
Closing the CMMC Gap: Visitor Management for Defense Contractors
Status as of September 2026: CMMC Phase 1 self-assessment is in force. DoD suspended Phase 2 on July 13, 2026 pending a program review, so the C3PAO assessment date this paper was written against is no longer fixed. The physical-access evidence below is required under either timeline. Verify current status at dodcio.defense.gov.
How purpose-built visitor management maps directly to CMMC Level 2 physical security controls — and why generic solutions put your contracts at risk.
Three Controls You Cannot Defer
The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework codifies 110 security practices required for Department of Defense contract retention. Six Physical Protection (PE) controls govern facility access, visitor escorts, and compliance documentation.
Three of the six PE controls cannot be deferred on a Plan of Action & Milestones (POA&M). This means your visitor management system must satisfy these requirements at the time of assessment — not as a future remediation item.
Non-Deferrable Controls
PE.L2-3.10.3 (Escort Visitors), PE.L2-3.10.4 (Audit Logs), and PE.L2-3.10.5 (Access Devices) must be fully operational at the time of assessment. Retroactive remediation will not satisfy these controls.
Physical Security Controls in CMMC Level 2
CMMC Level 2 aligns with NIST SP 800-171, Revision 2. Requirements apply to contractors handling Controlled Unclassified Information (CUI) across 14 domains.
The Physical Protection domain defines six controls that directly govern how visitors are screened, escorted, tracked, and documented at defense contractor facilities.
Limit Physical Access
Limit physical access to organizational information systems, equipment, and operating environments to authorized individuals.
Protect and Monitor the Physical Facility
Protect and monitor the physical facility and support infrastructure.
Escort Visitors
Escort visitors and monitor visitor activity. Every visitor in a CUI-adjacent space must have a designated escort.
Maintain Audit Logs
Maintain audit logs of physical access. Every check-in, check-out, escort assignment, badge issuance, and access event must be recorded in tamper-evident logs.
Control Physical Access Devices
Control and manage physical access devices (keys, badges, access cards). Visitor badges must be tracked from issuance through return or deactivation.
Enforce Safeguarding at Alternate Sites
Enforce safeguarding measures for CUI at alternate work sites. Visitor management policies must extend uniformly to every site where CUI is handled.
Why Traditional VMS Solutions Fall Short
Most of the visitor management market is built for corporate offices, co-working spaces, and commercial real estate — environments with very different security requirements than CUI-handling facilities. Vendors in this space typically optimize for visitor experience, not for the kind of evidence a CMMC assessor expects to see.
Hospitality-first VMS products excel at lobby check-ins, tablet UX, and notifications. That is a real product strength, not a critique. The point is that design goals matter — and a product whose design goal is visitor experience is unlikely to also satisfy the evidence-driven obligations in the PE family of NIST 800-171 without significant gaps.
The Critical Gaps
ITAR/EAR Screening
Generic VMS platforms typically do not capture citizenship or foreign-person status against ITAR. Without that data, a foreign national entering an ITAR-controlled area can create deemed-export exposure under 22 CFR § 120.54 — even if the front desk had no way to know.
OFAC Sanctions
None of the major commercial VMS platforms check visitors against the OFAC SDN list in real time. Screening occurs at pre-registration and again at check-in to catch list updates between booking and arrival.
Escort Enforcement
Most systems allow optional escort fields. Optional does not satisfy PE.L2-3.10.3. An assessor will test whether a visitor can be checked in without an assigned escort — and if the answer is yes, you fail the control.
Audit Log Integrity
SaaS platforms routinely allow administrators to edit or delete records. For PE.L2-3.10.4, audit logs must be tamper-evident. If a database admin can retroactively alter a check-in record, the log has no evidentiary value.
Badge Lifecycle
Printing a visitor badge is not the same as managing one. PE.L2-3.10.5 requires tracking issuance, active use, return, and deactivation — a full chain of custody.
Multi-Site Enforcement
PE.L2-3.10.6 requires consistent controls across all facilities. Most VMS platforms offer per-location configuration, not centrally enforced compliance policies.
Commercial VMS platforms optimize for visitor experience. Defense contractors need systems that optimize for compliance evidence. These are fundamentally different design goals, and bolting compliance features onto a hospitality platform creates gaps that assessors are trained to find.
How SecurePoint USA Maps to CMMC Level 2
Control-by-control mapping showing where SecurePoint produces direct evidence, where it only supports, and where it claims nothing, for each Physical Protection requirement.
| CMMC Control | Requirement | SecurePoint USA | POA&M |
|---|---|---|---|
| PE.L2-3.10.1Limit Physical AccessSupporting | Limit physical access to organizational information systems, equipment, and operating environments to authorized individuals. | Supporting. Pre-registration approval, host authorization and ID capture establish who is authorized, and badge issuance is gated on the evidence the site requires. SecurePoint authorises the person; your facility enforces the physical boundary. | Eligible |
| PE.L2-3.10.2Protect and Monitor the Physical FacilityDeployment-dependent | Protect and monitor the physical facility and support infrastructure. | Deployment-dependent. SecurePoint shows who is on site and for how long, and flags overdue check-outs. It does not monitor the facility itself: there is no CCTV or access-control-system integration and no location tracking. Facility monitoring remains yours. | Eligible |
| PE.L2-3.10.3Escort VisitorsDirect evidence | Escort visitors and monitor visitor activity. Every visitor in a CUI-adjacent space must have a designated escort. | Direct. Escort assignment is recorded against the visit, escort start and end are captured as events, and where a site requires an escort the badge is gated on it. The escort record exports with the rest of the visit evidence. | No |
| PE.L2-3.10.4Maintain Audit LogsDirect evidence | Maintain audit logs of physical access. Every check-in, check-out, escort assignment, badge issuance, and access event must be recorded in tamper-evident logs. | Direct. Append-only audit trail: update and delete are refused by the database rather than discouraged in the application, and each row is hash-chained to the previous one per organization. Exportable for assessor review. | No |
| PE.L2-3.10.5Control Physical Access DevicesSupporting | Control and manage physical access devices (keys, badges, access cards). Visitor badges must be tracked from issuance through return or deactivation. | Supporting. Badge issuance and badge return are recorded against the visit and export with it, so an unreturned badge is visible rather than assumed. The physical badge stock, and any electronic credential system, remain under your control. | No |
| PE.L2-3.10.6Enforce Safeguarding at Alternate SitesNot claimed | Enforce safeguarding measures for CUI at alternate work sites. Visitor management policies must extend uniformly to every site where CUI is handled. | Not claimed. This control concerns safeguarding CUI at alternate work sites. SecurePoint supports per-site configuration and multi-site visibility for the facilities it runs in, which is not the same thing. We do not claim this control. | Eligible |
Built Different for Defense
ITAR/EAR Visitor Screening
The International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) impose controls on who can access defense-related technical data. Allowing a foreign person to view, hear, or be present where controlled technical data is disclosed can constitute a “deemed export” under 22 CFR § 120.54, with significant civil and criminal exposure. Penalty maximums change; consult current DDTC and BIS guidance for current numbers.
SecurePoint USA screens every visitor against ITAR/EAR criteria during pre-registration. Foreign person status is evaluated, citizenship is verified, and license exception eligibility is determined before the visitor arrives on site. If a visitor does not clear screening, the system prevents badge issuance entirely — removing human judgment from a high-consequence decision.
OFAC Sanctions Checks
Every visitor is automatically screened against the OFAC Specially Designated Nationals and Blocked Persons (SDN) list, the Entity List, and the Denied Persons List. Screening occurs at pre-registration and again at check-in to catch list updates between booking and arrival.
Matches trigger an automatic hold and compliance officer notification — no badge is issued until the match is resolved.
Escort Enforcement
SecurePoint USA does not treat escort assignment as a data field — it treats it as a workflow gate. The system requires:
- 1A designated escort selected from the authorized personnel roster
- 2Escort notification delivered via the platform
- 3Escort acknowledgment confirming availability and acceptance
If the escort does not confirm within a configurable window, the system escalates to backup escorts and security management. At no point can a visitor receive a badge without a confirmed escort — producing the escort record PE.L2-3.10.3 is assessed against. The practice is assessed against your organization, not against a vendor.
Immutable Audit Trails
Every action in SecurePoint USA generates an append-only, cryptographically hashed log entry. Records cannot be edited, deleted, or backdated — by anyone, including system administrators. This design produces the tamper-evident physical-access log PE.L2-3.10.4 is assessed against, and provides assessors with the evidentiary confidence they need.
Audit data is exportable in CSV, PDF, and structured JSON formats, with date-range filtering, visitor search, and control-specific report templates designed to match common C3PAO assessment request formats.
