3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.16 — Encrypt CUI at rest

Protect the confidentiality of CUI at rest.

CUI sitting on disks, laptops, and drives should be encrypted.

What it actually means

Protect the confidentiality of CUI at rest — stored on servers, workstations, laptops, and removable media. Full-disk encryption (BitLocker, FileVault) on every device that holds CUI is the standard approach, plus encryption for backups and removable media. Pair it with FIPS-validated cryptography (3.13.11).

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

To fully satisfy this alongside 3.13.11, the at-rest encryption must be FIPS-validated. Most BitLocker / FileVault deployments can run in a FIPS-validated mode.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.