Access Control for Transmission protects the physical cabling that carries your data. It is a net-new requirement in R3, and it addresses a layer of the facility that many programs overlook: the distribution and transmission lines running through walls, ceilings, and wiring closets. Access Control for Transmission (03.10.08) is a single statement: control physical access to system distribution and transmission lines within organizational facilities. Per the NIST discussion, safeguarding these lines prevents accidental damage, disruption, and physical tampering, and may also be necessary to prevent eavesdropping or the modification of unencrypted transmissions, with measures such as locked wiring closets, conduit or cable trays, disconnected or locked spare jacks, and wiretapping sensors.
A common difficulty with this requirement is not treating cabling as an asset that needs protection. An open wiring closet, an accessible network jack in a public area, or exposed cabling in a shared space all present opportunities for tampering or eavesdropping. This requirement is new for R3, so most organizations have no existing control specifically for transmission lines, making it genuinely new work rather than a reinterpretation.
Where things stand for companies facing the transition from NIST 800-171 R2 to R3:
The following is reproduced verbatim from NIST 800-171 R3, requirement 03.10.08 Access Control for Transmission. Only the formatting has been adjusted for readability. This is a single statement with no lettered parts:
The source control is PE-04 from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, safeguarding measures include disconnected or locked spare jacks, locked wiring closets, cabling protection with conduit or cable trays, and wiretapping sensors. You can read the requirement directly at NIST 800-171 R3, 03.10.08 (p. 53).
None (0). Requirement 03.10.08 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.
Your System Security Plan (SSP) narrative for 03.10.08 therefore records how the requirement is implemented rather than a parameter you chose.
NIST 800-171A R3 breaks 03.10.08 into one (1) determination statement, and it has no Organization-Defined Parameters (ODPs). The AO is:
The single objective is that physical access to distribution and transmission lines is controlled. An assessor will look at how cabling, jacks, and wiring closets are protected. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.10.08 (p. 68).
Note that the requirement is titled Access Control for Transmission in both the NIST 800-171 R3 and NIST 800-171A R3 publications. Some control listings append and Output Devices, but output device control is addressed separately in Physical Access Control (03.10.07).
Examine: physical protection policy and procedures; procedures for access control for transmission mediums; system design documentation; facility communications and wiring diagrams; list of physical security safeguards applied to system distribution and transmission lines; procedures for access control for display medium; facility layout of system components; list of output devices and associated outputs that require physical access controls; actual displays from system components; physical access control logs or records for areas containing output devices and related outputs; system security plan.
Interview: personnel with physical access control responsibilities; personnel with information security responsibilities.
Test: processes for access control for distribution and transmission lines; mechanisms for supporting or implementing access control for distribution and transmission lines; processes for access control to output devices; mechanisms for supporting or implementing access control for output devices.
03.10.08 is net new for R3 and has no corresponding requirement in NIST 800-171 R2:
Mapped against the one (1) AO, it is net new (significant effort), with none direct, indirect, or unmapped. The source control, PE-04, was an assumed control in R2 rather than one that R2 separately assessed, so there is no transition path. Plan to add a specific control for the physical protection of distribution and transmission lines rather than assuming general facility access covers it.
Source Control in NIST 800-53 R5:
Secure Controls Framework (SCF) Crosswalk
Organizations running a single control set across multiple frameworks can satisfy 03.10.08 through the following SCF controls:
The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.
The pitfalls for this net-new requirement are about protecting the physical cabling, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:
Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.10.08 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.10.08 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.
Alongside these, keep the System Security Plan (SSP) narrative for 03.10.08.
With the single AO net new, plan to add a specific safeguard rather than refresh an existing one. A realistic sequence:
How many assessment objectives does NIST 800-171 R3 03.10.08 have? NIST 800-171A R3 breaks 03.10.08 into one (1) assessment objectives. An assessor works through each one separately, so each needs its own evidence.
Which NIST 800-53 R5 control does NIST 800-171 R3 03.10.08 come from? PE-04.
How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.10.08 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.
Where does NIST 800-171 R3 03.10.08 sit in the NIST 800-171 R3 Kill Chain? Phase 20, Physical Security. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.
03.10.08 Access Control for Transmission controls physical access to system distribution and transmission lines within facilities. It is net new for R3 with no R2 predecessor, so the single objective is new work. The recurring problem is leaving cabling and wiring closets unprotected. Secure wiring closets and jacks, protect exposed cabling with conduit or trays, and consider eavesdropping risk, keeping this distinct from output device control in 03.10.07.
Authoritative sources:
Authoritative sources:
This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.