What Do Assessors Check in CUI Repair Tickets? (MA.L2-3.7.3)

What Do Assessors Check in CUI Repair Tickets? (MA.L2-3.7.3)

See the cmmc assessor CUI repair ticket evidence needed to prove off-site maintenance equipment was sanitized before release.

LakeRidge Team
July 18, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

Assessors check whether your repair tickets prove that equipment leaving your facility for off-site maintenance was identified, evaluated for CUI, sanitized using an approved method, validated, and released by an authorized person. Effective cmmc assessor CUI repair ticket evidence connects the asset, the media disposition decision, the sanitization record, and the vendor handoff so an assessor can trace one device from repair request through return. For MA.L2-3.7.3, a ticket that merely says “wiped” is usually not enough.

What does a CMMC assessor actually check in CUI repair tickets?

For NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice MA.L2-3.7.3, the assessment objective is straightforward: equipment removed from organizational spaces for off-site maintenance must be sanitized of CUI. The assessor will not only review a policy statement; they will sample actual repair events and determine whether your process worked consistently when equipment left your control.

  • A traceable asset identifier: The ticket should identify the specific laptop, workstation, server, printer, network appliance, removable drive, or other equipment by asset tag, serial number, hostname, or service tag. “Dell laptop from engineering” cannot be reliably tied to a CUI determination or sanitization action.
  • A documented CUI and media decision: The record should show whether the equipment contained, processed, or could have retained CUI on internal storage, removable media, printer storage, embedded memory, or configuration backups. If the answer is “no CUI,” retain the basis for that conclusion, such as the device role, system owner confirmation, or an inventory classification.
  • The sanitization method and technical result: Assessors expect evidence that matches the media type and organizational procedure. Examples include a secure-erase completion report, a degaussing log, a certificate of destruction, or a record showing that the drive was removed and retained onsite before the chassis was sent out. The evidence should identify the method, date, performer, and result.
  • Approval before release: The repair ticket or linked workflow should show that an authorized employee verified sanitization before the equipment was transferred to the maintenance provider. This is particularly important when a help desk technician creates the ticket but an information system security manager, IT manager, or designated custodian approves release.
  • Custody and closure records: The assessor may compare the repair ticket to shipping records, vendor RMA documentation, pickup logs, and the asset inventory. Dates should make sense: sanitization and approval must occur before shipment or vendor pickup, not after the device returns.

A program manager should treat each sampled ticket as a small chain-of-custody case file. The strongest CUI repair-ticket evidence allows an assessor to start with an asset tag and independently find the service request, sanitization output, release approval, and vendor handoff without relying on verbal explanations.

Where should cmmc assessor CUI repair ticket evidence be stored before the audit?

Build an evidence map before the assessment rather than asking technical staff to search across systems while the assessor waits. The map should identify the authoritative system, the exact location or report to retrieve, and the person accountable for producing it. Use read-only exports or screenshots where live system access would expose unrelated CUI.

Tool Location or report to provide Evidence owner
ServiceNow ITSM Incident/Request records with category set to Off-Site Repair, asset tag, CUI/media assessment field, release approval, and closure notes IT Service Desk Manager
Microsoft Intune Devices report filtered by serial number; proof of device ownership, last check-in, and device retirement status when applicable Endpoint Management Lead
Blancco Drive Eraser Signed erasure certificate showing drive serial number, erasure standard, verification result, operator, and timestamp Desktop Support Supervisor
Jira Service Management Linked RMA task, approval history, attached vendor shipping label, and asset disposition checklist for engineering-managed systems Engineering IT Manager
Asset Panda Asset history showing assigned user, physical location, CUI-capable system designation, repair status, and returned-to-service date Property Accountability Officer
SharePoint restricted compliance library Approved Media Sanitization Procedure, NIST SP 800-88 Rev. 1 decision matrix, technician training records, and monthly ticket review results ISSM or Compliance Manager
UPS CampusShip or FedEx Ship Manager Shipment record tied to the RMA number, including ship date, recipient, tracking number, and signature confirmation where used Facilities and Logistics Coordinator

For a mature audit package, select several completed repair events from the prior 12 months, including at least one laptop or workstation with internal storage and one device for which storage was removed before vendor repair. If your organization has had no off-site repairs during the review period, document that fact, retain the procedure and training evidence, and be ready to explain how the workflow would operate. Do not manufacture a ticket; an assessor can distinguish a real operational record from a retrospective exercise.

What should a complete ticket record look like?

Asset Tag: ENG-LT-044
Device: Dell Latitude 5540 / Service Tag 8K3M2X1
Repair Reason: Mainboard failure; vendor depot RMA 41023877
CUI/Media Assessment: Internal NVMe drive may contain CUI project files.
Disposition Decision: Remove and retain NVMe drive onsite; chassis approved for off-site repair.
Sanitization Method: Not applicable to chassis after drive removal.
Media Custody Record: Drive SN S6P1NX0R912345 retained in locked media cabinet, bin M-14.
Release Approval: J. Morales, IT Manager, approved 2026-06-10 14:22 EDT.
Shipment: UPS 1Z84A73E0391827465, shipped 2026-06-11.
Return Verification: Asset received, original drive reinstalled by authorized technician.

This example demonstrates an important point: sanitization does not always mean erasing a drive. If the organization removes CUI-bearing media and retains it inside its controlled environment, the equipment sent to the vendor no longer contains that media. The ticket must clearly establish that the drive was actually removed, uniquely identified, secured, and not shipped with the chassis.

What are the top three gotchas that cause MA.L2-3.7.3 audit failures?

  1. Using vague closure language instead of verifiable proof. “Cleaned,” “reset,” “reimaged,” and “wiped” are not sanitization methods by themselves. A standard operating system reset may leave recoverable data, and a reimage may not address all storage areas. Repair ticket evidence for CUI should state the approved method and retain the tool output, destruction record, or media-removal evidence.
  2. Forgetting nontraditional storage. Teams often focus on laptop drives while overlooking multifunction printer hard drives, network appliance configuration storage, mobile devices, diagnostic laptops, removable SSDs, and embedded flash. Your gap analysis should compare the asset inventory against the off-site repair workflow to identify every equipment class that can retain CUI.
  3. Having a policy that is not reflected in operations. A procedure may require ISSM approval, but sampled tickets may show equipment shipped before approval or no approval at all. Assessors will reconcile timestamps across the ticket, erase certificate, shipping record, and vendor RMA. A process that depends on undocumented technician judgment is difficult to defend.

What should the 7-day pre-audit countdown include?

  1. Day 7: Pull the full list of off-site repair, RMA, depot repair, and vendor-maintenance tickets for the assessment period. Reconcile it to shipping and asset-disposition records.
  2. Day 6: Identify the likely sample set: devices with internal storage, printers or appliances, drive-removal cases, and any emergency repair. Flag records with missing fields or inconsistent dates.
  3. Day 5: For each likely sample, assemble the ticket, asset record, sanitization certificate or media custody record, approval, and shipping evidence into a controlled evidence folder.
  4. Day 4: Perform a gap review against MA.L2-3.7.3. Confirm that the organization can explain how its approved sanitization choices align with NIST SP 800-88 Rev. 1 guidance for the relevant media type.
  5. Day 3: Correct operational gaps that can be corrected honestly, such as missing asset links, incomplete custody records, or improperly filed tool reports. Document corrective actions separately; do not alter historical timestamps or backdate approvals.
  6. Day 2: Conduct a tabletop interview with the service desk manager, endpoint lead, logistics coordinator, and ISSM. Have each person explain only the portion of the workflow they own.
  7. Day 1: Verify read access, export permissions, and file names. Prepare an evidence index that maps each artifact to the sampled repair ticket and confirms the designated presenter.

What should a program manager do during the assessor interview?

Lead with the workflow, then let the technical owners demonstrate the records. Explain that equipment is not released for off-site maintenance until the responsible team determines whether CUI-bearing media is present and either sanitizes it, removes and retains it, or destroys it according to the approved procedure. Then walk one completed sample chronologically: asset identification, CUI decision, sanitization or media removal, authorization, shipment, vendor repair, and return.

Keep answers precise. If the assessor asks why a specific method was used, point to the media type, your sanitization decision matrix, and the relevant NIST SP 800-88 Rev. 1 guidance rather than claiming every reset is equivalent to secure erasure. If a record has a deficiency, acknowledge it, explain the scope, show the corrective-action record, and distinguish it from evidence of normal practice. A credible response is better than an improvised explanation that conflicts with the ticket history.

Before the audit begins, assign one owner to validate your sampled repair records and ensure every off-site maintenance event has a defensible CUI sanitization trail.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.