Home
Training & Education
How to Perform a Physical CUI Facility Walk-down: 50-Point CMMC Inspection Guide
Practical guide
CUI can be exposed during a meeting even when no file is downloaded or document leaves the room. Learn how defense contractors can protect Controlled Unclassified Information displayed on screens, discussed aloud, written on whiteboards, printed for attendees and temporarily used in conference rooms.
Your System Security Plan says CUI printers are controlled.
Go look at them.
Your asset inventory says 47 devices are part of the CUI environment.
Find them.
Your visitor procedure says visitors are escorted.
Walk from the front door to engineering and see what a visitor can actually encounter.
Your media-protection procedure says removable media containing CUI is securely stored.
Open the approved storage location.
Your physical-security policy says unauthorized personnel cannot access systems handling CUI.
Stand in the hallway and look at the monitors.
This is the purpose of a physical CUI facility walkdown:
Verify that the real facility matches the documented CUI environment.
For defense contractors, this can be one of the most productive exercises performed before a NIST SP 800-171 assessment or CMMC assessment.
It does not replace a formal cybersecurity assessment.
It does something different.
It exposes the physical gaps that spreadsheets, network diagrams, policies, and SSP narratives can easily miss.
A physical CUI facility walkdown is a structured inspection of the real-world locations, equipment, media, documents, access points, and workflows through which Controlled Unclassified Information is handled.
The goal is to answer four questions:
1. Where does CUI physically exist or become visible?
2. Who can physically reach or observe it?
3. Do the physical controls match the organization's documented procedures?
4. Can employees tell what they are supposed to do without guessing?
This is not a formal term created by NIST or NARA.
It is a practical implementation method.
And it aligns naturally with what assessors actually examine.
For example, NIST SP 800-171A assessment guidance for Media Protection identifies physical control and secure storage of both paper and digital CUI media as assessment objectives. Potential assessment objects include media-protection policies, storage procedures, access-control procedures, the SSP, media-storage facilities, access-control records, and other relevant evidence.
In other words:
The written procedure matters.
The physical environment matters.
And they should agree.
There are two especially relevant reasons in September 2026.
First, on September 2, ISOO issued ISOO Notice 2026-07, revising Executive Agent guidance for implementation of the CUI Program. The notice says increasing cyber threats, foreign-intelligence collection, and unauthorized-disclosure risks require consistent and comprehensive protection of sensitive government information.
NARA remains the CUI Executive Agent, and 32 CFR Part 2002 establishes government-wide policy addressing designation, safeguarding, dissemination, marking, decontrol, and disposal of CUI.
Second, DoW suspended CMMC Phase II on July 13, 2026, but explicitly kept Phase I self-assessment requirements in place. Its current CMMC guidance says that during the review, the Department is enforcing NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments.
So this is an excellent time to stop thinking only about future certification dates and ask a simpler question:
What would someone physically see if they walked through our CUI environment today?
Do not make this exclusively an IT exercise.
Physical CUI crosses organizational boundaries.
A useful team may include representatives from:
A small contractor may only need two or three people.
The important part is having someone who understands the documented CUI environment and someone who understands how work actually happens on the floor.
Those are not always the same person.
Start with the organization's existing inventory.
NIST SP 800-171 Rev. 2 requirement 3.4.1 requires organizations to establish and maintain baseline configurations and inventories of organizational systems, including hardware, software, firmware, and documentation. NIST's discussion says useful hardware inventory information includes manufacturer, device type, model, serial number, physical location, system association, and component owner.
NIST SP 800-171A goes further from an assessment perspective: it asks whether the system inventory is established, includes the required component types, and is maintained throughout the system lifecycle.
For the physical walkdown, bring whatever inventory your organization actually uses.
Then verify it.
This distinction matters.
NIST requires an inventory.
It does not say every asset must have one particular commercial barcode label attached to it.
Physical asset labels are an implementation tool.
CUI Supply's CMMC Control Asset Labels are designed to help organizations visually identify assets in categories such as CUI-authorized, VDI-only, restricted, specialized, security-protection, CRMA, and out-of-scope devices.
CUI Supply explicitly distinguishes these inventory labels from SF-902 and Generic SF-905 media labels.
That is the correct way to think about them:
Inventory determines the asset's documented status.
The asset label communicates that status physically.
Do not reverse that sequence.
Do not start in the server room.
Start where a visitor starts.
Walk toward the facility.
Ask:
The point is not to turn every facility into a fortress.
It is to identify paths that bypass the physical controls described in your procedures.
Now enter the building.
Do not mentally skip to the security process you know is supposed to happen.
Observe what actually happens.
Can a visitor:
NIST SP 800-171 Rev. 2 requirement 3.10.1 requires organizations to limit physical access to organizational systems, equipment, and operating environments to authorized individuals. Its discussion explicitly includes employees, credentialed individuals, and visitors.
Requirement 3.10.3 separately requires organizations to escort visitors and monitor visitor activity.
The walkdown question is:
Does the facility make those procedures practical?
Do not inspect only the official controlled room.
Follow the route a customer, vendor, job candidate, delivery driver, maintenance technician, or auditor actually travels.
Look left and right.
What can they see?
Check:
You may discover that the highest-risk CUI exposure is not inside the controlled room.
It is on the route to it.
Now find every location your organization considers physically controlled for CUI purposes.
At each boundary, ask:
Where exactly does the controlled environment begin?
Can an employee tell?
Can a visitor tell?
What changes when someone crosses the boundary?
Is access actually controlled?
Clear physical identification can support the process.
CUI Supply provides CUI Restricted Area Signs and other facility-marking products that can visibly communicate where restricted-access procedures apply.
But remember:
The sign does not create the access restriction.
It communicates a restriction that should already exist in policy and practice.
This is where the walkdown becomes especially valuable.
Pick an area.
Find every:
Then ask:
Is it authorized to process CUI?
Is this device in the inventory?
Is its physical location correct?
Does its documented role match what employees actually use it for?
Who owns it?
Is it VDI-only?
Is it supposed to be out of scope?
If the inventory says a device is in Room 104 and it moved to production six months ago, fix the inventory.
If the inventory says a computer is out of scope but employees routinely download controlled drawings to it, you have discovered a much larger problem.
Every facility has them.
The old laptop under a desk.
The spare scanner.
The engineering computer nobody wants to replace.
The test stand running Windows from another era.
The shared shop-floor terminal.
The PC attached to a CNC machine.
The old external drive in a drawer.
Ask:
Can it access CUI?
Does it store CUI?
What is this?
Who owns it?
Is it inventoried?
Why is it here?
A physical walkdown often finds assets that never appear in an architecture diagram because everyone has simply forgotten about them.
If your organization uses physical asset classification labels, test them.
Do not simply confirm that stickers exist.
Ask whether the label is true.
A device labeled:
CUI AUTHORIZED
should actually be authorized under the organization's architecture and procedures.
A device labeled:
VDI ONLY
should actually be governed so employees understand and follow the VDI-only workflow.
A device labeled:
CUI RESTRICTED
should not quietly be used to process CUI.
CUI Supply's CUI Authorized Control Asset Labels and CUI Restricted Asset Labels are designed to support visual asset identification and inventory management.
They should reflect the system inventory.
Not contradict it.
This deserves its own checkpoint.
An inventory/control asset label answers:
What role does this asset have in our environment?
A CUI media label answers a different question:
Does this media/device contain or handle CUI requiring identification under our applicable marking procedure?
NARA identifies SF-902 as the CUI media label used for media such as hard drives and SF-903 as the smaller USB-size media label.
CUI Supply's SF-902 CUI Computer and Digital Media Labels include “U.S. Government Property.”
For company-owned equipment where that wording would be inaccurate, CUI Supply offers Generic SF-905 CUI Digital Media Labels without the government-property language.
The physical walkdown should verify that your labels communicate what you actually intend them to communicate.
Even the correct label is less useful if nobody can see it.
Check whether labels are:
For monitors, labels should be applied to the physical monitor housing or bezel, not rendered as an image on the display.
For laptops, consider a consistent location employees and inventory personnel can quickly find.
For printers, scanners, servers, and equipment, choose a visible physical surface appropriate to the device.
Consistency makes a large facility much easier to understand.
Do not sit in the employee's chair yet.
Stand where an unauthorized person might stand.
Can you read the monitor?
Can you see the engineering drawing?
Can you see a second monitor through the doorway?
Does the screen face a window?
Can someone waiting for a meeting see CUI?
NIST's physical-protection discussion identifies monitors among the equipment that organizations should physically protect from unauthorized access. It also identifies printers, copiers, scanners, external drives, networking devices, and computing devices.
A technically secure workstation can still have a poor physical sightline.
Now look at the environment from the user's perspective.
Ask the employee:
What CUI does this computer handle?
Can you download files locally?
Can you use USB drives?
Which printer do you use for CUI?
Where do printed documents go when you leave?
What do you do with a bad print?
Where do you store physical CUI overnight?
You are testing whether the real employee workflow matches the written one.
If employees consistently give different answers, that is a process problem even if every computer is correctly configured.
Printers deserve special attention because they convert protected electronic CUI into physical media.
For each printer used with CUI, ask:
NIST's physical-protection discussion explicitly lists printers, copiers, and scanners among equipment subject to physical-access considerations.
This is why a printer should be treated as part of the CUI workflow—not office furniture.
Scanners are easy to overlook because employees think about where the document is going rather than what device it passes through.
Ask:
Is this scanner approved for CUI?
Where does the scan go?
Does the device retain copies?
Who can use it?
Is it connected to email?
Does it have internal storage?
What happens at end of life?
A multifunction printer may simultaneously be:
printer + scanner + copier + network device + storage device.
Your physical inventory should reflect that reality.
NIST SP 800-171 Rev. 2 requirement 3.8.1 requires organizations to physically control and securely store system media containing CUI, both paper and digital. NIST's assessment objectives separately examine whether paper and digital media are physically controlled and securely stored.
Open the approved removable-media storage location.
Then look elsewhere.
Check:
Look for:
Ask whether each item is accounted for and handled according to the organization's procedure.
Now look for paper.
Not only official drawings.
Look for:
If the information contains CUI, the physical handling process matters.
NARA explains that an approved SF-901 cover sheet can identify CUI, alert observers that CUI is present, and act as a shield against inadvertent disclosure. If an agency chooses to use a coversheet, the approved form is SF-901.
CUI Supply provides SF-901 CUI Cover Sheets for organizations incorporating those cover sheets into their physical-document procedures.
Again:
SF-901 does not create CUI.
It helps identify and shield CUI that already exists.
Do not just ask whether one exists.
Inspect it.
NIST's Rev. 2 media-protection requirement specifically calls for physical control and secure storage of paper and digital media containing CUI.
Ask:
Sometimes the official CUI cabinet is pristine because nobody uses it.
That is not necessarily good news.
Manufacturing environments often expose the difference between cybersecurity diagrams and physical reality.
Look at:
Ask where controlled technical information enters the process and where it leaves.
Does a controlled drawing travel with the part?
Is it covered?
Does an old revision get destroyed?
Can a visitor walking the aisle see it?
Does a CNC controller or any other production device retain controlled files?
These are physical-CUI questions even when the underlying information originated electronically.
NIST's physical-protection discussion specifically includes networking devices and supporting infrastructure.
Check:
Ask whether the physical access restrictions match the organization's documented policy.
A server room with a sign but an unlocked door tells a very different story from the SSP.
We recently covered CUI meetings in detail, but conference rooms belong in the walkdown because they are often forgotten between meetings.
Look for:
Then ask:
Could the next person scheduled to use this room safely walk in right now?
That is an excellent physical-security test.
Go to the trash cans.
Go to recycling.
Then go to the approved CUI destruction collection point.
Look inside where appropriate under organizational procedures.
Are employees using the right one?
Is the secure destruction container clearly identifiable?
Is it protected from accessing or tampering with contents?
Are misprints appearing in ordinary trash or recycling?
A perfect written destruction procedure does not matter much if employees are throwing controlled drawings into the closest blue bin.
Shipping departments often sit outside the cybersecurity conversation but can handle:
Ask:
What happens when CUI arrives here?
How does shipping recognize it?
Who gets contacted?
Where is it held?
Can delivery drivers access controlled paperwork?
Physical CUI can enter or leave a facility through the loading dock just as easily as through engineering.
Where does broken equipment go?
An old CUI-authorized laptop may leave engineering and sit for two weeks on an IT repair shelf.
A printer may be staged for vendor pickup.
A hard drive may be placed in an electronics recycling box.
A CNC controller may wait for an outside technician.
The equipment has changed location.
The information risk may not have changed.
Make sure repair, surplus, quarantine, and disposition locations are included in the physical CUI workflow.
Who enters the facility after employees leave?
Potential examples:
Then inspect what CUI remains exposed overnight.
A workspace that is effectively controlled from 8:00 AM to 5:00 PM may operate very differently at 10:00 PM.
During the walkdown, ask several employees a simple hypothetical:
“Someone you don't recognize walks into this controlled area without an escort. What do you do?”
The exact response should follow organizational policy.
What matters is whether employees know it.
Signs, badges, and floor markings work best when employees understand what action the visual cue is supposed to trigger.
Documentation helps.
But be careful.
Do not create an uncontrolled collection of CUI photographs while documenting physical-security findings.
A safer walkdown record may use:
If photographs are needed and they contain CUI, they must be captured and handled through an authorized workflow.
The audit itself should not create a new information-handling problem.
Use this as the practical inspection sheet.
Do not treat 50/50 as a compliance score.
This is a gap-discovery checklist, not an official CMMC scoring methodology.
One serious finding can matter far more than ten minor ones.
Do not finish the walkdown with a notebook full of observations.
Convert each real finding into an actionable record.
A useful format is:
Location
Engineering Room 204
Asset / Process
Shared printer
Finding
CUI output accessible from uncontrolled hallway
Applicable Procedure / Requirement
Physical-access / media-handling procedure
Action
Relocate printer or implement appropriate access control
Owner
IT / Facilities
Target Date
Organization-defined
Evidence of Completion
Updated layout, procedure, inventory record, configuration or approved photograph
This creates a bridge between the physical inspection and the formal compliance program.
A faded sticker may need replacement.
But an unauthorized printer containing CUI is more important.
A crooked restricted-area sign may look unprofessional.
But a side door bypassing visitor controls is more important.
A useful prioritization sequence is:
First: actual unauthorized access or disclosure pathways.
Second: CUI on systems or media outside the documented environment.
Third: missing physical controls or storage.
Fourth: inconsistent procedures and employee behavior.
Fifth: visual identification and standardization improvements.
Physical markings matter because they make controls easier to operate.
They should not distract from the underlying control.
The walkdown may identify places where better visual controls would genuinely improve the environment.
For example:
Finding: Employees cannot distinguish CUI-authorized computers from general systems.
Possible implementation tool: CUI Authorized Control Asset Labels.
Finding: Contractor-owned devices need visible CUI identification without implying U.S. Government ownership.
Possible implementation tool: Generic SF-905 CUI Digital Media Labels.
Finding: Government-owned media requires standardized identification.
Possible implementation tool: SF-902 CUI Media Labels where appropriate under the organization's applicable procedure.
Finding: Employees routinely expose printed CUI.
Possible implementation tool: SF-901 CUI Cover Sheets.
Finding: Controlled-area entrances are unclear.
Possible implementation tool: CUI Restricted Area signage.
Finding: Employees cannot distinguish device scoping roles.
Possible implementation tool: CMMC Control Asset Labels.
The sequence matters:
Find the problem → determine the required control → implement the control → use physical products where they make that control clearer.
Not:
Buy products → look for places to stick them.
At the end, your team should be able to answer:
Where can CUI physically appear in this facility?
Which systems can process, store, transmit, display, or access it?
Which physical media can contain it?
Which printers and scanners are part of the workflow?
Where are controlled areas?
Who can enter them?
How are visitors handled?
Where is physical CUI stored?
Where does unwanted CUI go?
How are devices handled when they leave service?
Does the asset inventory match reality?
Do employees understand the physical system?
If those answers are clear, the facility becomes much easier to defend, operate, explain, and assess.
Keep this distinction clear during remediation.
NIST SP 800-171 Rev. 2 includes requirements such as maintaining system inventories, physically controlling and securely storing media containing CUI, limiting physical access to systems and operating environments, escorting visitors, maintaining physical-access records, and controlling physical-access devices.
NARA separately provides government-wide CUI policy, marking resources, approved forms such as SF-901, and standardized media labels such as SF-902 and SF-903.
Physical implementation practices may include:
Those practices can make the required safeguards much easier to implement consistently.
But do not describe a commercial product or locally chosen visual convention as federally mandatory unless the authoritative requirement actually makes it mandatory.
That precision makes a CUI program more credible.
A CUI facility walkdown is a practical inspection of the physical places, systems, media, documents, access points, and workflows through which CUI is handled. It is not an official NIST assessment type; it is a useful way to verify that the real facility matches documented CUI procedures.
Applicable NIST SP 800-171 requirements include physical protection, media protection, system inventory, visitor controls, and other safeguards that can involve physical systems, spaces, and evidence. Assessment guidance can include examination, interviews, and testing of relevant processes and objects. A “facility walkdown” is a practical preparation method, not a separately named universal requirement.
Yes. Revision 2 requirement 3.4.1 requires organizations to establish and maintain baseline configurations and inventories of organizational systems, including hardware, software, firmware, and documentation.
No universal requirement says the inventory must be implemented with a particular barcode sticker. Physical asset tags are an implementation tool that can make inventory, device identification, and scoping easier.
Not automatically. NARA identifies SF-902 as a standardized CUI media label for media containing CUI, such as hard drives. Organizations should follow applicable agency, contract, ownership, and internal marking procedures rather than assuming every device receives the same label.
An asset label can communicate a device's inventory or scoping role, such as CUI-authorized, VDI-only, restricted, or out of scope. A media label identifies CUI media or equipment according to the organization's applicable marking process. They solve related but different problems.
Physical labels should be applied to the monitor housing, bezel, back, or another suitable physical surface—not digitally placed over the display itself.
Yes. NIST's physical-protection discussion specifically identifies printers, copiers, scanners, monitors, external drives, networking devices, and computing devices as examples of equipment relevant to physical access protection.
Yes. NIST SP 800-171 Rev. 2 requires physical control and secure storage of system media containing CUI, including paper and digital media.
No universal rule requires an SF-901 on every physical CUI document. NARA says agencies may use an approved coversheet to identify CUI, alert observers, and shield it from inadvertent disclosure; when an agency chooses a CUI coversheet, it uses the approved SF-901.
There is no universal federal rule prescribing a specific “CUI walkdown” interval. A practical approach is to perform one periodically and after meaningful facility, system, equipment, workflow, or access changes, consistent with the organization's risk management and assessment processes.
Walk your facility. Find the physical gaps. Then make the correct CUI workflow obvious.
CUI Supply provides standardized physical tools for CUI asset identification, media marking, document protection, controlled-area identification, visitor control, printer workflows, and facility-wide implementation—helping defense contractors turn documented CUI safeguards into physical processes employees can actually follow.
Explore CMMC Control Asset Labels, browse CUI media labels, or view the complete CUI Supply catalog.