Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-22 |
| Control Name | Component Marking |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Physical and Environmental Protection |
| Baselines | — |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What this control requires
PE-22 requires organizations to mark hardware components with labels indicating the impact or classification level of information they handle. This control applies to both input devices, such as laptops, keyboards, tablets, and smartphones, and output devices, such as printers, monitors, scanners, and copiers.
In practice, this requirement means that every piece of hardware connected to a classified or controlled system needs a visible, human-readable marking that communicates what type of information that device handles. Without clear markings, personnel have no reliable way to determine whether a device is authorized for handling controlled unclassified information (CUI) or higher-classification data. The result is a breakdown in physical security boundaries that access controls alone can’t prevent.
Where this control draws an important distinction is between security marking and security labeling. Security marking refers to human-readable attributes, like physical stickers or engravings on a device chassis, that people can see and interpret. Security labeling refers to machine-readable attributes embedded in internal system data structures. PE-22 focuses specifically on the human-readable side. Organizations don’t need to mark hardware that handles only publicly releasable information, though they may choose to do so to make the public status explicit.
Why it matters
Most organizations invest heavily in logical access controls but overlook the physical markers that tell personnel which devices belong on which networks. PE-22 addresses this gap directly. When hardware components lack clear classification markings, the risk isn’t a dramatic breach but rather a slow erosion of information handling discipline that auditors will flag and that regulatory bodies take seriously.
The compliance and audit risk here is real, even though PE-22 carries a low severity rating. Assessors evaluating NIST SP 800-171 environments or performing agency audits will examine whether hardware markings match the documented impact levels in the system security plan. A mismatch between what a device is marked for and what it actually processes creates a finding that calls the entire physical security program into question.
This control also supports the broader chain of physical and environmental protections within the PE family. Component marking reinforces access enforcement (AC-3) and information flow enforcement (AC-4) by providing a visual verification layer that complements technical controls.
The following threat vectors become relevant when component marking fails:
- Unauthorized data spillage when personnel process classified or CUI material on devices marked for lower impact levels
- Improper disposal of hardware that lacks markings indicating it held sensitive data, leading to incomplete sanitization
- Cross-domain contamination where unmarked devices move between networks of different classification levels
- Audit findings during federal assessments where missing or inaccurate markings indicate a systemic gap in the physical security program
- Insider misuse facilitated by ambiguity about which devices are authorized for sensitive information handling
How to implement
For your organization
The core challenge with PE-22 is that hardware marking sounds straightforward but breaks down at scale. Organizations with hundreds or thousands of endpoints need a repeatable process, not a one-time labeling effort. Building that process starts with a complete inventory of hardware components that process, store, or transmit information at each impact or classification level.
Begin by mapping every input and output device to its authorized information type and impact level. This mapping should reference the system security plan and align with the organization’s information classification scheme. Desktops, notebooks, tablets, smartphones, printers, monitors, copiers, scanners, and audio devices all fall within scope.
Develop a marking standard that defines the label format, placement, and materials. Labels need to be durable enough to remain legible through the hardware lifecycle. Many organizations use color-coded labels or tamper-evident stickers that correspond to impact levels. The marking standard should specify where on the device the label goes, what information the label contains, and how replacements are handled when labels degrade or fall off.
Integrate component marking into the hardware provisioning workflow so new devices receive their markings before deployment. Deprovisioning workflows should verify that markings are present and accurate before sanitization or disposal. Periodic spot checks confirm that markings remain current, especially after system reauthorizations that may change impact levels.
Document the marking procedures, maintain an up-to-date component inventory that records the marking status of each device, and train personnel on what the markings mean and how to report discrepancies. This documentation becomes the primary evidence during assessments.
For your vendors
Evaluating PE-22 compliance in a third-party environment requires confirming that the vendor has both the policy and the operational practice for marking hardware components. Start by requesting the vendor’s physical and environmental protection policy and their specific procedures for component marking.
