations are included in the physical CUI workflow.

Stop 23: Ask about after-hours access

Who enters the facility after employees leave?

Potential examples:

  • cleaning crews;
  • security contractors;
  • HVAC technicians;
  • maintenance personnel;
  • facilities staff;
  • construction contractors.

Then inspect what CUI remains exposed overnight.

A workspace that is effectively controlled from 8:00 AM to 5:00 PM may operate very differently at 10:00 PM.

Stop 24: Test the employee challenge process

During the walkdown, ask several employees a simple hypothetical:

“Someone you don't recognize walks into this controlled area without an escort. What do you do?”

The exact response should follow organizational policy.

What matters is whether employees know it.

Signs, badges, and floor markings work best when employees understand what action the visual cue is supposed to trigger.

Stop 25: Photograph findings—not CUI

Documentation helps.

But be careful.

Do not create an uncontrolled collection of CUI photographs while documenting physical-security findings.

A safer walkdown record may use:

  • asset ID;
  • room number;
  • finding category;
  • description;
  • responsible owner;
  • due date;
  • remediation status.

If photographs are needed and they contain CUI, they must be captured and handled through an authorized workflow.

The audit itself should not create a new information-handling problem.

The 50-Point Physical CUI Facility Walkdown Checklist

Use this as the practical inspection sheet.

Facility perimeter and entry

  1. Are all normal entry points known?
  2. Are secondary entrances controlled appropriately?
  3. Can exterior windows expose CUI?
  4. Can loading docks bypass visitor controls?
  5. Are doors being propped open?

Reception and visitors

  1. Is there a defined visitor entry process?
  2. Can visitors bypass reception?
  3. Are visitors identified?
  4. Are escort procedures understood?
  5. Can visitors see CUI from waiting areas?

Controlled areas

  1. Are controlled-area boundaries clearly understood?
  2. Do signs match actual access policy?
  3. Are secondary entrances addressed?
  4. Can visitors accidentally enter?
  5. Are temporary CUI areas handled consistently?

Asset inventory

  1. Can inventoried devices be physically located?
  2. Do physical locations match inventory records?
  3. Are unknown or legacy devices present?
  4. Do device roles match documented CUI authorization?
  5. Are inventory records updated when equipment moves?

Asset and media identification

  1. Do asset labels match documented device status?
  2. Are CUI media labels used according to organizational procedure?
  3. Are labels legible?
  4. Are labels placed consistently?
  5. Are company-owned assets free of inaccurate ownership markings?

Workstations

  1. Can unauthorized people see monitors?
  2. Are VDI-only endpoints clearly understood by users?
  3. Are physical documents left exposed?
  4. Do employees know which systems may handle CUI?
  5. Are unattended workstations protected according to policy?

Printers, scanners, and copiers

  1. Are CUI-authorized printers known?
  2. Can unauthorized people reach output trays?
  3. Are scanners included in the documented environment?
  4. Are misprints handled correctly?
  5. Is internal device storage considered?

Media and documents

  1. Is removable media physically controlled?
  2. Is CUI media securely stored?
  3. Are paper documents appropriately controlled?
  4. Are handwritten notes considered?
  5. Are manufacturing travelers included?

Manufacturing and infrastructure

  1. Are CNC and production terminals accounted for?
  2. Are inspection stations physically protected?
  3. Are server/network rooms appropriately restricted?
  4. Are repair and maintenance areas included?
  5. Are old devices awaiting disposition controlled?

Destruction and after-hours operations

  1. Is CUI kept out of normal trash/recycling?
  2. Is the approved destruction location obvious?
  3. Is CUI protected while awaiting destruction?
  4. Are after-hours personnel considered?
  5. Does the real facility match the SSP and written procedures?

Do not treat 50/50 as a compliance score.

This is a gap-discovery checklist, not an official CMMC scoring methodology.

One serious finding can matter far more than ten minor ones.

Turn findings into a remediation register

Do not finish the walkdown with a notebook full of observations.

Convert each real finding into an actionable record.

A useful format is:

Location

Engineering Room 204

Asset / Process

Shared printer

Finding

CUI output accessible from uncontrolled hallway

Applicable Procedure / Requirement

Physical-access / media-handling procedure

Action

Relocate printer or implement appropriate access control

Owner

IT / Facilities

Target Date

Organization-defined

Evidence of Completion

Updated layout, procedure, inventory record, configuration or approved photograph

This creates a bridge between the physical inspection and the formal compliance program.

Prioritize findings by exposure, not appearance

A faded sticker may need replacement.

But an unauthorized printer containing CUI is more important.

A crooked restricted-area sign may look unprofessional.

But a side door bypassing visitor controls is more important.

A useful prioritization sequence is:

First: actual unauthorized access or disclosure pathways.

Second: CUI on systems or media outside the documented environment.

Third: missing physical controls or storage.

Fourth: inconsistent procedures and employee behavior.

Fifth: visual identification and standardization improvements.

Physical markings matter because they make controls easier to operate.

They should not distract from the underlying control.

Where physical CUI products fit after the walkdown

The walkdown may identify places where better visual controls would genuinely improve the environment.

For example:

Finding: Employees cannot distinguish CUI-authorized computers from general systems.

Possible implementation tool: CUI Authorized Control Asset Labels.

