CMMC Level 1 · RequirementSEC / REQMP.L1-b.1.vii

Media Protection · MP.L1-b.1.vii

Sanitize or destroy media before disposal or reuse

Requirement MP.L1-b.1.vii of the fifteen CMMC Level 1 security requirements, in the Media Protection domain.

Short Answer

What do we do with old drives, disks, and paper that held Federal Contract Information?

Drives, disks, and paper that held Federal Contract Information are wiped or destroyed before they are thrown out or handed on.

Official Requirement

Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Media Protection (MP)
Requirement ID
MP.L1-b.1.vii
FAR Clause
FAR 52.204-21(b.1.vii)
NIST SP 800-171 Mapping
3.8.3

Assessment Objectives

Common Questions

What counts as media I have to sanitize or destroy?
Any media that held Federal Contract Information. That includes hard drives, solid-state drives, USB drives, backup tapes, and printed paper. Before you throw it away or pass it on for reuse, wipe it or destroy it so the information cannot be recovered. Simply reformatting a drive is often not enough.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.