Removable Media Vendor Questionnaire Excel Template (MP.L2-3.8.7)

Removable Media Vendor Questionnaire Excel Template (MP.L2-3.8.7)

Use this removable media vendor questionnaire template to evaluate supplier controls, score responses, and document MP.L2-3.8.7 evidence.

LakeRidge Team
July 18, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

A removable media vendor questionnaire template for MP.L2-3.8.7 should require vendors to explain how they restrict USB, CD/DVD, external-drive, and other removable-media use; scan approved media for malware; preserve audit evidence; and support your organization’s policy during an acquisition. Build the questionnaire as an Excel workbook with weighted questions, evidence requests, red-flag criteria, and an evaluation matrix so your ISSO, FSO, IT lead, and acquired-company stakeholders can compare inherited and proposed vendors consistently. For NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2, the objective is straightforward: control the use of removable media on system components.

When should an organization issue an RFP for removable-media control?

Issue an RFP, vendor security addendum, or targeted questionnaire when a supplier will provide endpoint management, managed security services, secure file transfer, data-loss prevention, media encryption, media sanitization, or support personnel with access to systems processing CUI. During an M&A integration, also issue the questionnaire to inherited IT providers before accepting their existing USB exceptions, endpoint-management agents, help-desk practices, or media inventory processes as the combined company standard.

For a small defense contractor, a full procurement event is not always necessary. A concise vendor questionnaire may be enough when renewing an existing Microsoft 365, Microsoft Intune, CrowdStrike, Huntress, NinjaOne, or managed-service-provider agreement. The key is to document whether the vendor can enforce your approved removable-media policy rather than merely stating that it has a general security program.

  • Issue the questionnaire before selecting an endpoint-management or managed detection and response provider.
  • Use it during M&A due diligence when the acquired organization has different USB practices, local administrator privileges, or unmanaged laptops.
  • Reissue it after a material service change, such as moving from on-premises Active Directory Group Policy to Microsoft Intune.
  • Require it when a vendor supplies encrypted USB devices, performs media destruction, or handles CUI transfers on portable storage.
  • Use a shorter version annually for critical vendors and whenever a removable-media incident, malware event, or unauthorized data transfer occurs.

What questions belong in a removable media vendor questionnaire template?

Organize the Excel workbook by category, assign each question an owner, and require a response, supporting evidence, score, and reviewer notes. The questions below can be copied into a removable-media vendor assessment workbook for both new suppliers and inherited M&A vendors.

Policy, scope, and governance questions

  • Provide your documented removable-media policy and identify the policy owner, approval date, review frequency, and revision history.
  • Which media types are covered, including USB flash drives, external hard drives, SSDs, SD cards, CDs/DVDs, mobile devices, and write-once versus rewritable media?
  • Does your policy prohibit removable media by default, permit it by role, or permit it broadly? Explain the business rationale.
  • How do you limit removable-media use to the smallest number of users, systems, and devices necessary?
  • Identify the personnel or roles authorized to approve an exception and the maximum exception duration.
  • Can you support a customer-specific policy that is stricter than your internal standard?

Technical enforcement and endpoint-management questions

  • Identify the products and versions used to control removable media, such as Microsoft Intune Device Control, Microsoft Defender for Endpoint Device Control, CrowdStrike Falcon Device Control, or Trellix Device Control.
  • Can the service block USB mass-storage devices while allowing approved keyboards, mice, smart-card readers, and headsets?
  • Can controls distinguish between read access, write access, execute access, and full device blocking?
  • Can authorized devices be allowlisted by hardware ID, serial number, vendor ID/product ID, or cryptographic certificate?
  • Can the vendor enforce encryption requirements for approved removable media, such as BitLocker To Go with AES-256 encryption?
  • Describe how controls apply to remote endpoints that are off the corporate network and not connected to a VPN.
  • Provide screenshots, policy exports, or configuration documentation demonstrating the current device-control settings.

Malware scanning, monitoring, and incident-response questions

  • How is every approved removable device scanned for malware before files are opened, copied, or executed?
  • Does the endpoint security product scan media automatically on insertion, on access, or only through a user-initiated scan?
  • Identify the antimalware engine, signature update frequency, cloud-protection settings, and response when malware is detected.
  • What logs are retained for device insertion, blocked activity, file copy attempts, malware detections, and policy exceptions?
  • Can events be forwarded to a SIEM such as Microsoft Sentinel, Splunk, or Elastic Security? Provide sample event fields.
  • What is your notification timeline if vendor-managed systems detect suspected malware or unauthorized CUI transfer through removable media?
  • Describe your process for preserving forensic evidence and coordinating with the customer after a removable-media incident.

Access, support, and M&A transition questions

  • Do your support technicians ever use removable media while servicing customer systems? If yes, describe authorization, scanning, logging, and chain-of-custody controls.
  • How do you prevent shared technician USB devices from moving between customers or security enclaves?
  • Can you export the current list of approved users, approved device identifiers, exceptions, and policy assignments for M&A transition validation?
  • What implementation assistance will you provide to reconcile two organizations with different device-control products and exception inventories?
  • Will you notify us before changing a device-control policy, disabling endpoint protection, or altering log-retention settings?

How should vendor answers be scored for MP.L2-3.8.7?

Use a five-point scale for each question, then apply weights based on the control objective. A supplier should not pass merely because it offers a technical product: it must demonstrate that the service can enforce least-necessary use, malware scanning, exception management, and auditable operation across the combined environment.

</tr>
Score Meaning Evaluation guidance
5 Fully meets requirement Provides documented procedures, current configuration evidence, customer-specific enforcement, logs, and named accountable roles.
4 Meets requirement with minor gaps Control is operating and evidenced, but reporting, workflow detail, or a nonmaterial configuration item needs clarification.
3 Partially meets requirement Capabilities exist but are not consistently deployed, are dependent on manual action, or lack complete evidence.
2 Material weakness Vendor has a general policy or product feature but cannot prove enforcement for your endpoints or users.
1 Does not meet requirement Vendor permits unrestricted media, lacks malware scanning, or cannot provide meaningful logging or exception control.
0 No response or unacceptable Vendor refuses evidence, provides contradictory statements, or identifies a known control failure without a credible remediation plan.

Recommended weights are 30% for technical enforcement, 25% for malware scanning and monitoring, 20% for policy and exception governance, 15% for incident response and logging, and 10% for implementation and transition support. In Excel, calculate the weighted total as a percentage of the maximum available score:

=SUMPRODUCT(ScoreRange,WeightRange)/(5*SUM(WeightRange))*100

Set a minimum overall score of 80%, but add non-negotiable gates: a vendor should fail evaluation if it cannot block unauthorized removable media, cannot ensure antimalware scanning of approved media, or cannot provide sufficient logs for investigation. This prevents a high score in less critical categories from masking a fundamental MP.L2-3.8.7 gap.

Which vendor responses are red flags?

  • “Users are trained not to use USB drives.” Training does not replace technical restrictions, approvals, or monitoring.
  • “Our antivirus scans devices nightly.” A nightly scan does not address malware introduced and executed immediately after insertion.
  • “USB is allowed for trusted employees.” Ask how trust is defined, how access is limited, and whether individual actions are logged.
  • “We can block USB if requested.” Request proof of the actual configuration, deployment coverage, exclusions, and enforcement on remote devices.
  • “Exceptions are handled by the help desk.” A help-desk ticket alone is not sufficient unless approval authority, duration, review, and removal are defined.
  • “Our technicians use company-issued thumb drives.” Company ownership does not make a device safe; require encryption, malware scanning, inventory, and customer-environment separation.
  • “Logs are available in the endpoint console.” Determine retention period, export capability, alerting, access control, and whether logs identify user, endpoint, device, action, and timestamp.
  • “The acquired company can retain its current exceptions temporarily.” Require a dated transition plan, complete exception inventory, risk owner, and end-state configuration.

What does a sample vendor evaluation matrix look like?

The following sample shows how an ISSO can compare vendors while integrating two organizations. Record source documents and evidence locations in the same Excel row so the matrix becomes reusable assessment evidence rather than a one-time selection worksheet.

Evaluation area Weight Northstar MSP LegacyCo IT Provider Evidence and reviewer conclusion
USB storage blocking and allowlisting 30% 5 2 Northstar demonstrated Intune Device Control policies blocking removable storage except serial-number allowlisted BitLocker To Go devices. LegacyCo relies on local administrator approval.
Automatic malware scanning 25% 4 2 Northstar uses Defender for Endpoint real-time protection and scans on access; insertion-specific alerting needs confirmation. LegacyCo requires users to initiate scans manually.
Policy and exception workflow 20% 4 3 Northstar has 90-day exceptions approved by the customer security contact. LegacyCo has tickets but no formal expiry or quarterly review.
Logging and incident response 15% 5 2 Northstar forwards device-control events to Microsoft Sentinel with 180-day searchable retention. LegacyCo retains console events for 30 days.
M&A transition support 10% 4 3 Northstar will import approved-device inventory and provide a 45-day migration plan. LegacyCo can export assets but cannot export historical exceptions.
Weighted score 100% 92% 46% Northstar is conditionally acceptable after insertion-alert evidence is provided; LegacyCo requires remediation or replacement.

Before selecting or renewing a provider, have the FSO, ISSO, and integration lead review the completed workbook, attach the vendor’s evidence, and convert accepted gaps into dated contract obligations or a tracked plan of action and milestones.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.