CMMC visitor log requirements: what a US defence customer actually expects from your sign-in book

woman holding lanyard

If you manufacture in the UK and you’ve recently won work in an American defence supply chain, there’s a good chance a customer has sent you a document with “CMMC” on the front and asked how you intend to comply.

Most of what that document covers (encryption, system boundaries, incident response, assessment scoring) belongs to a qualified compliance advisor, and this article is not going to pretend otherwise. Noon Elite is not a CMMC consultancy, a Registered Provider Organisation or an assessor. If you don’t yet have advice, get it before you spend money on anything.

But there is one small corner of the framework that isn’t a cyber problem at all. It’s a front desk problem. And it’s the corner where UK manufacturers most often discover that the hardback book on the reception counter doesn’t produce the evidence anyone is asking for. That’s what this article covers, and nothing else.

Where visitor management fits in CMMC

CMMC is a verification programme layered on top of security requirements that already existed. The programme rule is explicit about this: the security requirements at CMMC Level 2 are identical to those in NIST SP 800-171 Revision 2. Same 110 requirements, with an assessment regime attached rather than new technical rules.

Those 110 requirements are grouped into fourteen families. Thirteen of them concern your IT. One, Physical Protection (3.10), concerns your building.

Five requirements in that family touch the front desk directly:

  • 3.10.1: limit physical access to systems, equipment and their operating environments to authorised individuals
  • 3.10.2: protect and monitor the physical facility and its supporting infrastructure
  • 3.10.3: escort visitors and monitor visitor activity
  • 3.10.4: maintain audit logs of physical access
  • 3.10.5: control and manage physical access devices

(You may also see these written as 03.10.01 and 03.10.07. Revision 3 of NIST 800-171 folds 3.10.3, 3.10.4 and 3.10.5 into a single physical access control requirement. Confusingly, NIST formally withdrew Revision 2 in May 2024 and superseded it with Revision 3. The CMMC programme rule still incorporates Revision 2 by reference, though, so Revision 2 is what a CMMC assessment currently works from. If you find two advisors disagreeing about which numbers apply, this is why. Follow whichever your own advisor specifies.)

Read plainly, that list describes: knowing who is in the building, deciding in advance whether they’re allowed to be, keeping them accompanied while they are, holding a record afterwards, and keeping control of the badges and keys that open doors.

Most factories already do four of those five informally. The gap is almost always evidence.

Why a paper book is technically allowed and practically painful

An important nuance that saves a lot of panic: the standard does not mandate any particular system. Physical access logs may be procedural (a written record), automated, or a mix of both. Organisations are given flexibility in how they log.

So nobody is going to fail you for owning a paper book.

What happens instead is subtler. Assessment isn’t about whether you have a control; it’s about whether you can demonstrate it. And a hardback book struggles under three specific questions:

“Show me everyone who entered the restricted area last March.” A book records arrivals at a building, not movements within one. If part of your site is designated as needing additional control, the book cannot evidence who crossed that line.

“Who authorised this person’s access, and when?” A signature in a book is a record that someone was present. It is not a record that anyone approved them in advance. Requirement 3.10.1 is about authorisation, and authorisation that happens implicitly, because the visitor was already stood in reception, is difficult to evidence at all.

“Where is this month’s log?” In a drawer, mostly. Possibly water damaged, frequently illegible, and containing every other visitor’s name and company on the same page, which in the UK is its own data protection problem entirely separate from anything the Americans have asked for.

None of these are reasons to buy software. They’re reasons to be honest with yourself about what your current record actually proves.

What “good” tends to look like

Regardless of what you use to achieve it, the pattern assessors are looking for is roughly this:

  1. Authorisation before entry, recorded. Someone with standing to approve visitors approves this visitor, and that approval is captured rather than assumed.
  2. A visible distinction between authorised and unauthorised people. In practice this usually means a badge. Note that people holding permanent access credentials, meaning your own staff, aren’t counted as visitors at all.
  3. An escort rule that is written down as well as observed. “We always walk people round” is a habit. “Visitors are escorted at all times in non-public areas” in a document, plus records showing who escorted whom, is a control.
  4. A retrievable log. Timestamped in and out, searchable after the fact, and retained for a defined period and no longer, which matters in the UK.
  5. Control of the badges and keys themselves. An inventory of what opens what, and what happens when one goes missing.
  6. A written procedure covering all of the above. Assessments are conducted using the procedures in NIST SP 800-171A, which examine documented policy and procedure alongside the working control. A log with no documented process behind it is a weaker position than a log with one.

Point six is worth repeating, because it’s the cheapest thing on the list and the one most often missing. If you do nothing else after reading this, write down your visitor procedure.

Where this leaves you

If a customer has raised CMMC with you, your first call is to a compliance advisor who can tell you what level applies, what information you’re actually handling, and what your obligations are. That conversation will range far beyond reception.

But the physical protection piece is worth looking at early, for a practical reason: it’s one of the few areas where the fix is quick, cheap and entirely within your control. You don’t need a systems integrator to write down who approves visitors.


Noon Elite supplies fully managed iPad visitor check-in kiosks to industrial and commercial sites across the East Midlands: timestamped visitor logs, on-screen approval before entry, printed badges, and fire evacuation roll-call. We’re not compliance consultants, and a kiosk is not certification. What it does is produce the record and the approval trail, so that when someone asks what your process is, you have an answer and the evidence to go with it.

If you’d like to see what that looks like in practice, get in touch for a demonstration.


Sources

This article is general information about published standards, not compliance advice. Requirements and implementation timetables have changed more than once; confirm the current position with a qualified advisor before acting.