CMMC 3.13.8 (Encrypt CUI in Transit): Evidence & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.13.8 · CMMC Practice: SC.L2-3.13.8 · Updated June 2026

    Plain-English answer

    3.13.8 requires cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission — unless it's otherwise protected by alternative physical safeguards. So: encrypt CUI in transit (TLS, VPN, encrypted email/file transfer), or protect the path physically (e.g., a protected distribution system). One or the other must cover every path CUI travels.

    Who this applies to

    Every organization seeking CMMC Level 2 that transmits CUI — over email, file transfer, web apps, VPNs, or between sites.

    Why it matters

    CUI in transit is exposed to interception. Encryption (or physical protection) is what keeps it confidential on the wire. Pair it with FIPS-validated modules (3.13.11) so the mechanism itself holds up. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: SC.L2-3.13.8
    • NIST 800-171 Rev. 2: §3.13.8 — implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
    • NIST 800-171A objectives: [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI during transmission are identified; [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI during transmission are identified; [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission.

    What the assessor will EXAMINE

    • The transmission paths CUI travels (email, file transfer, web/app traffic, site-to-site) and the encryption protecting each.
    • Configuration enforcing encryption in transit (TLS versions/ciphers, VPN config, enforced HTTPS, encrypted email).
    • Any alternative physical safeguards where encryption isn't used, with justification.
    • Linkage to FIPS-validated modules (3.13.11) and the SSP narrative for 3.13.8.

    What the assessor will INTERVIEW & TEST

    • Interview: "Trace a piece of CUI from here to its destination — what protects it in transit at each hop?" — name encryption or physical safeguard for each path.
    • Test: Inspect a live transmission path (e.g., TLS handshake, VPN tunnel) to confirm encryption is actually applied.
    • Test: Look for unencrypted channels (plain SMTP, HTTP, FTP) carrying CUI.

    Evidence examples (produce these)

    • Map of CUI transmission paths with the protection on each.
    • TLS/VPN/email-encryption configuration exports (versions, ciphers, enforcement).
    • Evidence the underlying modules are FIPS-validated (ties to 3.13.11).
    • Documented alternative physical safeguards where used, with rationale.
    • SSP section 3.13.8 referencing the above.

    Common failure patterns

    • Web/VPN traffic encrypted, but email carrying CUI sent in the clear — a path left uncovered.
    • Encryption used but not FIPS-validated, weakening the claim under 3.13.11.
    • Weak/deprecated TLS or ciphers still enabled.
    • An internal "trusted" link assumed safe without encryption or a documented physical safeguard.

    SPRS impact & POA&M

    SPRS: 3.13.8 carries a weighted deduction (verify the exact value). POA&M: confirm 3.13.8's POA&M eligibility against current CMMC rules before assuming it can be deferred — note encryption-related controls have specific POA&M conditions worth checking.

    Assessor-ready summary

    You're good on 3.13.8 when every path CUI travels is protected in transit by encryption (preferably FIPS-validated) or a documented physical safeguard, the protection is verifiable in the live configuration, and the SSP matches.

    Sure no CUI leaves you in the clear? Get a transmission-protection evidence map →

    Related: 3.13.11 FIPS Cryptography · 3.13.1 Boundary Protection · All control pages

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.