3.13 System & Communications Protection3 ptsPOA&M-eligible

3.13.8 — Encrypt CUI in transit

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

Any CUI moving across a network you don't fully control must be encrypted.

What it actually means

When CUI travels over a network — email, file transfer, remote access, web — it must be protected with encryption unless an alternative physical safeguard protects it. In practice that means TLS for web and email, encrypted file transfer (SFTP/HTTPS), and a VPN for remote access. This pairs with 3.13.11, which adds the requirement that the cryptography be FIPS-validated.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

A 3-point control, and closely tied to 3.13.11 — encryption in transit must use FIPS-validated cryptography to fully satisfy both. Solve them together.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.