3.10.5Manage keys and badges in Rev. 3
Withdrawn and incorporated elsewhere: 03.10.07 Physical Access Control.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.10.5 Manage Physical Access
Assessment objectives · 800-171A
- [a] physical access devices are identified
- [b] physical access devices are controlled
- [c] physical access devices are managed
Rev. 3 · not adopted 03.10.07 Physical Access Control
a. Enforce physical access authorizations at entry and exit points to the facility where the system resides by:
01. Verifying individual physical access authorizations before granting access to the facility and
02. Controlling ingress and egress with physical access control systems, devices, or guards.
b. Maintain physical access audit logs for entry or exit points.
c. Escort visitors, and control visitor activity.
d. Secure keys, combinations, and other physical access devices.
e. Control physical access to output devices to prevent unauthorized individuals from obtaining access to CUI.
Determination statements · 800-171A Rev. 3
- 03.10.07.a.01 physical access authorizations are enforced at entry and exit points to the facility where the system resides by verifying individual physical access authorizations before granting access.
- 03.10.07.a.02 physical access authorizations are enforced at entry and exit points to the facility where the system resides by controlling ingress and egress with physical access control systems, devices, or guards.
- 03.10.07.b physical access audit logs for entry or exit points are maintained.
- 03.10.07.c[01] visitors are escorted.
- 03.10.07.c[02] visitor activity is controlled.
- 03.10.07.d keys, combinations, and other physical access devices are secured.
- 03.10.07.e physical access to output devices is controlled to prevent unauthorized individuals from obtaining access to CUI.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.10.5 → Rev. 3 03.10.07 Physical Access Control
5 words kept, 1 removed, 75 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
Rev. 3 withdraws this requirement as a separate item and folds it into another requirement. NIST's note: Incorporated into 03.10.07.
NIST's Rev. 3 discussion for 03.10.07
This requirement addresses physical locations containing systems or system components that process, store, or transmit CUI. Organizations determine the types of guards needed, including professional security staff or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include exterior access points, interior access points to systems that require supplemental access controls, or both. Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and only allowing access to authorized individuals, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, facsimile machines, audio devices, and copiers.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.10.5 as written in Rev. 2.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.10.07
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]