
CMMC Level 2 &
DFARS Physical Security
Where the evidence lands
The Physical Protection (PE) controls of NIST SP 800-171 that visitor evidence bears on, and how far it goes. An assessor assesses your organization, not a vendor.
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
SecurePoint USA supports ID-verified check-in, escort workflows, and physical-access audit evidence.
Escort visitors and monitor visitor activity.
Automated host notifications and digital visitor badges clearly state escort requirements and restricted zones based on screening results.
Maintain audit logs of physical access.
Every visitor check-in, host approval, and FSO decision is captured in an append-only vault with 10-year audit log retention. ID image retention is configurable by policy and plan.
Control and manage physical access devices.
Track visitor badge issuance and return with precise timestamps, ensuring all physical access tokens are accounted for in the audit trail.
Assessment-Grade
Evidence Packs
Satisfy assessors with cryptographically signed audit summaries. One-click exports for every visitor access event during your assessment window.
Append-Only Logs
Append-only records with SHA-256 verification ensure data integrity.
Designed for assessor review
Evidence packs structured for CMMC and DFARS assessment workflows.
Evidence Summary
ID: EVIDENCE-2024-Q2
Hardened cloud infrastructure
Visitor metadata runs on hardened cloud infrastructure with tenant isolation, role-based access, and append-only audit logging.
Encrypted at rest and in transit
Visitor records are encrypted at rest and in transit, with site-scoped access controls and configurable retention.
Audit Trail Integrity
Digital signatures prevent any manipulation of access records, providing the "defensibility" auditors require.
Automate Your Assessment Prep
Phase 1: Control Alignment
Map your specific site policies to PE requirements in our rules engine.
Phase 2: Data Orchestration
Unified screening and ID verification automatically creates the evidence trail.
Phase 3: Append-Only Archive
Logs are vaulted with cryptographic hashes for external audit validation.
Related compliance resources
The CMMC physical-security roadblock
Why PE controls stall Level 2 assessments, and how to clear them.
ProductVisitor check-in kiosk
Self-service kiosk capturing the visitor access records CMMC PE controls require.
ComplianceITAR & EAR workflows
Export-control access screening for the same regulated facilities.
The Standard for
Audit Readiness
Stop manually collecting paper logs. Join the facilities using SecurePoint USA to automate the physical security of their CUI.
Frequently asked questions
Does SecurePoint make our organization CMMC compliant?
No. CMMC compliance is a program you run and an assessment you pass. SecurePoint is one internal control inside that program: it screens visitors, records host and escort assignment, gates badge issuance, and produces the physical-access records an assessor can review.
Which controls does visitor management actually touch?
Not all of them, and not equally. SecurePoint produces direct evidence for PE.L2-3.10.3 (escort visitors and monitor visitor activity) and PE.L2-3.10.4 (maintain audit logs of physical access). It supports PE.L2-3.10.1 and PE.L2-3.10.5 without being sufficient for them alone, contributes only partially to PE.L2-3.10.2, and does not address PE.L2-3.10.6, which concerns alternate work sites. Confirm your scope with your C3PAO.
Does SecurePoint satisfy DFARS 252.204-7012 for us?
No. The clause obligations sit with your organization. SecurePoint produces physical-access evidence supporting the safeguarding and audit expectations, and the records that let you show the control operated. Confirm your clause scope with counsel and your contracting officer.
What does an assessor actually receive?
An evidence pack covering the date range and sites you select: visit activity, screening results, adjudication decisions and the audit trail, exported together with SHA-256 checksums.
Is a sign-in sheet enough for the physical protection controls?
A sign-in sheet records that someone signed in. The PE controls also ask you to show that visitors were escorted and monitored, that access devices were controlled, and that a durable audit log of physical access exists. What satisfies your assessor depends on your scope, so confirm it with your C3PAO.