- Decide the model — corporate-owned enrolled devices, personal devices with a managed container, or no mobile CUI at all — and write it down.
- Enforce encryption and passcode requirements technically through MDM or app-protection policy, not through an acceptable-use memo alone.
- Bound what the container can do: cut copy-paste and save-to-personal-storage paths out of the CUI applications.
03.01.18 — Access Control for Mobile Devices
03.01 Access Control · NIST SP 800-171 Rev. 3
Requires establishing usage restrictions, configuration requirements, and connection requirements for mobile devices; authorizing the connection of mobile devices to the system; and implementing full-device or container-based encryption to protect the confidentiality of CUI on mobile devices (aligned to SP 800-53 AC-19 with the CUI-encryption enhancement).
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
Phones and tablets touch CUI only on your terms: enrolled or containerized, configured to written rules, and encrypted — the whole device or a managed work container. For most small contractors the honest options are two: corporate-enrolled devices with enforced encryption, or app-protection containers around mail and files on personal phones. Unmanaged company mail on a personal phone is the standing violation.
Merges Rev. 2's mobile connection control (3.1.18) and CUI encryption on mobile devices (3.1.19); the encryption duty survives intact as an explicit element, with full-device and container-based encryption both recognized.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- The mobile-device standard with usage restrictions and the authorization model
- MDM or app-protection policy exports showing encryption enforced
- Enrollment reports showing the devices with CUI access under management
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |