PS Domain

Personnel Security
CMMC Level 2

Screen individuals prior to authorizing access to CUI — 2 requirements covering 4 total SPRS points.

2 Requirements
4 SPRS Points at Risk
100% Complete Coverage

Personnel Security Domain Overview

The Personnel Security domain has just 2 requirements but addresses a foundational control: ensuring that individuals who access CUI-handling systems are screened before access is granted, and that CUI access is properly terminated when personnel depart. Insider threats — whether malicious or inadvertent — represent a persistent risk to CUI. Screening individuals before granting access and ensuring access is revoked when personnel leave are basic controls that significantly reduce exposure.

NIST SP 800-171 Requirements

All Personnel Security requirements assessed during a CMMC Level 2 certification.

RequirementDescriptionPointsPOA&M
PS.L2-3.9.1Screen individuals prior to authorizing access to organizational systems containing CUI.3Yes
PS.L2-3.9.2Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.5Conditional

How 1TEN Covers This Domain

Platform capabilities that address Personnel Security requirements.

Personnel Screening Tracker

Track screening status for every individual with CUI access, including background check completion, verification dates, and re-screening schedules.

3.9.1

Access Termination Workflows

Automate access revocation workflows when personnel are terminated, ensuring all system access and CUI permissions are removed promptly.

3.9.2

Transfer Checklist Generator

Generate role-specific checklists for internal transfers that ensure CUI access is adjusted to match new responsibilities and old access is revoked.

3.9.2

Personnel Action Audit Trail

Maintain a complete, timestamped audit trail of all personnel actions — hires, transfers, and terminations — with linked evidence for assessors.

3.9.13.9.2

Common Tools for PS Compliance

These tools are commonly used by defense contractors to satisfy PS requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will review personnel screening procedures and ask about what screening is performed before granting access to CUI systems. They'll verify that offboarding procedures include account termination and access revocation, and ask for evidence that this process is actually followed.

PS Domain

Every insider threat begins with a personnel action that was missed or delayed. Screening and offboarding are your first and last lines of defense.

Related Domains

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo