How do CMMC physical controls work across leased and home offices?

The landlord's lobby and your cloud provider's data center don't cover your suite or a home desk. What 3.10.1–3.10.6 ask of you, and the home rules to paste into policy.

Physical protection has owners. Landlord entrance. Company work area. Home handling. Working guide.
In this guide

Updated September 29, 2026

You rent a suite in a building with a badge reader in the lobby, one engineer works from home on Fridays, and the files live in the cloud. It's tempting to call physical security somebody else's problem. It isn't. You own the room where the controlled drawings are, the visitors who get near them, and how your people handle screens and paper at home. The landlord's badge covers the landlord's door. Your cloud provider's data center covers its own building, not a printed drawing on a kitchen table.

The drawings in question are CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive). CMMC, the Defense Department's cybersecurity certification for contractors, has six requirements about physical security, and in a small company all six land on the same person.

Three of those six carry an extra penalty. Escorting visitors, keeping a visitor log, and controlling keys and badges are on the short list of requirements the rule never lets you leave open for later (32 CFR 170.21). Miss one at assessment and you can't get the conditional result that keeps you eligible for new awards while you fix the rest. A missing key list is cheap to fix now and expensive to discover then.

Walk it with a stranger

The fastest way to find your gaps is to walk someone who doesn't work there from the lobby to the engineering room. Borrow a friend or a new hire and watch.

The landlord's guard waves them to the elevator. At your suite, who lets them in, and does anyone write it down? The drawing on the second monitor by the door: can they read it from the hallway? The engineering room: locked, and who has keys? Most shops can't produce a key list, and the one they eventually find includes a former employee and "spare, lost?"

Then check what your walk skipped. The landlord's cleaning crew has a master key to every suite in the building, after hours, with nobody watching. That's usually the biggest hole, and a lockable cabinet or a room on your own lock closes it. Labs get the same treatment: a test instrument that can't run security software leans on the lock on its door. The shared conference room down the hall needs a rule too: controlled drawings leave with you at the end of the meeting.

For the office, what satisfies an assessor is short. A list of people allowed in the room where CUI is kept. A visitor log with name, date, time in and out, and who escorted them. A key and badge list you check every quarter. And the landlord's written description of what the building provides. A company with two plants keeps this set for each one.

Three rules for home

Nobody needs a camera watching a home office. They need rules they can follow without thinking. Paste these into your remote-work policy as written:

When working with CUI at home, work where household members and visitors can't see your screen, and lock the screen whenever you step away. Don't print CUI at home unless your manager has approved it in writing; anything printed stays in a locked drawer and goes through a cross-cut shredder when you're done. If someone enters, a contractor needs the room, or you're working somewhere other than your approved spot, close the session and resume later.

Keep home addresses in HR records, not in your scope documents. If the home worker uses a personal laptop, that's a separate question: personal devices and virtual desktops. For printers and media at the office, see printers, media, and laptops.

A good walk-through ends with a handful of specific fixes with names on them: the key nobody can account for, the print tray nobody clears, the Friday coffee-shop habit. Fix those, and add each location to your scope.

When the assessor asks by number

The six requirements are in NIST SP 800-171 (Rev. 2), numbered 3.10.1 to 3.10.6. The room access list answers 3.10.1 (limit physical access to authorized people). The locks and the landlord's description answer 3.10.2 (protect and monitor the facility). Escorts answer 3.10.3, the visitor log 3.10.4, and the key and badge list 3.10.5; those are the three that can't be left open. The home rules answer 3.10.6, safeguards at alternate work sites.

Mock assessment

Bring every working location into the record.

Garde1 records each office's visitor handling, the printers that handle CUI, and how paper is stored and destroyed, and writes your physical protection policy from it.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE