By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 20, 2026
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.
The CMMC personnel security requirements are two controls — not a background-check program. At CMMC Level 2 they are PS.L2-3.9.1 (screen people before you let them into systems that hold CUI) and PS.L2-3.9.2 (keep those systems protected when someone is terminated or transferred). They come from §3.9 of NIST SP 800-171 Revision 2. Between them they carry four assessment objectives and eight score points, and neither one can go on a Plan of Action and Milestones (POA&M). Level 1 has no personnel security requirements at all. Level 3 adds exactly one.
Here's the part almost nobody has noticed, and it's the reason this page exists.
32 CFR Part 170 — the CMMC Program rule — does name a specific, federally defined personnel screening standard. It names it in four separate places. It names the investigation tier, the form, and the risk designation, right down to the Title 5 citations.
Every one of those four places applies to the assessment ecosystem around you. None of them prescribes the screening standard for your own workforce.
We'll show you all four, with the section numbers, so you can check it yourself in about two minutes.
The 30-second answer
| CMMC level | Personnel security requirements | Points at stake | Can you defer them? |
|---|---|---|---|
| Level 1 (FCI only) | None. The 15 requirements at Level 1 sit in six domains — access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. Personnel security isn't one of them. | 0 | Level 1 allows no POA&M at all |
| Level 2 (CUI) | Two: PS.L2-3.9.1 (3 points, 1 objective) and PS.L2-3.9.2 (5 points, 3 objectives) | 8 | No — neither one |
| Level 3 (CUI tied to designated critical programs or high-value assets) | Everything at Level 2, plus one enhanced requirement: PS.L3-3.9.2e, on what you do when adverse information surfaces about someone with CUI access | 1 additional point | Level 3 requires a maximum Level 2 score to even begin |
Sources: 32 CFR §170.14(c)(2)–(4); §170.24(c); §170.21(a)(2). Verified at the eCFR on August 20, 2026.
Current status — verified August 20, 2026. CMMC Phase II implementation was suspended on July 13, 2026. Level 1 and Level 2 self-assessments remain in force, and DFARS 252.204-7012 safeguarding obligations were not eliminated. Nothing about the suspension changed the text of PS.L2-3.9.1 or PS.L2-3.9.2. If you've read that "Phase 2 enforcement begins November 10, 2026," that page is out of date — see our current CMMC phase status coverage. We are not going to build urgency on a suspended deadline.
Who this page is for — and who should leave
Read this if: you're writing the personnel security section of your System Security Plan (SSP) and there's nothing obvious to write. Or a prime's questionnaire asked whether you background-check people with CUI access. Or a mock assessment flagged 3.9.2 because somebody left in March and their account was still live in July. Or you're the HR lead who just got told "CMMC requires background checks" and you want to know what that costs, legally and financially, before you sign off.
Skip this if: you only handle Federal Contract Information (FCI) on a Level 1 path. Personnel security doesn't apply to you, and we'd rather you spend the next ten minutes on our CMMC Level 1 self-assessment checklist than read a page about requirements you don't have.
Also skip this if your real question is about security clearances, facility clearances, or insider threat programs under the NISPOM. Those are a different federal program with different rules. We'll show you exactly where the line falls further down, but we're not going to teach the NISPOM here.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citations for material regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
What are the CMMC personnel security requirements?
Answer capsule: CMMC Level 2 contains two personnel security requirements, drawn from §3.9 of NIST SP 800-171 Revision 2. PS.L2-3.9.1 requires screening individuals before authorizing their access to systems containing Controlled Unclassified Information (CUI). PS.L2-3.9.2 requires that those systems stay protected during and after personnel actions such as terminations and transfers. NIST SP 800-171A breaks the two into four assessment objectives — one for screening, three for personnel actions.
The Personnel Security domain (abbreviated PS in CMMC's identifier scheme) is the smallest of the 14 control families in NIST SP 800-171 Rev. 2. Two requirements out of 110. Less than two percent of the standard.
That's what makes people careless with it.
The identifier, decoded
CMMC identifiers look cryptic until you know the pattern. 32 CFR §170.14(c)(1) spells it out: domain, level, requirement number.
- PS = Personnel Security domain
- L2 = CMMC Level 2
- 3.9.1 = the NIST SP 800-171 Rev. 2 requirement number
So PS.L2-3.9.1 and NIST SP 800-171 Rev. 2 requirement 3.9.1 are the same thing. §170.14(c)(3) is explicit that the Level 2 security requirements are identical to NIST SP 800-171 Rev. 2.
If you see PS.2.127 or PS.2.128, you're reading CMMC 1.0 identifiers that stopped being current years ago. The same is true of descriptions that give CMMC 171 practices across 17 domains and five maturity levels. That model is gone.
PS.L2-3.9.1 — Screen individuals
The requirement is to screen people before you authorize their access to organizational systems containing CUI. (NIST SP 800-171 Rev. 2, §3.9.1)
Three things about that sentence do real work:
The trigger is access, not hiring. The control attaches to the moment you authorize someone into a CUI system. Not their start date. Not their offer letter. This matters more than it sounds — we'll come back to it when we talk about new hires who can start work on day one.
The system has to contain CUI. If someone never touches a system that holds CUI, 3.9.1 isn't triggered by their employment alone.
Order of operations is the whole control. Screening has to come first. And you have to be able to prove the sequence, which means the "screening complete" date and the "access granted" date need to be independently visible somewhere.
PS.L2-3.9.2 — Personnel actions
The second requirement covers what happens when someone leaves or changes roles: systems holding CUI have to stay protected through the personnel action and afterward. The rule names terminations and transfers as its examples.
Note that word — examples. Terminations and transfers are illustrations of personnel actions, not an exhaustive list. Contract end dates, assignment changes, and extended reassignments should run through the same personnel-action process whenever they change authorized access.
The two numbers people confuse
NIST SP 800-171 establishes two personnel security requirements. Four is the number of assessment objectives.
PS-3 is a control identifier from NIST SP 800-53 — a different publication with a different numbering scheme and a nine-control personnel security family. NIST SP 800-171 Rev. 2 uses 3.9.1 and 3.9.2. If a page mixes those catalogs, it is mixing two different standards.
Before we go further: the honest part
We're a lead-routing publication. We make money when readers who need help get matched with the right kind of provider. So take this in the spirit it's offered.
There is no mandatory CMMC product to buy for this control family.
No platform makes PS.L2-3.9.1 true. No managed service provider can own your screening standard or your access-authorization decision — those belong to your management or HR lead, with employment counsel where needed. And PS.L2-3.9.2 isn't a product either. It's a handoff among departments that already exist in your company.
If a proposal you're reviewing has a line item called "personnel security," ask what the deliverable is. If the answer is a policy template, that's fine — just know what a policy template costs.
Now the pivot, because it's the actual point of this page: one of the least tool-dependent families in the standard is the one that quietly takes eight non-deferrable points off your score. Not because the controls are hard. Because the evidence is a records problem across HR, IT, and facilities, and nobody owns records problems until an assessor asks for one. That's a program design issue, and that's where a readiness partner genuinely earns a fee — not on the background checks.
Does CMMC require background checks?
Answer capsule: CMMC requires personnel screening before authorized access to CUI systems, but it does not prescribe a specific background check. The Department of Defense CIO's own CMMC Assessment Guide – Level 2 describes what's expected as "organization-defined" screening based on the position and role, and presents criminal and credit checks as an example rather than a mandate. CMMC itself sets no lookback period, vendor, form, or minimum depth for a contractor's own workforce.
