Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.1.19OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.1.19CUI encryption on mobile

3.1 Access Control · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Encrypt CUI on mobile devices and mobile computing platforms.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Any CUI that lands on a mobile device or mobile computing platform sits under encryption, so a lost phone or laptop bag is an inconvenience rather than an incident. Enforcement, not user diligence, is what makes this true.

Across revisions

Withdrawn as a standalone slot in Rev. 3 (03.01.19); mobile encryption is carried inside Access Control for Mobile Devices, 03.01.18.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Enforce full-device encryption through device management and treat an unencrypted device as failing posture, blocked from CUI-bearing services.
  • Where CUI confidentiality rests on the encryption, FIPS-validated cryptographic modules become relevant — check the platform's validation status rather than assuming.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Device management posture reports showing encryption enforced across enrolled devices
  • The policy configuration requiring encryption before access
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated