Most defense contractors spend months preparing for CMMC 2.0. They document their access controls, configure their SSP, and work through 110 NIST SP 800-171 requirements line by line. Then an assessor walks through the front door and asks to see the physical facility.
That's when the gaps show up.
The Physical Protection domain — Domain PE in CMMC's 14-domain framework — doesn't care how clean your network architecture looks on paper. An assessor conducting a Level 2 certification assessment will physically tour your facility, inspect your access points, and verify that what your System Security Plan describes actually exists in the real world. A locked front door is not a physical security program. Neither is a single camera mounted in the lobby.
As of November 10, 2025, the CMMC Acquisition Rule (48 CFR) went into effect. CMMC requirements are appearing in live DoD solicitations now. If you handle Controlled Unclassified Information (CUI) and haven't closed your physical security gaps, you're behind.
What the CMMC Physical Protection Domain Actually Requires
The PE domain contains six requirements spread across CMMC Levels 1, 2, and 3. They're not technically complex — but they are exacting, and they require documented, observable evidence, not just written policies.
Level 1: The Foundation
Four requirements apply at Level 1, the baseline tier covering contractors who handle Federal Contract Information (FCI):
- PE.L1-3.10.1: Limit physical access to organizational information systems, equipment, and their operating environments to authorized individuals only.
- PE.L1-3.10.3: Escort visitors and monitor visitor activity in areas where FCI is stored or processed.
- PE.L1-3.10.4: Maintain audit logs of physical access.
- PE.L1-3.10.5: Control and manage physical access devices — keys, badges, keycards, PIN combinations, and any other credentials that grant access to protected areas.
These aren't abstract IT controls. They require real infrastructure: door locks, badge systems, visitor logs, and a documented process for revoking access when employees leave. If a terminated employee still has an active badge, you fail PE.L1-3.10.5. If visitors walk unescorted through areas where CUI systems are present, you fail PE.L1-3.10.3.
Level 2: Monitoring Becomes Mandatory
Level 2 adds one requirement that dramatically changes the scope of what's needed:
- PE.L2-3.10.2: Protect and monitor the physical facility and support infrastructure for organizational systems.
The word "monitor" is doing significant work here. The CMMC model explicitly identifies video surveillance, sensors, alarms, and human guards as the mechanisms that satisfy this requirement. A facility with locked doors but no active monitoring for after-hours intrusion satisfies the letter of "protection" but not the monitoring obligation. Both elements must be present and documented.
Support infrastructure is also in scope. Power systems, HVAC, and network cabling that serves CUI systems all fall under PE.L2-3.10.2. A locked server room with an unlocked utility closet housing that server's power distribution is an incomplete control — and assessors know to look for exactly this kind of gap.
Level 3: Alternate Work Sites
Level 3 adds requirements around remote work environments where CUI is accessed. For most contractors, this means formalizing physical safeguards for employees working from home — company-managed devices, VPN enforcement, and documented policies that employees have acknowledged.
Why Physical Security Produces More Assessment Failures Than Any Other Domain
The gap isn't usually ignorance of the requirements. Most contractors know what PE.L2-3.10.2 says. The problem is the distance between what's written in a System Security Plan and what actually exists in the facility.
For small defense contractors — particularly in manufacturing, aerospace components, and defense supply chain fabrication — physical security programs have often been informal. A front desk, some cameras that record to a local DVR, and a visitor sign-in sheet covers the basics for day-to-day operations. That's not a CMMC-compliant monitoring program.
CMMC assessors evaluate the PE domain through all three examination methods: document review, interviews with personnel, and physical testing. The physical testing component is what separates PE from most other domains. Assessors will walk your floor. They'll check whether access-controlled doors actually lock, whether monitoring systems are operational, whether visitor protocols are enforced in practice, and whether the people who work there understand the policies.
A written policy that no one follows is worse than no policy — it signals to an assessor that compliance posture across other domains may be equally informal.
How AI Video Analytics Satisfies the PE.L2-3.10.2 Monitoring Requirement
The monitoring requirement at Level 2 calls for active, documented surveillance of the physical facility and its infrastructure. Traditional CCTV addresses one piece of this: it records. But recording is not monitoring.
A passive camera system that stores footage on a DVR and gets reviewed only after an incident has occurred satisfies neither the spirit nor the letter of PE.L2-3.10.2. The requirement is to protect and monitor — present tense, ongoing, capable of detecting and responding to physical access events as they happen.
IntelliSee's AI-powered video analytics platform turns existing security cameras into an active monitoring layer. Rather than recording activity for post-incident review, the system analyzes video feeds in real time and generates alerts when detection criteria are met — unauthorized presence in restricted areas, after-hours intrusion, visitor activity in sensitive zones, or individuals who deviate from established access patterns.
