Skip to content
CMMC Assessment Visualization
Assessment-Ready Controls

CMMC Level 2 &
DFARS Physical Security

Visitor management workflows designed for CMMC 2.0 Level 2 and DFARS 252.204-7012. Append-only audit logging, identity verification, and assessment-ready evidence packs. Phase 1 self-assessment is in force today; DoD suspended Phase 2 on July 13, 2026 pending a program review, and the physical-access evidence is required either way. Verify current status at dodcio.defense.gov before relying on a date.

Where the evidence lands

The Physical Protection (PE) controls of NIST SP 800-171 that visitor evidence bears on, and how far it goes. An assessor assesses your organization, not a vendor.

PE.L2-3.10.1
Supporting

Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

SecurePoint USA supports ID-verified check-in, escort workflows, and physical-access audit evidence.

PE.L2-3.10.3
Direct evidence

Escort visitors and monitor visitor activity.

Automated host notifications and digital visitor badges clearly state escort requirements and restricted zones based on screening results.

PE.L2-3.10.4
Direct evidence

Maintain audit logs of physical access.

Every visitor check-in, host approval, and FSO decision is captured in an append-only vault with 10-year audit log retention. ID image retention is configurable by policy and plan.

PE.L2-3.10.5
Supporting

Control and manage physical access devices.

Track visitor badge issuance and return with precise timestamps, ensuring all physical access tokens are accounted for in the audit trail.

Assessment-Grade
Evidence Packs

Satisfy assessors with cryptographically signed audit summaries. One-click exports for every visitor access event during your assessment window.

Append-Only Logs

Append-only records with SHA-256 verification ensure data integrity.

Designed for assessor review

Evidence packs structured for CMMC and DFARS assessment workflows.

Evidence Summary

ID: EVIDENCE-2024-Q2

Verified
Control PE.3.10.1
Supported
Control PE.3.10.3
Escorted
Control PE.3.10.4
Logged

Hardened cloud infrastructure

Visitor metadata runs on hardened cloud infrastructure with tenant isolation, role-based access, and append-only audit logging.

Encrypted at rest and in transit

Visitor records are encrypted at rest and in transit, with site-scoped access controls and configurable retention.

Audit Trail Integrity

Digital signatures prevent any manipulation of access records, providing the "defensibility" auditors require.

Automate Your Assessment Prep

1

Phase 1: Control Alignment

Map your specific site policies to PE requirements in our rules engine.

2

Phase 2: Data Orchestration

Unified screening and ID verification automatically creates the evidence trail.

3

Phase 3: Append-Only Archive

Logs are vaulted with cryptographic hashes for external audit validation.

The Standard for
Audit Readiness

Stop manually collecting paper logs. Join the facilities using SecurePoint USA to automate the physical security of their CUI.

Frequently asked questions

Does SecurePoint make our organization CMMC compliant?

No. CMMC compliance is a program you run and an assessment you pass. SecurePoint is one internal control inside that program: it screens visitors, records host and escort assignment, gates badge issuance, and produces the physical-access records an assessor can review.

Which controls does visitor management actually touch?

Not all of them, and not equally. SecurePoint produces direct evidence for PE.L2-3.10.3 (escort visitors and monitor visitor activity) and PE.L2-3.10.4 (maintain audit logs of physical access). It supports PE.L2-3.10.1 and PE.L2-3.10.5 without being sufficient for them alone, contributes only partially to PE.L2-3.10.2, and does not address PE.L2-3.10.6, which concerns alternate work sites. Confirm your scope with your C3PAO.

Does SecurePoint satisfy DFARS 252.204-7012 for us?

No. The clause obligations sit with your organization. SecurePoint produces physical-access evidence supporting the safeguarding and audit expectations, and the records that let you show the control operated. Confirm your clause scope with counsel and your contracting officer.

What does an assessor actually receive?

An evidence pack covering the date range and sites you select: visit activity, screening results, adjudication decisions and the audit trail, exported together with SHA-256 checksums.

Is a sign-in sheet enough for the physical protection controls?

A sign-in sheet records that someone signed in. The PE controls also ask you to show that visitors were escorted and monitored, that access devices were controlled, and that a durable audit log of physical access exists. What satisfies your assessor depends on your scope, so confirm it with your C3PAO.

CMMC and DFARS Compliance | SecurePoint USA