Finding: Contractor-owned devices need visible CUI identification without implying U.S. Government ownership.

Possible implementation tool: Generic SF-905 CUI Digital Media Labels.

Finding: Government-owned media requires standardized identification.

Possible implementation tool: SF-902 CUI Media Labels where appropriate under the organization's applicable procedure.

Finding: Employees routinely expose printed CUI.

Possible implementation tool: SF-901 CUI Cover Sheets.

Finding: Controlled-area entrances are unclear.

Possible implementation tool: CUI Restricted Area signage.

Finding: Employees cannot distinguish device scoping roles.

Possible implementation tool: CMMC Control Asset Labels.

The sequence matters:

Find the problem → determine the required control → implement the control → use physical products where they make that control clearer.

Not:

Buy products → look for places to stick them.

What should you be able to answer after the walkdown?

At the end, your team should be able to answer:

Where can CUI physically appear in this facility?

Which systems can process, store, transmit, display, or access it?

Which physical media can contain it?

Which printers and scanners are part of the workflow?

Where are controlled areas?

Who can enter them?

How are visitors handled?

Where is physical CUI stored?

Where does unwanted CUI go?

How are devices handled when they leave service?

Does the asset inventory match reality?

Do employees understand the physical system?

If those answers are clear, the facility becomes much easier to defend, operate, explain, and assess.

Mandatory Requirements vs. Physical Best Practices

Keep this distinction clear during remediation.

NIST SP 800-171 Rev. 2 includes requirements such as maintaining system inventories, physically controlling and securely storing media containing CUI, limiting physical access to systems and operating environments, escorting visitors, maintaining physical-access records, and controlling physical-access devices.

NARA separately provides government-wide CUI policy, marking resources, approved forms such as SF-901, and standardized media labels such as SF-902 and SF-903.

Physical implementation practices may include:

  • color-coded asset classifications;
  • barcode asset tags;
  • workstation labels;
  • floor markings;
  • restricted-area signs;
  • visitor badge colors;
  • printer-station identification;
  • destruction-container signs;
  • standardized label placement.

Those practices can make the required safeguards much easier to implement consistently.

But do not describe a commercial product or locally chosen visual convention as federally mandatory unless the authoritative requirement actually makes it mandatory.

That precision makes a CUI program more credible.

Frequently Asked Questions

What is a CUI facility walkdown?

A CUI facility walkdown is a practical inspection of the physical places, systems, media, documents, access points, and workflows through which CUI is handled. It is not an official NIST assessment type; it is a useful way to verify that the real facility matches documented CUI procedures.

Does CMMC require a physical facility inspection?

Applicable NIST SP 800-171 requirements include physical protection, media protection, system inventory, visitor controls, and other safeguards that can involve physical systems, spaces, and evidence. Assessment guidance can include examination, interviews, and testing of relevant processes and objects. A “facility walkdown” is a practical preparation method, not a separately named universal requirement.

Does NIST 800-171 require an asset inventory?

Yes. Revision 2 requirement 3.4.1 requires organizations to establish and maintain baseline configurations and inventories of organizational systems, including hardware, software, firmware, and documentation.

Does NIST 800-171 require barcode asset labels?

No universal requirement says the inventory must be implemented with a particular barcode sticker. Physical asset tags are an implementation tool that can make inventory, device identification, and scoping easier.

Should every CUI device have an SF-902 label?

Not automatically. NARA identifies SF-902 as a standardized CUI media label for media containing CUI, such as hard drives. Organizations should follow applicable agency, contract, ownership, and internal marking procedures rather than assuming every device receives the same label.

What is the difference between an asset label and an SF-902/SF-905-style media label?

An asset label can communicate a device's inventory or scoping role, such as CUI-authorized, VDI-only, restricted, or out of scope. A media label identifies CUI media or equipment according to the organization's applicable marking process. They solve related but different problems.

Should monitors receive CUI labels on the screen?

Physical labels should be applied to the monitor housing, bezel, back, or another suitable physical surface—not digitally placed over the display itself.

Should printers and scanners be included in a CUI walkdown?

Yes. NIST's physical-protection discussion specifically identifies printers, copiers, scanners, monitors, external drives, networking devices, and computing devices as examples of equipment relevant to physical access protection.

Should removable media be checked physically?

Yes. NIST SP 800-171 Rev. 2 requires physical control and secure storage of system media containing CUI, including paper and digital media.

Is SF-901 required on every physical CUI document?

No universal rule requires an SF-901 on every physical CUI document. NARA says agencies may use an approved coversheet to identify CUI, alert observers, and shield it from inadvertent disclosure; when an agency chooses a CUI coversheet, it uses the approved SF-901.

How often should a contractor perform a physical CUI walkdown?

There is no universal federal rule prescribing a specific “CUI walkdown” interval. A practical approach is to perform one periodically and after meaningful facility, system, equipment, workflow, or access changes, consistent with the organization's risk management and assessment processes.

Walk your facility. Find the physical gaps. Then make the correct CUI workflow obvious.

CUI Supply provides standardized physical tools for CUI asset identification, media marking, document protection, controlled-area identification, visitor control, printer workflows, and facility-wide implementation—helping defense contractors turn documented CUI safeguards into physical processes employees can actually follow.

Explore CMMC Control Asset Labels, browse CUI media labels, or view the complete CUI Supply catalog.