CMMC 3.8.3 (Media Sanitization): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.8.3 · CMMC Practice: MP.L2-3.8.3 · Updated June 2026

    Plain-English answer

    3.8.3 requires you to sanitize or destroy system media containing CUI before disposal or release for reuse. Two trigger points: before media is disposed of, and before it's reused. "Media" is broad — drives, SSDs, USB sticks, tapes, and paper. The CUI must be rendered unrecoverable, not just deleted.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment — particularly anyone retiring hardware, returning leased equipment, or repurposing drives and removable media.

    Why it matters

    Discarded or reused media is a quiet CUI leak — recoverable data on a drive that left your control is a disclosure. Proper sanitization closes it. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: MP.L2-3.8.3
    • NIST 800-171 Rev. 2: §3.8.3 — sanitize or destroy system media containing CUI before disposal or release for reuse.
    • NIST 800-171A objectives: [a] system media containing CUI is sanitized or destroyed before disposal; [b] system media containing CUI is sanitized before it is released for reuse.
    • Method reference: sanitization methods are commonly aligned to NIST SP 800-88 (clear / purge / destroy).

    What the assessor will EXAMINE

    • The media sanitization/destruction policy and the methods used (aligned to NIST SP 800-88).
    • Sanitization/destruction records — certificates of destruction, wipe logs, serial numbers.
    • Any third-party disposal vendor contract and their certificates.
    • SSP narrative for 3.8.3.

    What the assessor will INTERVIEW & TEST

    • Interview: "What happens to a drive containing CUI when a laptop is retired or a drive is repurposed?" — name the method and where it's recorded.
    • Test: Pull a recent disposal/reuse event and confirm a sanitization/destruction record exists for that media.
    • Test: Confirm the method is appropriate to the media type (e.g., not a quick format on an SSD).

    Evidence examples (produce these)

    • Media sanitization/destruction policy specifying methods by media type.
    • Sanitization logs or certificates of destruction with media identifiers/serials and dates.
    • Vendor destruction certificates if disposal is outsourced.
    • SSP section 3.8.3 referencing the above.

    Common failure patterns

    • Drives "deleted" or quick-formatted before disposal — data still recoverable, objective [a] fails.
    • Media reused/repurposed internally with no sanitization — objective [b] fails.
    • No records, so sanitization can't be proven even if it happened.
    • SSD/flash sanitized with a method meant for spinning disks.

    SPRS impact & POA&M

    SPRS: 3.8.3 carries a weighted deduction (verify the exact value). POA&M: confirm 3.8.3's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.8.3 when media containing CUI is sanitized or destroyed (by a media-appropriate method) before disposal and before reuse, you keep records/certificates proving it, and the SSP matches the practice.

    Can you produce a destruction record for the last drive you retired? Get a media-sanitization evidence map →

    Related: 3.13.11 FIPS Cryptography · 3.1.20 External Systems · All control pages

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.