- Make sanitization a gate in the RMA and service workflow, not a memory test: no equipment leaves without a sanitization or media-removal record attached to the ticket.
- Hunt the non-obvious storage — printer and copier drives, controller SD cards, appliance flash — which is where this requirement actually fails.
- Where a failed drive cannot be wiped, keep-your-drive contract clauses or documented destruction do the work instead.
3.7.3 — Off-site maintenance sanitization
3.7 Maintenance · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.
Ensure equipment removed for off-site maintenance is sanitized of any CUI.
NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A — Assessing Security Requirements for CUI ↗What this requirement is after
A server sent for repair, a copier returned to the leasing company, a laptop shipped back under warranty — anything leaving for off-site service is scrubbed of CUI first. The failure mode is the storage nobody thought about inside the device.
The standalone slot (03.07.03) is withdrawn in Rev. 3; equipment sanitization before off-site maintenance travels with the consolidated Maintenance Tools requirement, 03.07.04.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Sanitization records tied to service and RMA tickets
- A documented procedure naming approved sanitization methods per media type
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this lands in Rev. 3
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |