GENERAL

CMMC Physical Security Requirements: What Defense Contractors Actually Need to Pass the Assessment

May 14, 2026 9 min read
Most defense contractors spend months preparing for CMMC 2.0.

Most defense contractors spend months preparing for CMMC 2.0. They document their access controls, configure their SSP, and work through 110 NIST SP 800-171 requirements line by line. Then an assessor walks through the front door and asks to see the physical facility.

That's when the gaps show up.

The Physical Protection domain — Domain PE in CMMC's 14-domain framework — doesn't care how clean your network architecture looks on paper. An assessor conducting a Level 2 certification assessment will physically tour your facility, inspect your access points, and verify that what your System Security Plan describes actually exists in the real world. A locked front door is not a physical security program. Neither is a single camera mounted in the lobby.

As of November 10, 2025, the CMMC Acquisition Rule (48 CFR) went into effect. CMMC requirements are appearing in live DoD solicitations now. If you handle Controlled Unclassified Information (CUI) and haven't closed your physical security gaps, you're behind.

Engineer working inside a precision manufacturing facility — the type of defense contractor environment subject to CMMC PE domain physical protection requirements
Defense contractors in precision manufacturing, aerospace, and supply chain fabrication are entering the CMMC enforcement window — and the PE domain is where most assessments break down.

What the CMMC Physical Protection Domain Actually Requires

The PE domain contains six requirements spread across CMMC Levels 1, 2, and 3. They're not technically complex — but they are exacting, and they require documented, observable evidence, not just written policies.

CMMC Physical Protection domain requirements by level Editorial diagram of the six PE domain requirements across CMMC Levels 1, 2, and 3 PE DOMAIN MAP Six requirements. Three levels. One walkthrough. LEVEL 1 Foundational FCI PE.L1-3.10.1 Limit physical access to authorized individuals PE.L1-3.10.3 Escort visitors and monitor their activity PE.L1-3.10.4 Maintain audit logs of physical access events PE.L1-3.10.5 Manage access devices keys, badges, codes LEVEL 2 Advanced CUI PE.L2-3.10.2 — THE MONITORING MANDATE Protect and monitor the physical facility Video surveillance, sensors, alarms, or guards — and support infrastructure too LEVEL 3 Expert PE.L3-3.10.6 Safeguard CUI at alternate work sites Home offices, temporary spaces, remote access Each level inherits the one below. A Level 2 assessment evaluates all five requirements above.

Level 1: The Foundation

Four requirements apply at Level 1, the baseline tier covering contractors who handle Federal Contract Information (FCI):

  • PE.L1-3.10.1: Limit physical access to organizational information systems, equipment, and their operating environments to authorized individuals only.
  • PE.L1-3.10.3: Escort visitors and monitor visitor activity in areas where FCI is stored or processed.
  • PE.L1-3.10.4: Maintain audit logs of physical access.
  • PE.L1-3.10.5: Control and manage physical access devices — keys, badges, keycards, PIN combinations, and any other credentials that grant access to protected areas.

These aren't abstract IT controls. They require real infrastructure: door locks, badge systems, visitor logs, and a documented process for revoking access when employees leave. If a terminated employee still has an active badge, you fail PE.L1-3.10.5. If visitors walk unescorted through areas where CUI systems are present, you fail PE.L1-3.10.3.

Level 2: Monitoring Becomes Mandatory

Level 2 adds one requirement that dramatically changes the scope of what's needed:

  • PE.L2-3.10.2: Protect and monitor the physical facility and support infrastructure for organizational systems.

The word "monitor" is doing significant work here. The CMMC model explicitly identifies video surveillance, sensors, alarms, and human guards as the mechanisms that satisfy this requirement. A facility with locked doors but no active monitoring for after-hours intrusion satisfies the letter of "protection" but not the monitoring obligation. Both elements must be present and documented.

Support infrastructure is also in scope. Power systems, HVAC, and network cabling that serves CUI systems all fall under PE.L2-3.10.2. A locked server room with an unlocked utility closet housing that server's power distribution is an incomplete control — and assessors know to look for exactly this kind of gap.

Level 3: Alternate Work Sites

Level 3 adds requirements around remote work environments where CUI is accessed. For most contractors, this means formalizing physical safeguards for employees working from home — company-managed devices, VPN enforcement, and documented policies that employees have acknowledged.

Why Physical Security Produces More Assessment Failures Than Any Other Domain

The gap isn't usually ignorance of the requirements. Most contractors know what PE.L2-3.10.2 says. The problem is the distance between what's written in a System Security Plan and what actually exists in the facility.

For small defense contractors — particularly in manufacturing, aerospace components, and defense supply chain fabrication — physical security programs have often been informal. A front desk, some cameras that record to a local DVR, and a visitor sign-in sheet covers the basics for day-to-day operations. That's not a CMMC-compliant monitoring program.

CMMC assessors evaluate the PE domain through all three examination methods: document review, interviews with personnel, and physical testing. The physical testing component is what separates PE from most other domains. Assessors will walk your floor. They'll check whether access-controlled doors actually lock, whether monitoring systems are operational, whether visitor protocols are enforced in practice, and whether the people who work there understand the policies.

A written policy that no one follows is worse than no policy — it signals to an assessor that compliance posture across other domains may be equally informal.

How AI Video Analytics Satisfies the PE.L2-3.10.2 Monitoring Requirement

The monitoring requirement at Level 2 calls for active, documented surveillance of the physical facility and its infrastructure. Traditional CCTV addresses one piece of this: it records. But recording is not monitoring.

A passive camera system that stores footage on a DVR and gets reviewed only after an incident has occurred satisfies neither the spirit nor the letter of PE.L2-3.10.2. The requirement is to protect and monitor — present tense, ongoing, capable of detecting and responding to physical access events as they happen.

Recording vs. monitoring — the CMMC compliance gap Editorial comparison of traditional CCTV and AI video analytics for CMMC PE.L2-3.10.2 THE COMPLIANCE GAP Recording is not monitoring. TRADITIONAL CCTV AI VIDEO ANALYTICS Records to DVR Reviewed only after an incident Analyzes feeds in real time Alerts generated as events occur No audit trail by default Evidence only if someone watches Timestamped detection logs Native audit trail for C3PAO assessors Passive Records what happened Active Detects as it happens — satisfies PE.L2-3.10.2 Visitor zones unmonitored PE.L1-3.10.3 gap risk Visitor alerts and movement log Satisfies PE.L1-3.10.3 documentation The requirement is present tense. A system that reviews footage later does not satisfy it.

IntelliSee's AI-powered video analytics platform turns existing security cameras into an active monitoring layer. Rather than recording activity for post-incident review, the system analyzes video feeds in real time and generates alerts when detection criteria are met — unauthorized presence in restricted areas, after-hours intrusion, visitor activity in sensitive zones, or individuals who deviate from established access patterns.

This distinction matters for CMMC compliance in three specific ways:

1. Real-Time Detection Creates Defensible Audit Evidence

CMMC assessors reviewing the PE domain will ask for evidence of monitoring activity — not just proof that cameras exist. AI-generated alerts, timestamps, and detection logs create a native audit trail that documents when the monitoring system activated, what it detected, and how the organization responded. That's the kind of artifact that supports a successful C3PAO assessment.

Traditional CCTV, by contrast, generates footage. Footage is evidence only if someone reviews it. An organization that can't demonstrate an active review process for camera footage has a monitoring gap, even if the cameras are technically operational.

2. Coverage of Support Infrastructure

PE.L2-3.10.2 explicitly includes support infrastructure — the power, HVAC, and cabling that keeps CUI systems running. AI video analytics applied to camera feeds covering these areas can detect unauthorized access to server rooms, utility closets, and network infrastructure zones in real time. This is a control that passive CCTV cannot provide: a camera records what happened, but AI analytics alerts when it's happening.

