CMMC Backup Requirements and The Myths Worth Ignoring

In this article
There is a sales pitch making the rounds that makes CMMC harder than it needs to be. It goes something like this. If you do not buy our backup solution, you will fail your assessment. It sounds urgent, it sounds official, and it is mostly wrong.
We keep running into this one, so let’s set the record straight. Backups matter for your business. They are not, on their own, a NIST SP 800-171 requirement in the way many vendors imply. Here is what the requirement actually says, why it reads that way, and how to tell solid guidance from a scare tactic.
A quick note before we start. This is general education from our consulting and assessment team, not formal consulting or legal advice, and interpretations can vary by assessor.
Does NIST SP 800-171 Require You to Have Backups?
Short answer, no. Nothing in NIST SP 800-171 Rev. 2, the version in effect now, requires you to run backups in order to pass a CMMC assessment. If someone tells you an assessor will fail you for not having backups, that is not how the requirement works.
Now the important caveat. We strongly recommend you keep backups anyway. Any cybersecurity professional would. Build a solid backup architecture for your core infrastructure, and test it, because an untested backup is not a backup you can count on. Redundancy protects your business. Just do not confuse a smart business practice with a CMMC pass or fail line.
What Does 800-171 Actually Require for Backups?
The requirement is narrow. If you do keep backups of CUI, you have to protect the confidentiality of those backups. That is control 3.8.9, and it sits under Media Protection, not under any availability or recovery family.
In practice that means protecting backup CUI through physical security or through encryption. Encryption is the approach we most often see used, and we have seen it hold up well in real assessments. The assessment objective is straightforward. The confidentiality of backup CUI is protected at its storage locations. That is the whole scope of backups for the assessment. Not your backup schedule. Not your retention period. Not whether you can restore inside four hours. Only whether the CUI in those backups is protected.
Why Do Backups Fall Under Confidentiality and Not Availability?
This is where the CIA triad helps. Most security frameworks protect three things. Confidentiality keeps information away from people who should not see it. Integrity keeps data accurate and in its original form. Availability keeps information reachable for the people who need it.
NIST SP 800-171 deliberately covers only one of the three. It protects the confidentiality of CUI on non-federal systems. The Department of War made that call as a cost reduction decision for the defense industrial base. Full triad frameworks already exist for federal systems and higher classification information, like RMF and NIST SP 800-53. For CUI on a contractor network, the government decided the priority is keeping the information out of the wrong hands. How you handle availability and integrity is your business decision, unless a specific contract says otherwise, in which case you meet that contract on its own terms.
Here is the part that trips people up. Control 3.8.9 traces back to a NIST SP 800-53 control called CP-9, contingency planning. In the federal world, backups support contingency operations, redundancy, and availability. So, people see that lineage and assume 800-171 must be demanding backups for availability. It is not. 800-171 borrowed only the confidentiality slice of that idea. The message is simple. If you do backups, protect them, and do not get distracted by the availability background the control came from.
What About Backing Up CUI to the Cloud?
A couple of years ago the Department of War made a point that still matters here. Encrypted CUI is still CUI. That came up specifically around backups. Encrypting your data before it leaves your hands does not change what it is or take it out of scope. Encryption is a control that protects the data while it stays in scope.
So if you back up CUI to the cloud, that destination is expected to be a FedRAMP Moderate or FedRAMP Moderate equivalent environment, even when you encrypt the data before sending it. Encryption protects confidentiality. The FedRAMP expectation reflects that the CUI is still CUI wherever it lands.
How Do Assessors Actually Look at Backups?
The Department of War took a risk-based, plan-driven approach. Show us how you protect backup CUI, put it in your plan, then show us you actually do what the plan says. An assessor looks for the method. Are you using physical protection. Are you using encryption. Either can work, and we have seen both used successfully, as long as the confidentiality of the backup CUI is genuinely protected at its storage location and matches what you documented.
What an assessor is not doing is auditing your disaster recovery program. They are not grading your recovery time or your retention policy against 800-171. If you have backups, the question is whether you are protecting them.
How Do You Spot Backup Compliance Misinformation?
Trust your gut, then verify against the source. When a vendor uses CMMC or 800-171 as the reason you must buy a product, they are sometimes right and sometimes not. Some marketers know the pitch, not the requirement. The tell is usually a fail your assessment threat attached to a feature that 800-171 never actually mandates.
The fix is boring and it works. Read the requirement. Read NIST SP 800-171. If you want bonus points, read the assessment guide, NIST SP 800-171A, which lays out the objectives an assessor uses. There is real interpretation bias in this ecosystem, and the best defense is knowing what the words on the page say so nobody can talk you into a requirement that is not there.
Where Do the Backup Rules Actually Come From?
If you ever need to stand your ground with an assessor, it helps to know the paper trail.
NIST SP 800-171 is a requirement under DFARS 252.204-7012, the safeguarding clause in defense contracts, and its assessment objectives live in NIST SP 800-171A, published through the Department of War CIO’s office. Some contracts now also carry the CMMC clause, DFARS 252.204-7021, which is why that assessment guide keeps mattering.
One level up sits 32 CFR Part 2002, the Controlled Unclassified Information Program, run by the Information Security Oversight Office. It splits information systems into federal and non-federal, and it states plainly that agencies must use NIST SP 800-171 to protect the confidentiality of CUI Basic on non-federal systems. The exception is CUI Specified, where an underlying law or regulation adds its own safeguarding rules. Categories like Naval Nuclear Propulsion Information and Export Control carry that extra authority.
Knowing where a rule lives is what lets you prove your position instead of just asserting it. If you and an assessor read a requirement differently, the regulation is the ground you stand on.
The Bottom Line
Backups are good business and we recommend them. They are not a standalone CMMC requirement. What 800-171 asks is narrow and clear. If you keep backups of CUI, protect their confidentiality, usually through encryption, and store cloud backups in a FedRAMP Moderate or equivalent environment. Everything past that is your architecture decision, not an assessment pass or fail line.
Subscribers to the Kieri Compliance Documentation and the Kieri Reference Architecture get check-ins with our team, and a claim like this is exactly the kind of thing worth running past us first. Not sure whether a vendor pitch matches the actual requirement? Schedule a free consultation with our certified CMMC assessors and we will help you read it against the source.
Frequently Asked Questions
Does CMMC or NIST SP 800-171 require you to have backups?
No. NIST SP 800-171 Rev. 2 does not require backups to pass a CMMC assessment. It requires that if you keep backups of CUI, you protect their confidentiality under control 3.8.9. Backups are still strongly recommended as good practice.
What does NIST SP 800-171 control 3.8.9 require?
It requires you to protect the confidentiality of backup CUI at its storage locations, and it sits under Media Protection. Encryption or physical protection are the common ways to meet it.
Do you have to encrypt CUI backups?
Encryption is the method most commonly used to protect backup confidentiality, and we have seen it hold up in assessments. Physical protection can also meet the requirement. Cloud backups are expected to sit in a FedRAMP Moderate or equivalent environment even when the data is encrypted first.
Does 800-171 focus on availability and integrity?
No. It focuses on the confidentiality of CUI. A few requirements can produce an incidental integrity or availability benefit, but that is not the focus. RMF and NIST SP 800-53 cover the full CIA triad.
Will an assessor check my backup schedule and retention period?
No. Assessors check whether backup CUI is protected at its storage location. They are not grading your recovery time, backup schedule, or retention policy against 800-171.
Evidence Review
Thorough examination of your compliance evidence. We verify documentation completeness.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.


























