Ask whether the vendor maintains a hardware inventory that records marking status alongside impact or classification levels. A vendor that can produce this inventory demonstrates operational maturity. A vendor that can’t is likely treating component marking as an afterthought.
Review the vendor’s marking standard for consistency. Markings should align with the information types the vendor is authorized to handle under the contract. If the vendor processes CUI on your behalf, their hardware markings should reflect CUI handling requirements. If the vendor handles multiple clients with different classification requirements, their marking scheme should prevent cross-client confusion.
During vendor assessments or site visits, visually verify that hardware in scope carries the appropriate markings. Compare a sample of marked devices against the vendor’s component inventory. Discrepancies between the inventory records and actual device markings indicate a process gap that creates risk for your data.
Include PE-22 compliance language in vendor contracts and security requirements documents. Require vendors to notify you of changes to their hardware environment that affect marking practices, such as system reauthorizations or migrations that alter the impact levels of devices handling your information.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Physical and environmental protection policy | Policy document defining the organization’s approach to hardware marking, including scope, responsibilities, and applicable regulations |
| Component marking procedures | Step-by-step procedures for applying, updating, and removing classification or impact-level markings on hardware devices |
| Marking attribute definitions | Reference document listing approved marking labels, color codes, and their corresponding impact or classification levels |
| Hardware component inventory | Asset register recording each device’s type, location, assigned information impact level, and current marking status |
| Information type catalog | Documentation of the information types processed by the organization, their impact levels, and any special handling requirements |
| System security plan excerpt | Sections of the SSP that define information impact levels and tie them to specific hardware components and networks |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.13 Labelling of information | Partial |
Related controls
- AC-03 Access Enforcement relates to PE-22 by governing the logical permissions that determine what information a user can send to output devices, complementing the physical markings that indicate what a device is authorized to handle
- AC-04 Information Flow Enforcement supports PE-22 by controlling the movement of information between systems of different classification levels, where component markings provide the visual reference for which devices participate in which flows
- AC-16 Security and Privacy Attributes connects directly to PE-22 by defining the security attributes, both human-readable markings and machine-readable labels, that organizations assign to information and system components
- MP-03 Media Marking parallels PE-22 by applying similar marking requirements to removable media, ensuring that portable storage devices carry the same classification or impact-level indicators as the hardware they connect to
Frequently asked questions
What is NIST SP 800-53 PE-22
PE-22 is a NIST SP 800-53 control that requires organizations to mark hardware components with human-readable labels indicating the impact level or classification level of information those components handle. This control covers input devices like laptops, keyboards, and tablets, as well as output devices like printers, monitors, and copiers. The markings give personnel a visual reference for determining whether a device is authorized for specific types of information.
What happens if PE-22 is not implemented
Organizations that don’t implement PE-22 face audit findings that call the credibility of their physical security program into question. Without hardware markings, personnel can’t visually verify whether a device is authorized for the classification level of information they’re handling, which increases the risk of data spillage across security boundaries. Federal assessors will document the gap during evaluations, and the finding can delay or prevent system authorization.
How do you audit PE-22
Auditing PE-22 starts with examining the organization’s component marking procedures and the hardware component inventory to confirm that marking standards are documented and maintained. Assessors then conduct physical inspections, comparing a sample of hardware devices against the inventory to verify that markings are present, legible, and accurate. The assessment also checks that the markings align with the impact levels documented in the system security plan and the organization’s information type catalog.
What is the difference between security marking and security labeling
Security marking refers to human-readable attributes applied to hardware components, such as physical stickers, tags, or engravings that personnel can see and interpret without technical tools. Security labeling refers to machine-readable security attributes embedded within internal system data structures that software processes use to enforce access and flow controls. PE-22 focuses on security marking because its purpose is to give people a visual indicator of a device’s authorized information handling level, while security labeling supports automated enforcement through controls like AC-16.