Personnel Security (PS) — 3.9.1, 3.9.2

FutureFeed CMMC Education Series · Personnel Security

Personnel Security (PS) 3.9.1, 3.9.2

The short version

If you’re responsible for CMMC compliance, here’s what these two requirements come down to. You need to:

  • Screen individuals before granting access to systems that process Controlled Unclassified Information (CUI)
  • Turn off their access when they leave or change roles
  • Collect your property (laptops, badges, keys, tokens) when they go
  • Keep dated records showing you did all of this

If you already have those things and can prove them, you’re well on your way. Now let’s talk about what each one actually looks like.

Personnel Security 3.9.1 and 3.9.2: screening before access and protecting systems during departures

Applies to: Organizations working toward CMMC compliance · NIST SP 800-171 Rev 2, Personnel Security (3.9) · Requirements 3.9.1 and 3.9.2.

Last reviewed: July 2026.

01

In plain English

This family is about the two moments that matter most with any employee or contractor: the day they arrive and the day they leave. Before someone gets access to systems that process CUI, you make sure they’ve been checked out. And when they walk out the door, you make sure your systems and information don’t walk out with them.

Two requirements, two moments:

  • Before access: screen the person appropriately for the role they’re being hired into.
  • During and after a departure or transfer: shut off access, collect your property, and make sure nothing is left open.

That’s the whole family. Who you let in, and how you let them go.

Example. An employee or contractor gives two weeks’ notice on a Monday. Their manager opens an offboarding ticket that day. On the person’s last afternoon, IT disables their accounts, and they hand back their laptop, badge, and building key. HR runs a short exit interview and reminds them of the agreement they signed. On the hiring side, that same role was never granted access until a background check appropriate to the job came back clean. That’s what these requirements are asking you to do.

02

What you need to have in place

To be compliant, each of those boxes needs to be real and repeatable:

  • A screening step that happens before access is granted, matched to what the role actually needs.
  • A written offboarding process that kicks in the moment someone gives notice or changes roles.
  • Fast access removal so accounts are disabled on the person’s last day, not weeks later.
  • Property return for laptops, phones, badges, keys, and security tokens.
  • Records of both the screening and the access removal, with dates.

One of the easiest gaps to avoid is delayed access removal. Speed, combined with a dated record, is what closes it.

03

What you need to prove it

Think in three buckets. An assessor will want all three, so it helps to build them at the same time.

People

  • HR, who usually owns screening and the offboarding process
  • The manager who starts offboarding when someone leaves or transfers
  • IT or security, who disables access and collects property

Tools

  • Your background-check provider or screening process
  • The HR or ticketing system that triggers offboarding
  • The identity system where access actually gets turned off

Documents

  • A short written personnel security policy covering screening and departures
  • Screening records for each person, appropriate to their role
  • Offboarding checklists and access-termination records with dates
  • Property-return records
  • A note in your System Security Plan (SSP) describing the whole process

You don’t need a big HR platform. You need proof that people were checked before they got in, and that their access was removed promptly when they left.

The Road to CMMC

A new stop every Tuesday and Thursday.

Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.

04

When should I work on this

I’d tackle this right after Awareness and Training. It’s another people-focused family, so it pairs naturally with the work you just did. It also sets up Access Control later: a real offboarding process is what makes “remove access when someone leaves” actually happen, instead of being a promise on paper. Get this in place before you go deep on the technical access controls, and those become much easier to keep honest.

05

Common challenges

1

Access stays live after someone leaves.

Why it happens: Offboarding runs by word of mouth, so IT hears about a departure days or weeks after the person is gone.

Recommendation: Tie account disabling to the same trigger HR uses for offboarding, so access is removed on the last day automatically.

2

You can’t prove screening happened.

Why it happens: The check was done through a vendor or informally, but nothing dated ever made it into the person’s file.

Recommendation: Keep a dated screening record for each person, matched to the access they were later granted.

3

Company property walks out the door.

Why it happens: There’s no departure checklist, so laptops, badges, keys, and tokens aren’t reliably collected.

Recommendation: Add a property-return list to offboarding and record what actually came back, and when.

06

What good looks like

A compliant contractor can usually answer yes to all of these:

  • Do you screen people before granting access to systems that process CUI?
  • When someone leaves, is their access removed the same day?
  • Do you collect laptops, badges, keys, and tokens when they go?
  • Can you prove, with dates, that screening and offboarding happened?

If any answer is no, that’s your next place to start.

07

Watch out

Watch out: CMMC doesn’t prescribe a specific type of personnel screening. The requirement is to screen individuals before authorizing access to systems containing CUI. Define what screening means for your organization, apply it consistently, and keep records showing it was completed before access was granted.

08

How this connects to other controls

This family doesn’t stand alone. A few close relationships:

  • Awareness & Training: the people you screen and bring on board are the same people you train. These two families are the heart of your people-focused work.
  • Access Control: your offboarding process is what makes prompt access removal real, and your screening supports authorizing access in the first place.
  • Identification & Authentication: disabling someone’s credentials on their last day ties directly to this family.
09

The requirements, word for word

For your reference, here’s the exact language so you’re working from the source and not a paraphrase:

  • 3.9.1 Screen individuals prior to authorizing access to organizational systems containing CUI.
  • 3.9.2 Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Source: NIST SP 800-171 Rev 2, Personnel Security (3.9)

Related standards: NIST SP 800-53 Rev 5 (PS-3, PS-4, PS-5) · DFARS 252.204-7012

Every organization implements these controls a little differently. If you’re not sure whether your approach would satisfy an assessor, join one of our upcoming webinars or schedule a 15 Minutes with FutureFeed session. We’d rather answer your questions now than have you discover them during an assessment.

CMMC: Everything You Need to Know to Get Started, 6th Edition guide cover

CMMC: Everything You Need to Know to Get Started (6th Edition)

Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.