03.10.07Physical Access Control in Rev. 3
New in Revision 3 — NIST classes it as a new requirement that incorporates withdrawn Revision 2 3.10.3, 3.10.4, 3.10.5. Nothing in NIST SP 800-171 Rev. 2 maps onto this number, so it has no Rev. 2 page and no side-by-side; the Rev. 3 text is below in full.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
The requirement
Rev. 3 · not adopted 03.10.07 Physical Access Control
a. Enforce physical access authorizations at entry and exit points to the facility where the system resides by:
01. Verifying individual physical access authorizations before granting access to the facility and
02. Controlling ingress and egress with physical access control systems, devices, or guards.
b. Maintain physical access audit logs for entry or exit points.
c. Escort visitors, and control visitor activity.
d. Secure keys, combinations, and other physical access devices.
e. Control physical access to output devices to prevent unauthorized individuals from obtaining access to CUI.
NIST SP 800-171 Rev. 3, verbatim, with organization-defined blanks highlighted. Rev. 2 has no counterpart to place beside it.
Determination statements
What an assessor would check under NIST SP 800-171A Rev. 3. 7 statements, each one answered yes or no.
- 03.10.07.a.01 physical access authorizations are enforced at entry and exit points to the facility where the system resides by verifying individual physical access authorizations before granting access.
- 03.10.07.a.02 physical access authorizations are enforced at entry and exit points to the facility where the system resides by controlling ingress and egress with physical access control systems, devices, or guards.
- 03.10.07.b physical access audit logs for entry or exit points are maintained.
- 03.10.07.c[01] visitors are escorted.
- 03.10.07.c[02] visitor activity is controlled.
- 03.10.07.d keys, combinations, and other physical access devices are secured.
- 03.10.07.e physical access to output devices is controlled to prevent unauthorized individuals from obtaining access to CUI.
NIST SP 800-171A Rev. 3, verbatim.
What NIST says
- New security requirement based on PE-03 (SP 800-53, Revision 5)
- Added new ODP: circumstances requiring visitor escorts and control of visitor activity
- Incorporates withdrawn requirements: 03.10.03, 03.10.04, 03.10.05
The Rev. 2 requirements NIST folds into it, each with its own comparison: 3.10.3 Escort visitors, 3.10.4 Keep physical access logs, 3.10.5 Manage keys and badges.
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “New requirement”. At adoption, Bedrock files this under “New”.
NIST's Rev. 3 discussion for 03.10.07
This requirement addresses physical locations containing systems or system components that process, store, or transmit CUI. Organizations determine the types of guards needed, including professional security staff or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include exterior access points, interior access points to systems that require supplemental access controls, or both. Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and only allowing access to authorized individuals, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, facsimile machines, audio devices, and copiers.
Physical Protection in Rev. 3
The active PE requirements in Rev. 3. Those with a Rev. 2 predecessor link to that comparison; those marked new have their own page.
What this means for you now
Nothing. Until a class deviation or a published rule adopts Rev. 3, no assessor asks about 03.10.07 and SPRS has no score for it. If you already do what it describes, note where the evidence lives; that costs nothing and answers the question later.
Bedrock CMMC carries the Rev. 3 catalog beside your Rev. 2 package, so the day adoption lands the new requirements are a to-do list, not a surprise.
Where this page's facts come from
- Rev. 3 03.10.07 text, determination statements, parameters, class and note
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]