Any CUI moving across a network you don't fully control must be encrypted.
What it actually means
When CUI travels over a network — email, file transfer, remote access, web — it must be protected with encryption unless an alternative physical safeguard protects it. In practice that means TLS for web and email, encrypted file transfer (SFTP/HTTPS), and a VPN for remote access. This pairs with 3.13.11, which adds the requirement that the cryptography be FIPS-validated.
Pass or fail — an assessor needs a "yes" to each
- Is CUI encrypted whenever it crosses a network (TLS, VPN, SFTP, encrypted email)?
- Have you eliminated cleartext paths (plain FTP, unencrypted SMTP) for CUI?
What to have ready
- Configuration showing TLS / VPN / SFTP for CUI flows
- Email encryption configuration (TLS enforced, or message-level encryption)
Where teams trip up
- Sending CUI by ordinary email with no transport encryption enforced
- Legacy plain-FTP or HTTP paths still in use for files
A 3-point control, and closely tied to 3.13.11 — encryption in transit must use FIPS-validated cryptography to fully satisfy both. Solve them together.
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.13.11 — FIPS-validated cryptography3.1.13 — Encrypting remote access3.13.16 — Encrypting CUI at rest
More in System & Communications Protection (3.13)
3.13.1 — Protect your boundaries3.13.2 — Build security in by design3.13.3 — Separate user and admin functions3.13.4 — Stop data leaking through shared resources3.13.5 — Wall off your public-facing systems3.13.6 — Deny all, permit by exception3.13.7 — Block split tunneling on VPNs3.13.9 — Drop idle network sessions3.13.10 — Manage your encryption keys3.13.11 — FIPS-validated cryptography3.13.12 — Control cameras and microphones3.13.13 — Control mobile code3.13.14 — Control and monitor VoIP3.13.15 — Protect session authenticity3.13.16 — Encrypt CUI at rest