This distinction matters for CMMC compliance in three specific ways:
1. Real-Time Detection Creates Defensible Audit Evidence
CMMC assessors reviewing the PE domain will ask for evidence of monitoring activity — not just proof that cameras exist. AI-generated alerts, timestamps, and detection logs create a native audit trail that documents when the monitoring system activated, what it detected, and how the organization responded. That's the kind of artifact that supports a successful C3PAO assessment.
Traditional CCTV, by contrast, generates footage. Footage is evidence only if someone reviews it. An organization that can't demonstrate an active review process for camera footage has a monitoring gap, even if the cameras are technically operational.
2. Coverage of Support Infrastructure
PE.L2-3.10.2 explicitly includes support infrastructure — the power, HVAC, and cabling that keeps CUI systems running. AI video analytics applied to camera feeds covering these areas can detect unauthorized access to server rooms, utility closets, and network infrastructure zones in real time. This is a control that passive CCTV cannot provide: a camera records what happened, but AI analytics alerts when it's happening.
3. Visitor Monitoring Documentation
PE.L1-3.10.3 requires both escorting visitors and monitoring their activity. Visitor logs satisfy the escorting requirement. But "monitor visitor activity" implies active awareness of what visitors are doing while they're in the facility. AI video analytics applied to visitor access zones creates a documented record of visitor movement that goes beyond a sign-in sheet — and provides real-time alerts if a visitor accesses an area they shouldn't.
The DHS SAFETY Act Designation: Why It Matters for Federal Contractors
IntelliSee holds DHS SAFETY Act Qualified Anti-Terrorism Technology (QATT) Designation — federal recognition that the platform meets the Department of Homeland Security's standards for anti-terrorism technology. For defense contractors evaluating physical security vendors to support CMMC compliance, this designation carries weight that no marketing claim can replicate.
DoD contractors are already operating in a federal compliance environment. Selecting a physical security monitoring solution that has been vetted at the federal level — not just commercially certified — aligns with the broader risk posture CMMC is designed to enforce. An assessor seeing DHS SAFETY Act designation in vendor documentation has a materially different conversation than one reviewing a standard commercial product sheet.
Deploying on Existing Camera Infrastructure
One of the most common objections to upgrading physical security monitoring is cost — specifically, the assumption that real monitoring requires tearing out existing cameras and replacing them with new hardware.
IntelliSee deploys on existing camera infrastructure. If your facility already has IP cameras, the AI analytics layer can be applied without a camera replacement cycle. For defense contractors who have cameras but lack active monitoring, this is the path of least resistance to PE.L2-3.10.2 compliance.
This also simplifies the SSP documentation process. Rather than documenting a newly installed physical security system, the System Security Plan can reference an enhanced monitoring layer applied to existing infrastructure — with verifiable detection logs as supporting evidence.
What CMMC Assessors Are Looking For in the Physical Walkthrough
Understanding what a C3PAO assessment team evaluates during the PE walkthrough helps contractors prepare more effectively. Based on the CMMC Assessment Guide for Level 2 and NIST SP 800-171A assessment objectives, assessors are looking for:
- Operational monitoring systems — not just cameras, but evidence that monitoring is active and generates actionable output
- Access logs that match the SSP description — badge logs, door access records, or video timestamps that confirm who accessed what areas and when
- Visitor controls in practice — are visitors actually being escorted? Does the monitoring system cover visitor access zones?
- Support infrastructure coverage — are server rooms, network closets, and utility areas physically protected and monitored?
- Personnel awareness — do employees understand the physical security protocols? Can they describe what they're supposed to do when a visitor arrives?
A contractor who can point to an AI video analytics platform generating real-time alerts and maintaining a timestamped detection log is in a fundamentally stronger position than one who can only point to a DVR that records footage no one watches.
The Broader Compliance Picture
Physical security doesn't exist in isolation within CMMC. The PE domain connects directly to access control (AC), incident response (IR), and audit and accountability (AU) domains. A strong physical monitoring program produces audit artifacts that support multiple domain requirements simultaneously.
AI-powered monitoring scales across the compliance surface area in ways that human guards and passive cameras cannot. Detection logs feed audit requirements. Real-time alerts support incident response workflows. Documented coverage of support infrastructure demonstrates the layered security posture CMMC Level 2 is designed to verify.
For defense contractors working toward certification — or preparing for the C3PAO assessment queue that's growing as Phase 2 approaches in November 2026 — closing the physical monitoring gap now, with a system that generates defensible evidence, is the difference between a conditional CMMC status and a clean one.
The cameras are already there. The question is whether they're doing anything useful.
Learn how IntelliSee helps defense contractors meet CMMC physical protection requirements with AI video analytics that deploys on existing infrastructure.