HomeTemplatesEncryption Policy
CMMC Level 2 SC Domain IA Domain

Encryption & Cryptography Policy Template

FIPS 140-2 requirements, TLS configuration, encryption at rest and in transit, cryptographic key management, and password storage. Six NIST 800-171 practices covered in one document.

What Is Included

  • FIPS 140-2 / FIPS 140-3 compliance requirements and approved algorithm table
  • TLS 1.2 / 1.3 configuration requirements and prohibited protocol list
  • Encryption at rest: BitLocker, FileVault, mobile devices, removable media
  • Encryption in transit: email (S/MIME, TLS), web, API, file transfer requirements
  • Key management lifecycle: generation, distribution, storage, rotation schedule table, revocation, and destruction
  • Password cryptographic storage and transmission requirements (3.5.10)
  • Roles and responsibilities matrix
  • Exception process and compliance assessment guidance
  • Document control and signature block

Practice Coverage

3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission
3.13.10Establish and manage cryptographic keys when cryptography is employed
3.13.11Employ FIPS-validated cryptography when used to protect the confidentiality of CUI
3.13.16Protect CUI at rest
3.5.10Store and transmit only cryptographically-protected passwords
3.1.19Encrypt CUI on mobile devices and mobile computing platforms

Frequently Asked Questions

This policy covers six NIST SP 800-171 Rev 2 practices: 3.13.8 (encrypt CUI in transit), 3.13.10 (key management), 3.13.11 (FIPS-validated cryptography), 3.13.16 (encrypt CUI at rest), 3.5.10 (cryptographically protected passwords), and 3.1.19 (encrypt CUI on mobile devices).
FIPS 140-2 is the federal standard for cryptographic module validation. CMMC practice 3.13.11 requires that any cryptography used to protect CUI confidentiality must use FIPS-validated modules - meaning the specific implementations must be tested and certified by NIST's CMVP, not just any commercially available encryption. AES-256, TLS 1.2/1.3 with approved ciphers, and BitLocker are all FIPS-compatible when configured correctly.
Yes. The template includes specific guidance for Windows BitLocker with Entra ID key escrow, Intune mobile device encryption enforcement, and TLS configuration requirements applicable to M365 environments. Placeholders indicate where organization-specific implementation details should be added.
A properly completed version of this policy - with your organization's actual implementation details filled in - addresses the documentation requirement for these six practices. C3PAO assessors will also verify that the technical controls described in the policy are actually implemented. The policy is the documentation layer; the technical implementation is verified separately.
Encryption & Cryptography Policy
$29
Instant download · Editable .docx · CMMC mapped
Buy Now - $29 →
✓ Covers 6 NIST 800-171 practices
✓ FIPS 140-2 compliant language
✓ Key rotation schedule table included
✓ M365 / BitLocker / Intune guidance
✓ 30-day money-back guarantee
✓ Written by CISSP-exam-pass holder
Save more with bundles:
CMMC Certification Kit - $299 (12 policies + SSP + POA&M) CMMC Domain Policy Bundle

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain. Free PDF, instant access.

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, instant access.