3. Visitor Monitoring Documentation

PE.L1-3.10.3 requires both escorting visitors and monitoring their activity. Visitor logs satisfy the escorting requirement. But "monitor visitor activity" implies active awareness of what visitors are doing while they're in the facility. AI video analytics applied to visitor access zones creates a documented record of visitor movement that goes beyond a sign-in sheet — and provides real-time alerts if a visitor accesses an area they shouldn't.

Data center server room representing CUI systems and support infrastructure covered by CMMC PE.L2-3.10.2 physical protection requirements
The support infrastructure clause in PE.L2-3.10.2 extends beyond the server room to the power, HVAC, and cabling that keep CUI systems running — every piece is in assessment scope.

The DHS SAFETY Act Designation: Why It Matters for Federal Contractors

IntelliSee holds DHS SAFETY Act Qualified Anti-Terrorism Technology (QATT) Designation — federal recognition that the platform meets the Department of Homeland Security's standards for anti-terrorism technology. For defense contractors evaluating physical security vendors to support CMMC compliance, this designation carries weight that no marketing claim can replicate.

DoD contractors are already operating in a federal compliance environment. Selecting a physical security monitoring solution that has been vetted at the federal level — not just commercially certified — aligns with the broader risk posture CMMC is designed to enforce. An assessor seeing DHS SAFETY Act designation in vendor documentation has a materially different conversation than one reviewing a standard commercial product sheet.

Deploying on Existing Camera Infrastructure

One of the most common objections to upgrading physical security monitoring is cost — specifically, the assumption that real monitoring requires tearing out existing cameras and replacing them with new hardware.

IntelliSee deploys on existing camera infrastructure. If your facility already has IP cameras, the AI analytics layer can be applied without a camera replacement cycle. For defense contractors who have cameras but lack active monitoring, this is the path of least resistance to PE.L2-3.10.2 compliance.

This also simplifies the SSP documentation process. Rather than documenting a newly installed physical security system, the System Security Plan can reference an enhanced monitoring layer applied to existing infrastructure — with verifiable detection logs as supporting evidence.

What CMMC Assessors Are Looking For in the Physical Walkthrough

Understanding what a C3PAO assessment team evaluates during the PE walkthrough helps contractors prepare more effectively. Based on the CMMC Assessment Guide for Level 2 and NIST SP 800-171A assessment objectives, assessors are looking for:

  • Operational monitoring systems — not just cameras, but evidence that monitoring is active and generates actionable output
  • Access logs that match the SSP description — badge logs, door access records, or video timestamps that confirm who accessed what areas and when
  • Visitor controls in practice — are visitors actually being escorted? Does the monitoring system cover visitor access zones?
  • Support infrastructure coverage — are server rooms, network closets, and utility areas physically protected and monitored?
  • Personnel awareness — do employees understand the physical security protocols? Can they describe what they're supposed to do when a visitor arrives?

A contractor who can point to an AI video analytics platform generating real-time alerts and maintaining a timestamped detection log is in a fundamentally stronger position than one who can only point to a DVR that records footage no one watches.

The Broader Compliance Picture

Physical security doesn't exist in isolation within CMMC. The PE domain connects directly to access control (AC), incident response (IR), and audit and accountability (AU) domains. A strong physical monitoring program produces audit artifacts that support multiple domain requirements simultaneously.

AI-powered monitoring scales across the compliance surface area in ways that human guards and passive cameras cannot. Detection logs feed audit requirements. Real-time alerts support incident response workflows. Documented coverage of support infrastructure demonstrates the layered security posture CMMC Level 2 is designed to verify.

For defense contractors working toward certification — or preparing for the C3PAO assessment queue that's growing as Phase 2 approaches in November 2026 — closing the physical monitoring gap now, with a system that generates defensible evidence, is the difference between a conditional CMMC status and a clean one.

The cameras are already there. The question is whether they're doing anything useful.

Learn how IntelliSee helps defense contractors meet CMMC physical protection requirements with AI video analytics that deploys on existing infrastructure.

Take the Next Step

Turn Your Cameras Into Proactive Protectors

See how IntelliSee layers real-time AI threat detection onto your existing surveillance infrastructure, with no camera replacement required.

Request a Demo