3.1 Access Control3 ptsPOA&M-eligible

3.1.19 — Encrypt CUI on mobile devices

Encrypt CUI on mobile devices and mobile computing platforms.

Phones, tablets, and laptops carrying CUI must be encrypted.

What it actually means

Encrypt CUI on mobile devices and mobile computing platforms — laptops, phones, tablets. Full-disk encryption on laptops and device encryption or MDM policy on phones and tablets satisfies this. Pair it with FIPS-validated cryptography (3.13.11).

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

A 3-point control. Overlaps with 3.13.16 (CUI at rest) — handle device encryption once, centrally, and it covers both.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.