# Commenters Clarify CMMC Door-Access Requirements

Commenters discussing CMMC Level 2 say a badge or door-access system used only to control entry to a CUI space does not, by that function alone, require FIPS validation or NDAA compliance; it is treated as a Security Protection Asset subject to applicable physical-security controls. The assessment may differ if the system handles CUI or uses cryptography to protect CUI confidentiality. Camera systems warrant case-by-case review if their feeds could reveal CUI, and Section 889 obligations may still apply through contract clauses even though commenters distinguish those obligations from CMMC assessment requirements.

- Procurement teams should distinguish access-control functions from systems that process CUI or use cryptography to protect it when writing specifications and assessing CMMC scope.
- Evaluate camera placement and image detail to determine whether feeds could expose CUI; commenters note that applicable Section 889 or other contract clauses may impose separate restrictions.
- Mercury and Ubiquiti are mentioned as products in the discussion, but no procurement role or product-specific compliance determination is provided.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 09, 2026

### Vendors
- Mercury ()
- Ubiquiti ()

### Key Quotes
> For cameras, I do believe you’re required to follow NDAA/Section 889, but that’s not a CMMC issue but rather a FAR clause. An assessor will not assess that, but your contract likely requires you to follow it anyway.
> — Commenter (username not provided)

### Sources
- [Is FIPS and NDAA a requirement for Door Access Control Systems like Badges or Smartcards for a CUI Room / Physical Enclave](https://www.reddit.com/r/CMMC/comments/1x182tz/is_fips_and_ndaa_a_requirement_for_door_access) - reddit-cmmc