CMMC Level 1 · RequirementSEC / REQMP.L1-b.1.vii
Media Protection · MP.L1-b.1.vii
Sanitize or destroy media before disposal or reuse
Requirement MP.L1-b.1.vii of the fifteen CMMC Level 1 security requirements, in the Media Protection domain.
Short Answer
What do we do with old drives, disks, and paper that held Federal Contract Information?
Drives, disks, and paper that held Federal Contract Information are wiped or destroyed before they are thrown out or handed on.
Official Requirement
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Media Protection (MP)
- Requirement ID
- MP.L1-b.1.vii
- FAR Clause
- FAR 52.204-21(b.1.vii)
- NIST SP 800-171 Mapping
- 3.8.3
Assessment Objectives
Common Questions
- What counts as media I have to sanitize or destroy?
- Any media that held Federal Contract Information. That includes hard drives, solid-state drives, USB drives, backup tapes, and printed paper. Before you throw it away or pass it on for reuse, wipe it or destroy it so the information cannot be recovered. Simply reformatting a drive is often not enough.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
