Skip to content

CMMC and NIST SP 800-171

Thirteen of the fourteen CMMC families are an IT problem. One of them is your front door.

If a prime has sent you a document with CMMC on the front, most of it belongs to a qualified compliance advisor. The Physical Protection family does not. It describes what happens at your reception desk, and it is the part a UK manufacturer can usually close quickly and cheaply.

From £150 a month plus VAT. We are not assessors and a kiosk is not certification —what that means.

Where reception fits

The five requirements that describe your front desk

CMMC is a verification programme layered on requirements that already existed. At Level 2 the security requirements are the 110 in NIST SP 800-171 Revision 2, grouped into fourteen families. Thirteen concern your IT. Physical Protection, family 3.10, concerns your building — and five of its requirements land directly on the person at reception.

3.10.1

Limit physical access to authorised individuals

Decide in advance who is allowed in, and be able to show the decision was made rather than assumed. Somebody standing in reception is not an authorisation.

3.10.2

Protect and monitor the facility

The building and the infrastructure that supports it: the boundary, what crosses it, and who is watching. Most of this is locks and layout rather than software.

3.10.3

Escort visitors and monitor visitor activity

Visitors accompanied in non-public areas, with a record of who escorted whom. Written down as a rule, not just observed as a habit.

3.10.4

Maintain audit logs of physical access

Timestamped in and out, still retrievable months later. The standard is explicit that this log may be procedural, automated, or a mix of both.

3.10.5

Control and manage physical access devices

An inventory of the badges, fobs and keys that open things: what opens what, who is holding it, and what happens the day one goes missing.

Read plainly, that list describes knowing who is in the building, deciding in advance whether they are allowed to be, keeping them accompanied while they are, holding a record afterwards, and keeping control of the things that open doors. Most factories already do four of the five informally. The gap is almost always evidence.

Where the programme stands, September 2026. The DFARS rule took effect in November 2025 and its first phase put Level 1 and Level 2 self-assessment into new Department of Defense solicitations. In July 2026 the later phases — the ones requiring a third party certification — were suspended pending a review. None of that changed section 3.10 itself. If your customer has given you a date, work to their date, and confirm the current position with your own advisor rather than with this page.

The awkward part

Three questions a hardback book cannot answer

Nobody is going to fail you for owning a paper book. The standard does not mandate any particular system, and says so. What it asks is whether you can demonstrate the control — and that is where a book struggles.

“Show me everyone who entered the restricted area last March.”

A book at the front desk records arrival at a building, not movement within one. If part of your site is designated as needing extra control, the book cannot evidence who crossed that line.

“Who authorised this person, and when?”

A signature is a record that somebody was present. It is not a record that anyone approved them beforehand. Authorisation that happens implicitly is difficult to evidence at all.

“Where is this month’s log?”

In a drawer, mostly. Possibly water damaged, frequently illegible, and carrying every other visitor’s name and company on the same open page — which in the UK is its own problem.

The visitor history screen filtered to a single day, listing six visitors with their company, host, and sign in and sign out times, beside an Export CSV button
Any day, filtered and exported, with the time somebody arrived and the time they left against the name of the person they came to see.

None of these are reasons to buy software. They are reasons to be honest with yourself about what your current record actually proves.

What the kiosk produces

The evidence those five requirements ask for

Approval captured before the visit starts

The visitor enters their details and who they are here to see. The host is notified and approves on screen by PIN. No approval, no badge. The approval is stored against a named member of your staff with the time on it.

Relates to 3.10.1, 3.10.3

A timestamped log you can actually retrieve

In and out, against a name, tied to the person they came to see. When somebody asks who was on site on a given day, you filter and export rather than spending an afternoon on it.

Relates to 3.10.4

A visible difference between escorted and cleared

A printed badge with colour coded lanyards, so anyone on the floor can see at a glance whether the person in front of them needs accompanying. Every issue and return is logged.

Relates to 3.10.3, 3.10.5

Retention you set, deletion nobody has to remember

Records are kept for the period you choose and deleted automatically when it expires. Holding visitor data indefinitely is a UK data protection problem, not a compliance win.

Relates to 3.10.4

All of it is logged automatically, every time somebody signs in. There is nothing for your reception team to remember to do.

A printed visitor badge and lanyard produced by the kiosk at reception

A badge prints only after a member of your staff has approved the visit on screen.

Being straight with you

What this does not do

If a customer has raised CMMC with you, your first call is to a compliance advisor who can tell you what level applies, what information you are actually handling, and what your obligations are. That conversation ranges a very long way beyond reception.

  • We are not a Registered Provider Organisation, a C3PAO or an assessor, and nothing here is compliance advice.
  • A kiosk is not certification. No product makes anyone compliant with anything.
  • Thirteen of the fourteen requirement families are about your IT, and this page has nothing to say about them.
  • The written procedure behind the log is still yours to write. It is the cheapest item on the list and the one most often missing.

What a kiosk does is produce the record and the approval trail, so that when somebody asks what your process is, you have an answer and the evidence to go with it.

The longer read

What a US defence customer expects from your sign-in book

A fuller walk through the same ground: where visitor management sits in the framework, why a paper book is technically allowed and practically painful, and the six things assessors tend to look for. Written for UK manufacturers who have just won work in an American supply chain.

Read the full article

Sources

Check any of this yourself

General information about published standards, not compliance advice. Requirements and timetables have changed more than once.

Also asked of sites like yours

The other things somebody may ask you to evidence

Each of these is a page about one standard, one duty or one visitor, written the same way as this one: what it actually asks for, what an iPad at reception records towards it, and where it does not help.

Next step

See what your access records would look like

Fifteen minutes on the phone. Tell us what you have been asked to evidence and how people sign in today, and we will tell you straight whether this closes any of it.

Book a 15 minute call

No site visit needed and nothing to install. If it is not a fit we will say so on the call.

Would rather email? [email protected]

Not the person who signs it off? Send them the one page business case