Built for Defense Contractors
Procurement identifiers and SAM.gov evidence are provided during sales/procurement review after the evidence capture checklist is complete. SecurePoint USA does not represent GSA Schedule, FedRAMP authorization, SOC 2, ISO, CMMC certification, or endorsement by any government.
The Financial Exposure You Cannot Ignore
Defense contractors often underestimate the financial exposure created by inadequate visitor management. The penalties are not theoretical — they are actively enforced.
ITAR Violations
ITAR civil penalties reach up to $1,000,000 per violation. A single unauthorized foreign person accessing controlled technical data constitutes a violation. Multiple visitors, multiple days, multiple violations — penalties compound rapidly.
Criminal penalties include fines up to $1,000,000 and imprisonment of up to 20 years per violation. The Directorate of Defense Trade Controls (DDTC) does not require intent — strict liability means even accidental exposure creates enforcement risk.
Debarment from DoD Contracts
ITAR violations and CMMC assessment failures can result in debarment — the loss of eligibility to receive Department of Defense contracts. For contractors whose revenue depends on defense work, debarment is existential. It does not merely pause revenue; it eliminates the entire business model.
CMMC Assessment Failure
A failed CMMC Level 2 assessment means your organization cannot bid on or perform contracts requiring CUI handling. Because three PE controls cannot be deferred on a POA&M, a visitor management gap discovered during assessment results in an immediate failure that requires reassessment.
The cost of reassessment is not just the C3PAO engagement fee. It includes the months of scheduling delay, the contracts you cannot bid on during the gap, and the reputational damage with prime contractors who need compliant subcontractors now.
The Math Is Simple
A purpose-built CMMC visitor management solution costs a fraction of a single ITAR violation. It costs a fraction of a failed assessment and reassessment cycle. And it costs an infinitesimal fraction of the contract revenue at risk from debarment.
Close the Gap Before Your Assessment
Your CMMC Level 2 assessment will test your visitor management controls. Three of six PE controls cannot be deferred. The time to implement is before the assessor arrives — not after.
SecurePoint USA delivers a compliance-ready visitor management platform purpose-built for defense contractors — with ITAR screening, OFAC checks, escort enforcement, and immutable audit trails mapped directly to every PE control.
Frequently asked questions
Does SecurePoint make our organization CMMC compliant?
No. CMMC compliance is a program your organization runs and an assessment it passes. SecurePoint is one internal control inside that program: it screens visitors, records host and escort assignment, gates badge issuance, and produces the physical-access records an assessor can review. The obligation stays with your organization.
Which CMMC Level 2 controls does visitor management touch?
The Physical Protection family runs PE.L2-3.10.1 through PE.L2-3.10.6. Visitor management does not touch them equally. SecurePoint produces direct evidence for 3.10.3 (escort visitors and monitor visitor activity) and 3.10.4 (maintain audit logs of physical access). It supports 3.10.1 and 3.10.5 without being sufficient for them on its own, contributes only partially to 3.10.2, and does not address 3.10.6, which concerns alternate work sites. Confirm your assessment scope with your C3PAO.
Is a paper sign-in sheet enough for the physical protection controls?
A sign-in sheet records that someone signed in. The PE controls also ask you to show that visitors were escorted and monitored, that access devices were controlled, and that a durable audit log of physical access exists. What satisfies your assessor depends on your scope, so confirm it with your C3PAO rather than assuming any single artifact is sufficient.
What visitor evidence can we hand to an assessor?
Evidence packs bundle visit activity, screening results, adjudication decisions, and the audit trail into a single export with SHA-256 checksums, scoped to the date range and sites you select. The audit trail itself is append-only, with update and delete refused at the database.
Is sanctions screening part of CMMC?
No. The CMMC Physical Protection controls are about who may enter, who escorts them, and what is logged. Restricted-party screening is a separate obligation under OFAC and export-control rules. Many defense facilities run both, which is why SecurePoint records them against the same visit, but they answer to different regimes.
Informational only. This whitepaper is provided for general informational purposes only and does not constitute legal, regulatory, export-control, or compliance advice. It is not a substitute for review by qualified counsel, a C3PAO, your Facility Security Officer (FSO), an export-control officer, or other advisor familiar with your specific contracts and facilities.
Regulatory citations and statistics reflect publicly available information believed to be accurate as of the “Last reviewed” date in the PDF version. Regulations and enforcement priorities change; verify current text with primary sources before acting on anything in this document. © 2026 SecurePoint USA. All rights reserved.