Screen individuals prior to authorizing access to CUI — 2 requirements covering 4 total SPRS points.
The Personnel Security domain has just 2 requirements but addresses a foundational control: ensuring that individuals who access CUI-handling systems are screened before access is granted, and that CUI access is properly terminated when personnel depart. Insider threats — whether malicious or inadvertent — represent a persistent risk to CUI. Screening individuals before granting access and ensuring access is revoked when personnel leave are basic controls that significantly reduce exposure.
All Personnel Security requirements assessed during a CMMC Level 2 certification.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| PS.L2-3.9.1 | Screen individuals prior to authorizing access to organizational systems containing CUI. | 3 | Yes |
| PS.L2-3.9.2 | Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. | 5 | Conditional |
Platform capabilities that address Personnel Security requirements.
Track screening status for every individual with CUI access, including background check completion, verification dates, and re-screening schedules.
Automate access revocation workflows when personnel are terminated, ensuring all system access and CUI permissions are removed promptly.
Generate role-specific checklists for internal transfers that ensure CUI access is adjusted to match new responsibilities and old access is revoked.
Maintain a complete, timestamped audit trail of all personnel actions — hires, transfers, and terminations — with linked evidence for assessors.
These tools are commonly used by defense contractors to satisfy PS requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.
Assessors will review personnel screening procedures and ask about what screening is performed before granting access to CUI systems. They'll verify that offboarding procedures include account termination and access revocation, and ask for evidence that this process is actually followed.
Every insider threat begins with a personnel action that was missed or delayed. Screening and offboarding are your first and last lines of defense.
1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.
Request a Demo