This is the question that brought most readers here, so let's answer it completely.
The CMMC instruments do not tell a defense contractor what kind of background check to run on its own employees. Not 32 CFR Part 170. Not NIST SP 800-171 Rev. 2. Not the DoD CIO assessment guidance. The requirement says screen. The official guide says the screening is "organization-defined," based on the requirements for a given position and role, and then offers criminal and credit checks as an illustration.
NIST's discussion behind 3.9.1 describes screening as a judgment about trustworthiness — a person's "conduct, integrity, judgment, loyalty, reliability, and stability" — and says screening activities reflect applicable federal laws, executive orders, directives, policies, regulations, and criteria established for the level of access required.
Read that last clause carefully. It points to criteria established for the level of access required for assigned positions.
For a federal employee or a cleared contractor, separate position-risk, suitability, or national-security criteria may exist. For a DIB contractor holding CUI on its own unclassified systems, CMMC itself does not establish that screening depth. The pointer points outside the CMMC rule.
The contrast is still revealing, because DoD did write down a screening standard inside the CMMC rule. Just not for your workforce.
The screening standard the CMMC rule actually names
Here's the finding. We read 32 CFR Part 170 section by section at the eCFR on August 20, 2026. Part 170 names a specific federal personnel vetting standard — a Tier 3 background investigation, initiated with Standard Form 86, with positions designated non-critical sensitive at a "Moderate Risk" level under 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2).
It names that standard four times. Look at who it applies to.
| Who the rule screens | Named standard? | Investigation | Form | Risk designation | Citation |
|---|---|---|---|---|---|
| Accreditation Body board of directors, professional staff, IT staff, accreditation staff, and independent CCA staff | Yes | Tier 3; national-security eligibility determination | SF-86 | Non-critical sensitive; Moderate Risk | 32 CFR §170.8(b)(4) |
| All C3PAO personnel participating in a Level 2 certification assessment, expressly including the assessment team and quality-assurance individual | Yes | Tier 3; national-security eligibility determination | SF-86 | Non-critical sensitive; Moderate Risk | 32 CFR §170.9(b)(3) |
| CMMC Certified Assessor (CCA) | Yes | Tier 3; national-security eligibility determination | SF-86 | Non-critical sensitive; Moderate Risk | 32 CFR §170.11(b)(3) |
| CMMC Certified Professional (CCP) | Yes | Tier 3; national-security eligibility determination | SF-86 | Non-critical sensitive; Moderate Risk | 32 CFR §170.13(b)(3) |
| Your employees with CUI-system access | No contractor-workforce standard named | — | — | — | PS.L2-3.9.1; screening is organization-defined in the official guide |
| Your MSP or external service provider's staff with CUI-system access | No contractor-workforce standard named | — | — | — | PS.L2-3.9.1; responsibility must be defined and evidenced |
| A Level 3 contractor's employees | No contractor-workforce standard named | — | — | — | Table 1 to 32 CFR §170.14(c)(4) selects 3.9.2e, not 3.9.1e |
Compiled by The Defense Compliance Report from 32 CFR Part 170 and the official CMMC Assessment Guide – Level 2, read directly on August 20, 2026. The eCFR displayed Title 32 as current through August 18, 2026.
The rule is careful to say a Tier 3 investigation doesn't produce a security clearance and isn't being run for government employment purposes. So this isn't a clearance story. It's a published, specific, federally defined vetting standard — applied to people who grade assessments, participate in them, hold assessor credentials, or oversee the assessment ecosystem.
And CMMC does not prescribe that same standard for the company being assessed.
What that means practically: when you ask "what background check does CMMC require of me," the honest answer is that Part 170 writes a precise answer for the assessment ecosystem while leaving your workforce screening organization-defined. A CCA who assesses you must meet the Tier 3/SF-86 standard or its DoD-determined equivalent. CMMC does not impose that standard on your machinist merely because the machinist can access CUI.
That's not a loophole and it's not permission to skip screening. Screening is required. The CMMC screening depth is yours to set, in writing, and to defend — unless another contract term or legal authority sets it for you.
What we recommend you actually do
This is our editorial recommendation, not a rule. Label it that way in your own SSP.
Write a one-page screening standard that answers five questions:
- Which roles get authorized access to CUI systems?
- What screening applies to each of those roles — and why that depth fits that role?
- Who reviews and records completion?
- What status permits access to be granted?
- How are exceptions handled, and who approves them?
Then apply it consistently, complete it before access, and keep the record. That one-page standard plus a completion log gives you the core evidence for the single assessment objective under 3.9.1; the assessor still tests whether the process operated as written.
The part the background-check vendors don't lead with
Running background checks is not free of obligation. When an employer obtains an employment background report from a consumer reporting company, the Fair Credit Reporting Act can impose disclosure, written authorization, and adverse-action requirements. Federal equal-employment law requires that background information be used consistently and without discrimination. State and local rules add more, and they vary considerably. The FTC and the EEOC publish joint guidance for employers on exactly this.
We are not lawyers and this is not legal advice. But here is the practical consequence:
CMMC requires screening but does not prescribe a criminal, credit, or commercial background check — and choosing one can create legal obligations CMMC does not resolve for you. That combination makes this a decision for your HR lead and your employment counsel — not your IT director, and not your MSP.
If a compliance vendor is designing your screening program, something has gone sideways in your org chart.
✅ Turn the recommendation into an approved policy and evidence plan
Use the CMMC readiness checklist to place personnel security inside the rest of your Level 2 work, then use our policies and procedures guide to separate what must be approved from what must be proven in operation.
Open the CMMC readiness checklist →
See what a CMMC policy and procedure set actually needs →
⚠️ Do not submit employee names, Social Security numbers, dates of birth, background-report results, CUI, drawings, credentials, or contract details through a website form.
Before you go further: which provider category do you actually need?
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation and resulting contract language set your required CMMC status and assessment type, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
(Definitions, since we'll use these terms throughout: a C3PAO is a CMMC Third-Party Assessment Organization, authorized to conduct Level 2 certification assessments. An RPO/RP is a Registered Provider Organization or Registered Practitioner, providing readiness advice. An MSSP is a Managed Security Service Provider. A GRC platform is governance, risk, and compliance software. A CUI enclave is a segmented environment built to hold CUI so the rest of your network doesn't have to.)
A C3PAO is an assessor, not a guaranteed-certification vendor. Part 170 restricts a CMMC ecosystem member from participating in a Level 2 certification assessment when that member served as a consultant preparing the organization for a CMMC assessment within the prior three years, and the Cyber AB CMMC Assessment Process bars a C3PAO from promising or guaranteeing an assessment result.
Who must be screened before CUI access?
Answer capsule: PS.L2-3.9.1 attaches to individuals receiving authorized access to organizational systems containing CUI — not to payroll status. The requirement text says "individuals," while the DoD CIO's further discussion refers to employees. Applying the same screening gate to contractors, temporary staff, interns, and vendor administrators who receive equivalent CUI-system access is a reasonable access-based reading, but contractors should recognize it as an implementation judgment rather than explicit rule text.
There's a gap in the source documents worth knowing about, because every hard question on this page lives inside it.
The requirement says "individuals." The official further discussion says "employees."
That's not a contradiction so much as a narrowing, and it leaves the contractor-and-temp question unresolved in the source material. Our position — stated as our position, not as rule text — is that the sensible reading follows access, not employment classification. If a person is authorized into a system that holds CUI, the screening gate should apply to them, and your SSP should say so plainly.
| Person | Authorized CUI-system access? | Our working conclusion |
|---|---|---|
| Employee | Yes | Screen before access is granted |
| Employee | No | 3.9.1 isn't triggered by employment alone |
| Contractor, temp, or intern | Yes | Apply the same gate; document who performs and evidences the screening |
| Vendor or MSP administrator | Yes | Apply the same gate; handle responsibility and evidence contractually — see below |
| Visitor with no system access | No | Handle under physical protection and visitor controls instead |
| Sole owner or one-person company | Yes | Use a defined, evidenced process; confirm the approach with an RP/RPO or counsel before relying on it |
New hires can start on day one
This is the question that causes a mild panic two days before a start date.
The control gates CUI-system access, not employment. A new hire can begin work, complete onboarding, attend training, and do plenty of productive things while screening is pending — as long as they aren't authorized into a system that holds CUI.
Employment day one and CUI access day one are two different decisions. Separate them in your onboarding workflow and the tension disappears.
Existing employees who gain new access
Long tenure isn't evidence. If someone has worked for you for eighteen years and is now being added to the CUI environment for the first time, the screening gate applies at the moment access changes.
This is a quiet gap an assessor can find in a small company, because the screening record for a 2007 hire either doesn't exist or can't be located.
Contractors, temps, and your MSP
For someone else's employee, screening authority, privacy, and evidence usually become contract questions rather than a unilateral HR process:
- Define the screening standard you require for anyone authorized into your CUI systems.
- Require the provider to attest in writing that their personnel meet it.
- Track assignment and contract end dates as access-termination triggers, alongside employee departures.
- Include third-party personnel in your personnel-action notifications.
If your MSP holds administrative credentials in your CUI environment, its staff turnover can create a 3.9.2 exposure in your environment unless responsibility and evidence are defined. The agreement needs to address it. See our coverage of external service provider assessment scope for where ESP boundaries sit in the broader model.
What must happen when someone is terminated or transferred?
Answer capsule: PS.L2-3.9.2 requires three things: an established policy or process for terminating system access and credentials alongside personnel actions, actual termination of that access consistent with the personnel action, and protection of the system during and after transfers. Transfers are a separately tested assessment objective, not an afterthought to terminations. Neither the CMMC rule nor NIST specifies a universal deadline for disabling access.
This is the five-point requirement. It's also easy to fail on evidence rather than intent, because it depends on a handoff between departments.
The three objectives, in plain terms
NIST SP 800-171A (June 2018, the version incorporated by Part 170) breaks 3.9.2 into three determinations. Rendered plainly — the exact wording is in the CMMC Assessment Guide – Level 2:
| Objective | What has to be true | Where it usually fails |
|---|---|---|
| [a] | A policy or process exists for ending system access and credentials in step with personnel actions | The process exists in someone's head, or lives in a draft document |
| [b] | Access and credentials are actually ended, consistently with the personnel action that occurred | HR knew. IT didn't. Nobody was accountable for the handoff |
| [c] | The system stays protected during and after a transfer | There's no transfer workflow at all — only a termination checklist |
Objective [c] is the sleeper. If you reduce 3.9.2 to offboarding, you miss a separately tested objective. Transfers get their own determination. An internal move from engineering to sales, where the person keeps the CUI folder access they no longer need, fails objective [c] on its own — and takes all five points with it, because a requirement is only MET when every applicable objective is satisfied.
Is there a required CMMC offboarding deadline?
No. And this is where a lot of published advice goes wrong.
Advice that presents "immediate" action or "within 24 hours" as a universal CMMC mandate is wrong. Neither 32 CFR Part 170 nor NIST SP 800-171 Rev. 2 sets an hour count for disabling access.
What the official guidance actually does is stress timely execution, note that timeliness matters most for individuals terminated for cause, and observe that in certain situations organizations consider disabling accounts before the person is notified.
Here's the operational consequence, and it's the most useful sentence on this page:
The official guide contemplates a defined time frame but does not supply the number. You define the window in your process; your evidence then has to match it.
That cuts both ways. A policy promising two-hour revocation, backed by records showing five days, creates a direct contradiction between your approved process and your evidence. A policy promising one business day, backed by tickets showing one business day, is defensible and boring — which is what you want.
Pick a number your workflow can actually hit. Then engineer the workflow to hit it.
Our trigger-to-action model, by event type
This is our operational model, not a rule-defined SLA.
| Trigger | Recommended workflow | Evidence that proves it |
|---|---|---|
| New hire needs CUI access | Verify screening complete before access approval | Screening completion date + access authorization date |
| Existing worker gains CUI duties | Complete applicable screening before the new access | Role-change record, screening completion, approval |
| Voluntary resignation | Execute the defined final-access plan on the final day | HR notice, disablement logs, asset-return record |
| Involuntary or for-cause termination | Risk-based coordination; consider disabling access before notification | Restricted HR trigger, disablement timestamps, account reconciliation |
| Internal transfer or reassignment | Remove obsolete access; add only approved new access | Old-role vs. new-role access comparison, manager approval |
| Contractor or assignment end | End digital and physical access; recover assets | Contract-end trigger, tickets, access logs |
| Remote departure | End access under the defined risk-based clock; accelerate elevated-risk cases; track hardware return separately | Disablement logs, return tracking, exception record |
Note the asymmetry in the remote row. Account and credential termination and device recovery are different clocks. Your evidence should show that access ended on schedule even when the laptop took three weeks to come back. A delayed device return still needs risk treatment — especially if the device stores CUI — but it should not delay account and authenticator revocation.
What the official discussion says to collect
The NIST discussion behind 3.9.2 mentions returning system-related property — hardware authentication tokens, identification cards, system administration manuals, keys, building passes — and conducting exit interviews that remind departing individuals of nondisclosure obligations. It also acknowledges, refreshingly, that exit interviews aren't always possible: job abandonment, illness, and unavailable supervisors all happen.
Treat those as strong implementation practices and potential evidence, not as extra assessment objectives. The four objectives are what get assessed.
What evidence will a CMMC assessor examine for personnel security?
Answer capsule: For screening, assessors may examine personnel security policies, screening procedures, records of screened personnel, and SSP content; interview personnel security and information security staff; and test the screening process. For personnel actions, they may examine termination and transfer records, system account lists, records of revoked credentials, and exit interview records. Under 32 CFR §170.24(b)(1), a requirement is MET only when all applicable objectives are satisfied by evidence in final form — drafts and unapproved policies don't count.
This is the section we'd print and hand to whoever owns your evidence library. It's also our primary original asset for this page: a single table mapping each of the four objectives to what has to be true, what proves it, what an assessor may do to test it, which department executes it, and what the requirement does not extend to.
Assembling this by hand means opening 32 CFR §170.24 for the scoring, §170.21 for the POA&M rules, NIST SP 800-171A for the objectives and assessment methods, and the DoD CIO Level 2 Assessment Guide for the discussion — then reconciling four documents that use different vocabulary. We did that. Here's the result.
The Personnel Security Requirement-to-Evidence Matrix
| Objective | What must be true | Evidence packet | How an assessor may test it | Operational handoff | Score / POA&M | What the requirement does not say |
|---|---|---|---|---|---|---|
| PS.L2-3.9.1 [a] | The individual is screened before authorized access to a system containing CUI | Personnel security policy; role-based screening procedure; completion record with date; access-authorization date; SSP language; a recent sample showing screening preceded access | Examine: policy, procedure, screening records, SSP. Interview: personnel-security owner, information-security owner. Test: the screening and access-approval process | HR records completion → access approver verifies status → IT provisions CUI-system access | 3 points. Not POA&M-eligible. | It does not name a check type, lookback period, vendor, form, citizenship rule, or re-screening interval |
| PS.L2-3.9.2 [a] | A policy or process exists for ending system access and credentials alongside personnel actions | Approved termination/transfer procedure; HR notification workflow; ticketing or identity-management workflow; named responsibility; defined timing; SSP reference | Examine: procedures, workflow documentation. Interview: HR, account management. Test: notification and workflow mechanisms | Documented, executable, and owned by a named role — not a habit | Part of the 5-point requirement. Not POA&M-eligible. | It does not prescribe a specific HR system, ticketing tool, or hour-count SLA |
| PS.L2-3.9.2 [b] | Access and credentials are actually terminated, consistent with the personnel action | Personnel-action record; system account list; disablement timestamps; revoked authenticators and tokens; VPN, cloud, email, and privileged-account records; badge and physical-access records; asset-return record | Examine: account lists, revocation records, personnel-action records. Interview: administrators, security staff. Test: disablement and revocation mechanisms | HR trigger → IT/IAM disables → facilities revokes badges and keys → asset owner recovers devices → control owner reconciles | Part of the 5-point requirement. Not POA&M-eligible. | It does not impose a universal 24-hour deadline; it requires action consistent with the personnel action |
| PS.L2-3.9.2 [c] | The system stays protected during and after a transfer or reassignment | Transfer record; old-role vs. new-role access comparison; group-membership changes; privileged-access review; physical-access change; completed transfer checklist; manager approval | Examine: transfer records, access-change records. Interview: HR, managers, administrators. Test: the transfer process and resulting access | Manager defines new duties → HR records the transfer → IT removes obsolete access and grants only approved access → facilities adjusts physical rights | Part of the 5-point requirement. Not POA&M-eligible. | It is not limited to permanent moves; apply the process to any reassignment that changes required access |
Compiled by The Defense Compliance Report from NIST SP 800-171A, the official CMMC Assessment Guide – Level 2 (DoD CIO, v2.13, September 2024), 32 CFR §170.24, and 32 CFR §170.21. Verified August 20, 2026. The “operational handoff” and “what the requirement does not say” columns are our editorial analysis derived from those sources.
Version note: NIST withdrew SP 800-171A (June 2018) on May 14, 2024 after publishing Revision 3. CMMC Level 2 still explicitly incorporates the June 2018 assessment procedures at 32 CFR §§170.16(c)(1) and 170.17(c)(1). Revision 3 does not automatically replace the CMMC-controlling assessment publication.
Examine, interview, test — three different failure modes
Assessment methods aren't interchangeable, and each one catches a different kind of weakness:
- Examine asks whether the artifact exists. A missing procedure fails here.
- Interview asks whether the people responsible can describe what actually happens. A procedure nobody follows fails here — and it fails loudly, because two interviewees will describe two different processes.
- Test asks whether the mechanism works when demonstrated or sampled. A process that works in theory and breaks on the last three departures fails here.
Most companies prepare for examine and get caught by interview.
Final evidence, not promises
32 CFR §170.24(b)(1) is unusually blunt about this. A requirement is MET only when all applicable objectives are satisfied based on evidence, and that evidence must be in final form — not draft. The rule specifically names working papers, drafts, and unofficial or unapproved policies as unacceptable.
A personnel security policy sitting in review with three tracked-changes comments in it is not evidence. Approve it.
Also worth knowing: under §170.24(b)(3), an objective assessed as Not Applicable is treated the same as MET. If an objective genuinely does not apply to your environment, document why in the SSP rather than leaving it blank.
Retention and privacy — the tension nobody flags
Level 2 evidence carries a six-year retention obligation running from the CMMC Status Date. For Level 2 self-assessments, the OSA retains the supporting artifacts. For Level 2 certification assessments, §170.17 requires the OSC to retain the artifacts whose names and hash values are recorded in eMASS.
Now consider what you'd be retaining. Full background reports contain exactly the kind of personal information you don't want sitting in a broadly accessible evidence folder for six years.
Our recommendation, clearly labeled as ours: separate the proof of completion from the underlying report contents. Design the completion artifact to establish who or which role was screened, whether screening was complete, when it was complete, when access was authorized, and which procedure applied without duplicating sensitive report contents. Keep completion records in your evidence library and source reports in restricted HR files.
If an assessor asks for something you believe you shouldn't produce, that's a conversation to have with counsel and the assessment team — not a decision to make unilaterally on assessment day.
✅ Use the matrix against your own records
Take one recent hire, one transfer, and one departure. Map each record to the objective letters above, then use the CMMC readiness checklist to place any remaining gaps in the correct remediation sequence.
Open the CMMC readiness checklist →
⚠️ Do not submit names, CUI, credentials, background-report data, drawings, or sensitive contract details.
How many points are the CMMC personnel security requirements worth?
Answer capsule: Under the CMMC Scoring Methodology at 32 CFR §170.24, PS.L2-3.9.1 carries 3 points and PS.L2-3.9.2 carries 5 — eight points of the 110-point Level 2 maximum. Because 32 CFR §170.21(a)(2)(ii) bars any requirement worth more than one point from a Level 2 POA&M, with a narrow encryption exception that does not apply here, neither personnel security requirement can be deferred.
We read §170.24 in full at the eCFR on August 20, 2026 to confirm both values. Both are listed as basic security requirements, and they fall in different scoring tiers.
PS.L2-3.9.2 is in the five-point tier — the tier the rule reserves for requirements whose absence could lead to significant exploitation of the network or exfiltration of CUI. Personnel actions are scored as seriously as boundary protection and malicious code protection.
PS.L2-3.9.1 is in the three-point tier — the tier for requirements with a specific and confined effect.
| Requirement | Basic or derived | Objectives | Points if NOT MET | Partial credit? | POA&M eligible? |
|---|---|---|---|---|---|
| PS.L2-3.9.1 Screen Individuals | Basic | 1 | 3 | No | No |
| PS.L2-3.9.2 Personnel Actions | Basic | 3 | 5 | No | No |
| Family total | — | 4 | 8 | — | 0 of 2 |
Source: 32 CFR §170.24(c)(2)(i)(B) and §170.21(a)(2). Verified August 20, 2026.
The total is eight points, not four. And neither requirement is POA&M-eligible — nothing above one point is, apart from the narrow FIPS-validated encryption exception at SC.L2-3.13.11.
Why "eight points" understates the risk
The point deduction is the small part. Here's the arithmetic that should change how you sequence your remediation.
To reach Conditional Level 2 status, §170.21(a)(2) requires a score of at least 88 of 110 and that nothing on the POA&M is worth more than one point. Those are two independent tests, and the second one has no partial credit.
So run two companies:
- Company A meets 108 of 110 requirements. The two misses are PS.L2-3.9.1 and PS.L2-3.9.2. Score: 102. That's 93%. No conditional path from that assessment. Both gaps are ineligible for a POA&M.
- Company B scores 88 of 110, with only POA&M-eligible one-point gaps and every other §170.21 condition satisfied. Conditional status is available, with 180 days to close out.
Company A may have implemented far more requirements but cannot obtain Conditional Level 2 from that assessment; Company B may qualify for Conditional status. That's not a criticism of the rule; it's how a weighted, deferral-limited scoring system behaves. But it means the order you fix things in matters more than the total you fix.
There's no partial credit here either. §170.24(c)(2)(i)(B)(4) allows adjusted scoring for exactly two requirements in the whole standard — multi-factor authentication and FIPS-validated encryption. Personnel security is all-or-nothing. Satisfy two of the three objectives under 3.9.2 and you lose all five points.
A family-level fact worth knowing
When we built our scored breakdown of all 110 requirements, we computed the one-point count for every family. Personnel Security and System and Information Integrity contain no one-point requirements. Security Assessment contains one — CA.L2-3.12.4, the SSP requirement — but §170.21(a)(2)(iii)(C) expressly bars it from a POA&M.
Three of the fourteen families therefore contain no deferrable requirements at all: Personnel Security, Security Assessment, and System and Information Integrity. Personnel Security is the smallest and least tool-dependent of the three — which is exactly why it gets scheduled late and discovered late.
The people layer, priced
One more computation from the same source. Two families in NIST SP 800-171 Rev. 2 are about human beings rather than machines: Awareness and Training (AT) and Personnel Security (PS).
AT.L2-3.2.1 and AT.L2-3.2.2 are both five-point basic requirements. AT.L2-3.2.3 is the family's only one-pointer. Add personnel security's 3 and 5, and the people layer comes to five requirements and 19 points — of which exactly one point is deferrable.
Nineteen points riding on training records and HR handoffs, and effectively none of it can be pushed to a POA&M. (Training itself belongs to a different family and a different page — we're citing it here only for the arithmetic.)
Who owns this — HR, IT, security, or facilities?
Answer capsule: CMMC does not assign the personnel security family to a department. In practice, HR or management generates the authoritative personnel trigger, IT or identity administrators execute digital access changes, facilities handles badges and physical access, and security or compliance reconciles the evidence against the four assessment objectives. The control fails in the gaps between those groups more often than inside any one of them.
Personnel security is one of the clearest families in NIST SP 800-171 Rev. 2 where the primary owner may sit outside your IT department. That's the whole difficulty.
The following is The Defense Compliance Report's editorial operating model — a recommendation derived from the objectives and assessment methods, not a division of labor found anywhere in the rule.
| Activity | Accountable | Responsible | Consulted | Holds the evidence |
|---|---|---|---|---|
| Define role-based screening | Executive or HR lead | HR / personnel security | Security, employment counsel, program owner | HR / compliance |
| Record screening completion | HR lead | HR / personnel security | Security | HR |
| Approve CUI-system access | Security or system owner | IT / IAM | HR, hiring manager | IT / security |
| Initiate a termination or transfer | HR / management | HR | Legal and security as needed | HR |
| Disable or modify accounts | IT lead | IT / IAM administrators | Security, manager | IT |
| Revoke badges, keys, passes | Facilities or security lead | Facilities | HR | Facilities |
| Recover devices, tokens, media | Asset owner | IT / facilities | HR, manager | IT / facilities |
| Reconcile completion | Compliance or security lead | Control owner | HR, IT, facilities | Compliance |
| Sample-test recent events | Compliance or security lead | Internal assessor | HR, IT | Compliance |
The handoff that fails
The 3.9.2 failures in the table below often trace to the same root cause: the personnel action never reached the person who could act on it.
Not malice. Not incompetence. A resignation gets handled by a manager, HR processes the final paycheck, and nobody sends a ticket. Six weeks later there's an active VPN account belonging to someone who works for your competitor.
The five-line fix:
- One authoritative trigger — a single record type in HR that means "access must change."
- A unique event ID that IT, facilities, and compliance all reference.
- Task generation for every access category, not just the domain account.
- An exception path for anything that can't be closed on time, with a named approver.
- Closed-loop confirmation back to whoever owns the control.
That's it. It costs a workflow change, not a purchase order.
When HR gives late notice
It will happen. What matters is what you do with it:
- Execute immediately.
- Record the actual trigger receipt time, not the departure date.
- Assess whether anything happened in the gap.
- Fix the handoff.
- Never retroactively adjust timestamps. An assessor who catches an edited record has a much bigger problem in front of them than a late revocation.
Repeated late notice is a process failure, and it's better to document it honestly with a corrective action than to paper over it.
What changes at CMMC Level 1 and Level 3?
Answer capsule: CMMC Level 1 has no personnel security requirements — its 15 safeguarding requirements from FAR 52.204-21 sit in six other domains. CMMC Level 3 adds exactly one personnel security requirement, PS.L3-3.9.2e, addressing what an organization does when adverse information develops about someone with CUI access. Level 3 also requires a maximum score on the Level 2 certification assessment before it can begin.
Level 1: nothing here
32 CFR §170.14(c)(2) sets Level 1 as the 15 requirements at 48 CFR 52.204-21(b)(1)(i) through (xv). Those 15 fall into six domains — access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.
Personnel security isn't among them. Neither is awareness and training, audit and accountability, configuration management, incident response, maintenance, risk assessment, or security assessment.
If you handle FCI only, you do not have a CMMC personnel security requirement. Full stop. Don't let a vendor sell you one. Our Level 1 self-assessment checklist has all 15, and it also reconciles the "17 practices" number you'll still see floating around from the old model.
Level 3: one requirement, and a revealing omission
Level 3 draws 24 enhanced requirements from NIST SP 800-172 (February 2021), listed in Table 1 to 32 CFR §170.14(c)(4). We read all 24 rows on August 20, 2026.
Exactly one is a personnel security requirement: PS.L3-3.9.2e, requiring that organizational systems be protected if adverse information develops or is obtained about individuals with CUI access. NIST's discussion describes the response — precluding or limiting further access, auditing that person's actions — while the adverse information is resolved.
No DoD-assigned organization-defined parameter is attached to this row in Table 1.
Now here's what's missing, and it's the through-line of this entire page.
We read §3.9 of NIST SP 800-172 in the published PDF. The personnel security family there contains exactly two enhanced requirements:
- 3.9.1e — conduct organization-defined enhanced personnel screening, and reassess individual positions and CUI access on a defined frequency.
- 3.9.2e — protect systems when adverse information develops about someone with CUI access.
DoD selected 3.9.2e for CMMC Level 3. DoD did not select 3.9.1e.
Sit with that for a second. NIST wrote an enhanced screening requirement specifically for contractors handling CUI tied to critical programs and high value assets — the advanced persistent threat tier, the most sensitive work in the Defense Industrial Base. It is the personnel-security requirement that would have introduced periodic re-screening and enhanced screening.
DoD left it on the table.
| Level | Personnel security requirements | Screening standard defined by CMMC? |
|---|---|---|
| Level 1 | None | N/A |
| Level 2 | PS.L2-3.9.1, PS.L2-3.9.2 | No prescribed check type or depth — screening is organization-defined in the official guide |
| Level 3 | PS.L3-3.9.2e, plus the Level 2 baseline | No enhanced screening requirement selected — 3.9.1e was available in SP 800-172 but was not selected for CMMC Level 3 |
Compiled by The Defense Compliance Report from Table 1 to 32 CFR §170.14(c)(4), NIST SP 800-172 (February 2021) §3.9, and the official CMMC Assessment Guide – Level 2. All were read directly on August 20, 2026.
At every level of CMMC, the controlling text stops short of prescribing a contractor-workforce screening type, depth, or cadence. At Level 3, that includes selecting 3.9.2e while not selecting the enhanced screening requirement NIST had already drafted as 3.9.1e.
Worth noting in fairness: NIST's own discussion for 3.9.1e says federal vetting processes may be extended, in whole or in part, to people accessing CUI in nonfederal systems through contractual vehicles. So the route exists through contractual vehicles, and other legal authorities can impose separate screening conditions. If a specific screening standard applies to you, read the actual clause, program requirement, law, or regulation that imposes it.
One recency note on Level 3
NIST published SP 800-172 Revision 3 as final on May 13, 2026. CMMC Level 3 still incorporates the February 2021 version by reference under 32 CFR §170.2.
So Rev. 3 does not change the CMMC-controlling Level 3 baseline today. This is the same pattern we documented for NIST SP 800-171 Rev. 3 — NIST publishes, the Department regulates, and incorporation by reference doesn't auto-update. Watch for a rule amendment, not a NIST press release. Our NIST SP 800-171 Revision 2 versus Revision 3 comparison tracks which instrument pins which version, and our SP 800-171 versus SP 800-172 comparison explains the Level 2/Level 3 split.
Eight things people think are CMMC personnel requirements — and aren't
Answer capsule: The CMMC personnel security family covers screening before CUI access and access protection during personnel actions. It does not itself impose security clearances, insider threat programs, citizenship restrictions, security awareness training, position-risk designations, periodic re-screening, or a universal offboarding hour count. Some of those obligations may arise under other laws, regulations, programs, or contract terms, but none originates in PS.L2-3.9.1 or PS.L2-3.9.2.
This is the deconfliction table. Every row points somewhere else on purpose — we'd rather send you to the right authority than expand this page into a survey of federal security law.
| What people assume CMMC requires | In the PS family? | What actually governs it |
|---|---|---|
| A specific background check | No prescribed check type | Your contract or another legal authority may specify one. The named Tier 3/SF-86 standard in Part 170 applies to the assessment ecosystem — §§170.8, 170.9, 170.11, 170.13 |
| A security clearance | No | The National Industrial Security Program — 32 CFR Part 117 and the DD Form 254. A separate program with separate oversight |
| An insider-threat program with a designated official | No | The NISPOM. 32 CFR §117.7(b)(4) requires an Insider Threat Program Senior Official for cleared contractors under the National Industrial Security Program |
| Annual security awareness or CUI training | No | The Awareness and Training family — AT.L2-3.2.1, 3.2.2, and 3.2.3. Level 3 adds AT.L3-3.2.1e and AT.L3-3.2.2e. Training records don't prove screening |
| U.S. citizenship for CUI access | No | Nothing in NIST SP 800-171 Rev. 2 says it. Export-control rules, contract terms, and specific CUI categories can → CMMC scoping guide |
| Position-risk designations and investigation tiers | No | The federal position-risk system at 5 CFR Part 1400 and 5 CFR Part 731 — invoked by Part 170 for the assessment ecosystem, not as the PS.L2-3.9.1 standard for your workforce |
| Periodic re-screening on a set interval | No | That's NIST SP 800-172's 3.9.1e, which DoD did not select for CMMC Level 3 |
| A defined number of hours to cut off access | No | You define a defensible risk-based window; see the offboarding section above |
Two of these deserve a sentence more.
Security clearances. A completed clearance investigation may well be relevant evidence that a person was screened. What it isn't is an automatic universal answer to 3.9.1. Your SSP still needs to say what screening occurred, when it completed relative to CUI access, and why it satisfies your written procedure. If a clearance is pending, it is not completed screening evidence. Do not authorize CUI-system access until the screening required by your approved procedure is complete.
Training. Training completion certificates are good evidence — for a different family. A training record cannot show that screening preceded access, and it cannot show that an account was disabled after a termination.
The most common CMMC personnel security failures
Answer capsule: Personnel security failures cluster where HR and access administration disconnect: CUI access granted before screening completes, a transfer that leaves obsolete privileges in place, a personnel action that never reaches IT, physical access or authenticators overlooked, or evidence that can't prove the sequence. Policies also create risk when they promise timelines the organization doesn't consistently meet.
| Failure | What the assessor sees | The fix |
|---|---|---|
| Access granted before screening completed | Screening date after the access-authorization date | Add a hard access-approval gate tied to screening status |
| “We run background checks” with no records | No completion record, no sample | Preserve lawful completion evidence separately from source reports |
| Termination-only checklist | No transfer workflow, no transfer samples | Build a separate transfer access review — objective [c] is tested independently |
| HR notice never reaches IT | An active account belonging to a former employee | One authoritative, tracked trigger with a unique event ID |
| Accounts closed, badge still active | Incomplete personnel-action evidence | Put facilities in the workflow |
| Laptop recovered, VPN token still valid | Partial credential revocation | Maintain a complete access and authenticator inventory per person |
| Contractor end date not tracked | Third-party access persists after the assignment | Track assignment expiration; name an internal sponsor for every external account |
| Shared password never rotated | A former worker retains practical access | Eliminate shared credentials, or rotate them on every departure with exposure |
| Policy says two hours, records show four days | Your own document contradicts your evidence | Engineer the workflow to meet a defensible standard — don't just lower the number |
| Draft policy presented at assessment | Evidence isn't in final form (§170.24(b)(1)) | Approve it, date it, publish it |
| Training records offered as PS evidence | Adjacent-family evidence, wrong objective | Map every artifact to a specific objective letter |
| Full background reports in an open evidence folder | A privacy and access-control problem you created | Separate completion proof from restricted source material |
Why this question is so confusing in the first place
The confusion centers on two questions about 3.9.1: how deep the background check has to be, and whether a new hire can start on day one. Both attract confident, conflicting advice — five-year lookbacks, seven-year lookbacks, credit checks, citizenship rules — none of which appears in the controlling text.
That's not the practitioners' fault. When the authoritative source says "organization-defined," people fill the vacuum with whatever the last consultant told them. We'd rather give you the vacuum, accurately, plus a defensible way to fill it yourself.
(A note on method: we use practitioner discussion to understand where confusion lives. We never use it as authority for what a regulation requires. Every requirement claim on this page cites the rule, the standard, or the official assessment guidance.)
✅ Not sure whether your remaining gap is a policy problem or a provider problem?
Personnel security is primarily a policy, workflow, and evidence problem. The other 108 requirements are a different conversation — and the right kind of help depends on whether your gap is documentation, managed IT, evidence workflow, enclave scope, or assessment readiness.
The CMMC Path Framework maps your required level, FCI versus CUI handling, assessment type, cloud and IT environment, and contract timeline to the provider category that fits. It routes to a category, never to a named provider. It is not a score, a ranking, or compliance advice.
Compare provider categories with Find My CMMC Path →
⚠️ Do not submit CUI, drawings, export-controlled technical data, credentials, or sensitive contract details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
What did the July 2026 suspension change for personnel security?
Answer capsule: The July 13, 2026 suspension of CMMC Phase II changed the implementation schedule, not the requirement text. PS.L2-3.9.1 and PS.L2-3.9.2 are unchanged, NIST SP 800-171 Revision 2 remains the incorporated Level 2 baseline, Level 1 and Level 2 self-assessments remain in force, and DFARS 252.204-7012 safeguarding obligations were not eliminated.
The original schedule placed Phase I from November 10, 2025 through November 9, 2026, with Phase II set to begin November 10, 2026. The July 13 suspension stopped that transition; Phase I continues pending further official action.
Short version: nothing about these two controls changed. But one thing about your exposure did.
Where a contract requires Level 2 (Self) during Phase I, the determination that PS.L2-3.9.1 and PS.L2-3.9.2 are MET is made by your own company, submitted to the Supplier Performance Risk System (SPRS), and affirmed by your affirming official.
There is no C3PAO in that Level 2 (Self) loop to catch a mistake before it becomes a submitted score.
That's the honest urgency on this page, and it's the only one we'll offer. Not a countdown. Not a deadline. Just the observation that a self-declared score carries the weight of an affirmation, and that eight of the points behind it depend on whether HR told IT that somebody quit.
| Item | Status verified August 20, 2026 |
|---|---|
| Phase I Level 1 and Level 2 self-assessment requirements | Remain in force |
| Original Phase I schedule | November 10, 2025 through November 9, 2026 |
| Phase II requirements originally scheduled for November 10, 2026 | Suspended July 13, 2026 |
| Replacement Phase II date | None published as of this review |
| NIST version incorporated for CMMC Level 2 | Revision 2 |
| PS.L2-3.9.1 and PS.L2-3.9.2 text | Unchanged |
| DFARS 252.204-7012 safeguarding obligation | Not eliminated by the suspension |
For the full picture, including what a prime can still require of you regardless of what the Department paused, see our phase status coverage.
What goes into SPRS for CMMC personnel security?
Answer capsule: SPRS receives a CMMC status and assessment data — not your employees' background reports. For a Level 2 self-assessment, your organization submits the CMMC level, status date, scope, associated CAGE codes, overall score, and POA&M status. For a Level 2 certification assessment, the C3PAO submits the detailed assessment result and artifact-name/hash data through the CMMC instance of eMASS, which transmits the result to SPRS. Your affirming official still submits the required affirmation.
That distinction matters because four different records can be confused:
| Record | Who submits it | Route | What it contains |
|---|---|---|---|
| CMMC Level 2 (Self) | The OSA | Directly to SPRS | Level, status date, scope, CAGE codes, overall score, and POA&M status |
| CMMC Level 2 (C3PAO) | The C3PAO | CMMC eMASS → automated transmission to SPRS | Assessment date and level, C3PAO and assessor information, CAGE codes, SSP name/date/version, result for each objective, POA&M status, and artifact names plus hash values |
| NIST SP 800-171 DoD Basic Assessment under an instrument using codified DFARS 252.204-7019/-7020 | The contractor | SPRS under the NIST SP 800-171 DoD Assessment Methodology | A separate low-confidence, summary-level score record used by those clauses |
| Medium/High NIST SP 800-171 DoD Assessment under class-deviation clause 252.240-7997 | DoD | DoD posts the summary-level result to SPRS | A separate Government assessment record with the standard, assessing organization, CAGE codes, date and level, score, and expected implementation date |
Do not upload employee names, Social Security numbers, dates of birth, background reports, or personnel files as the CMMC self-assessment result. Keep the lawful evidence in your restricted evidence repository for the applicable retention period. SPRS is where the status and specified assessment fields go.
Current clause-number caveat — verified August 20, 2026. DFARS 252.204-7019 and -7020 remain in the codified DFARS and may appear in your paperwork. Class Deviation 2026-O0025, effective February 1, 2026, directs contracting officers to use new DFARS Part 240 and prescribes 252.240-7997 for NIST SP 800-171 DoD Assessment requirements. The deviation clause addresses Government Medium and High assessments and their SPRS records; it does not define the contractor Basic Assessment found in codified 252.204-7020. Read the clause package in your actual solicitation, contract, task order, delivery order, or modification rather than assuming the older or newer number applies.
The clause stack also matters. DFARS 252.204-7012 carries safeguarding and cyber-incident obligations. In instruments using the codified 252.204-7019/-7020 package, -7019 requires a current NIST SP 800-171 DoD Assessment score in SPRS for covered systems relevant to an offer, and -7020 governs the Basic/Medium/High assessment framework and resulting SPRS records. Under Class Deviation 2026-O0025, 252.240-7997 carries the Government Medium/High assessment function. DFARS 252.204-7021 carries the contract's required CMMC status and annual affirmation obligations. Those records are related, but they are not interchangeable.
What we actually verified
We think a page making this many specific claims owes you an accounting of where they came from. Here's what our editorial team checked, and when.
On August 20, 2026, we:
- Read 32 CFR §170.24 in full at the eCFR, which displayed Title 32 as current through August 18, 2026, and confirmed PS.L2-3.9.2 in the five-point basic list and PS.L2-3.9.1 in the three-point basic list.
- Confirmed at §170.24(c)(2)(i)(B)(4) that partial credit exists only for multi-factor authentication and FIPS-validated encryption — neither of which is in this family.
- Confirmed the POA&M restriction at §170.21(a)(2)(ii) and the narrow encryption exception.
- Read all 24 rows of Table 1 to §170.14(c)(4) and confirmed PS.L3-3.9.2e is present with no DoD-assigned parameter, and that PS.L3-3.9.1e is absent.
- Read §3.9 of NIST SP 800-172 (February 2021) in the published PDF and confirmed the family contains exactly two enhanced requirements — 3.9.1e and 3.9.2e.
- Read §170.8(b)(4), §170.9(b)(3), §170.11(b)(3), and §170.13(b)(3) and confirmed the Tier 3 / SF-86 / "Moderate Risk" screening standard applies to the Accreditation Body, C3PAO personnel, CCAs, and CCPs.
- Confirmed at §170.14(c)(2) that CMMC Level 1 is the 15 requirements at 48 CFR 52.204-21(b)(1)(i)–(xv), and at §170.14(c)(3) that Level 2 is identical to NIST SP 800-171 Rev. 2.
- Confirmed the MET / NOT MET / Not Applicable definitions and the final-form evidence rule at §170.24(b).
- Confirmed at NIST's CSRC that SP 800-172 Revision 3 was published as final on May 13, 2026, and that CMMC still incorporates the February 2021 version.
- Confirmed the insider threat program obligation at 32 CFR §117.7(b)(4) applies through the NISPOM to cleared contractors.
- Read 32 CFR §§170.16 and 170.17 and confirmed the separate SPRS/eMASS submission paths and the six-year evidence-retention obligations for Level 2 self-assessments and certification assessments.
- Confirmed that §§170.16(c)(1) and 170.17(c)(1) still incorporate NIST SP 800-171A June 2018 even though NIST withdrew that publication on May 14, 2024 and superseded it with Revision 3.
- Read DFARS 252.204-7012, -7019, -7020, and -7021 at Acquisition.gov and separated their safeguarding, NIST SP 800-171 DoD Assessment, SPRS, CMMC-status, flowdown, and affirmation functions. We also read Class Deviation 2026-O0025, effective February 1, 2026, and confirmed that new DFARS Part 240 prescribes 252.240-7997 for Government Medium/High NIST SP 800-171 DoD Assessments.
- Read the Cyber AB CMMC Assessment Process (CAP) v2.0 (December 2024) and confirmed that it governs Level 2 certification-assessment procedure, does not replace Part 170 or incorporated standards, and bars a C3PAO from promising or guaranteeing an assessment result.
- Confirmed the Cyber AB Marketplace is the public listing to check whether a C3PAO is shown as authorized or accredited before a Level 2 certification engagement.
- Confirmed the Department of War CIO's July 13, 2026 Phase II suspension notice and that Phase I self-assessment requirements remain in place.
The official assessment guide: we read the DoD CIO's CMMC Assessment Guide – Level 2 (v2.13, September 2024) directly and confirmed the four assessment objectives, the organization-defined screening language, the criminal-and-credit-check example, and the termination/transfer assessment considerations.
What we did not do: we did not assign a total count to NIST SP 800-172's enhanced requirements, because the number isn't needed to make any claim on this page. We did not quote practitioner forums as authority for any requirement.
No named reviewer is listed on this article. We don't attach a reviewer credit unless a real subject matter advisor from our published advisor list actually reviewed the piece.
What to do this week
Answer capsule: Assign one accountable owner for the personnel security family, then compare your most recent hire, transfer, and departure against the four assessment objectives. Fix any case where access preceded screening, where a personnel action failed to reach an access owner, where obsolete access remained after a transfer, or where the records can't establish the sequence.
This family is workflow-heavy rather than tool-heavy. Here's the order we'd run it in.
- Confirm your level. If your solicitation, contract, or flow-down puts you on a Level 2 path, personnel security applies. Use our CMMC Levels guide if the required status or assessment type is still unclear. If you're FCI-only at Level 1, stop here — go to the Level 1 checklist instead.
- List every role authorized into CUI systems. Include privileged accounts, contractors, and any external service provider staff.
- Write the one-page screening standard. Roles, screening components, reviewer, access-permitting status, exception path. Get employment counsel to look at it.
- Pull three recent records and compare the screening completion date against the access authorization date. If access came first, you have a finding waiting to happen.
- Test your most recent departure. Was every account disabled? Every credential revoked? The badge? The VPN token? The shared password?
- Test your most recent transfer. If you can't find one, that's your answer about objective [c].
- Reconcile HR records against active accounts — including cloud applications and physical access. This is often the fastest way to expose accounts and access that no longer have a valid personnel owner.
- Approve the documents. Draft policies score zero.
- Assemble a restricted evidence packet and confirm your retention approach against the six-year obligation.
- Name the accountable owner and put the reconciliation on a recurring calendar. (Frequency is your call — no CMMC rule sets one. We suggest quarterly as a readiness practice, clearly labeled as our recommendation.)
Frequently asked questions
How many CMMC personnel security requirements are there? Two at Level 2 — PS.L2-3.9.1 and PS.L2-3.9.2 — containing four assessment objectives between them. Level 3 adds one more, PS.L3-3.9.2e, on top of the full Level 2 baseline. (32 CFR §170.14; NIST SP 800-171A)
Does CMMC Level 1 include personnel security? No. Level 1 is the 15 requirements from FAR 52.204-21, spread across six domains, and personnel security isn't one of them. (32 CFR §170.14(c)(2))
Does CMMC require a criminal background check? It requires screening before authorized CUI-system access. Criminal and credit checks appear in the official assessment guidance as an example, following language that describes the screening as organization-defined based on position and role. A criminal check may be a reasonable component for a particular role. It is not a federal mandate.
How many years back does a CMMC background check have to go? No lookback period is specified anywhere in CMMC Level 2 personnel security. A commercial vendor may offer five-year or seven-year products, but those are not CMMC lookback requirements. Don't let a practitioner preference become a compliance claim in your SSP.
Does a security clearance satisfy PS.L2-3.9.1? Possibly, as evidence — but there's no universal automatic-satisfaction rule in the controlling text. Document what screening occurred, when it completed relative to CUI access, and why it satisfies your written procedure. Check whether the contract imposes its own clearance conditions separately.
Can someone access CUI while their clearance or background check is pending? The control requires the applicable screening to be complete before access is authorized. A person can perform work that does not require authorized access to a system containing CUI while the applicable screening is pending.
Does CMMC require U.S. citizenship for CUI access? Not through PS.L2-3.9.1. Export control rules, specific CUI categories, program requirements, and contract terms can impose citizenship or U.S.-person conditions. Those are separate authorities and you should read the actual clause.
Does CMMC require drug testing or credit checks? Neither is a Level 2 personnel security requirement. Credit checks appear in the official example; drug testing doesn't appear in the requirement or its objectives at all.
Does CMMC require annual employee re-screening? No. Re-screening is not a Level 2 requirement, and NIST's enhanced re-screening requirement (3.9.1e) was not selected for CMMC Level 3. You may choose a re-screening cadence — just don't describe it as a CMMC obligation.
Do contractors and temporary workers need to be screened? Our reading, stated as our reading: if they're authorized into a system that holds CUI, apply the same gate. The requirement text says "individuals" while the official further discussion says "employees," so document your approach and who's responsible for performing and evidencing the screening.
How does a one-person company screen its owner? The source documents don't provide an owner-specific procedure. Define an objective process, consider independent completion or third-party validation, document it, and confirm your approach with an RP/RPO or qualified counsel before relying on it.
How quickly must access be disabled after a termination? There's no universal CMMC deadline. The guidance emphasizes timely execution, especially for a for-cause termination, and notes that organizations sometimes disable access before notification. Define a risk-based timeline you can consistently meet, then meet it.
Are transfers really assessed, or just terminations? Really assessed. Objective [c] under PS.L2-3.9.2 tests protection during and after transfer actions independently. A termination-only process leaves a five-point requirement exposed.
What evidence does an assessor expect? Approved policies and procedures, screening completion records, personnel action records, system account lists, records of revoked credentials and authenticators, SSP content, and exit interview records where they exist. Assessors may also interview responsible personnel and test the mechanisms. (NIST SP 800-171A)
How long must CMMC assessment evidence be retained? Six years from the CMMC Status Date. Under §170.16, a Level 2 self-assessing organization retains the supporting artifacts. Under §170.17, a Level 2 certification organization retains the artifacts whose names and hash values were submitted through eMASS.
How many points are the personnel security requirements worth? Three for PS.L2-3.9.1 and five for PS.L2-3.9.2 — eight total. (32 CFR §170.24)
Can either personnel security requirement go on a POA&M? No. Both exceed one point, and 32 CFR §170.21(a)(2)(ii) excludes anything above one point from a Level 2 POA&M, apart from a narrow FIPS-validated encryption exception that doesn't apply here.
Does security awareness training satisfy personnel security? No. Training belongs to the Awareness and Training family. It cannot demonstrate that screening preceded access or that access ended after a departure.
Does CMMC require an insider threat program? Not through the personnel security family. Insider threat program obligations come from the NISPOM at 32 CFR §117.7(b)(4) and apply to cleared contractors under the National Industrial Security Program.
Did the July 2026 Phase II suspension eliminate these requirements? No. It changed the implementation schedule. Level 1 and Level 2 self-assessments remain in force, the Revision 2 baseline is unchanged, and DFARS 252.204-7012 safeguarding obligations were not eliminated.
Do I upload background reports to SPRS? No. A Level 2 self-assessment submission includes specified status, scope, CAGE-code, score, and POA&M fields. Certification results travel from the C3PAO through CMMC eMASS to SPRS and include artifact names and hash values, not the underlying employee background reports. Keep personnel evidence in a restricted repository.
The bottom line
CMMC personnel security is two requirements, four objectives, and eight points that you cannot defer. It is one of the least tool-dependent families in the standard and still easy to fail, because the work isn't technical — it's a records handoff between departments that don't normally talk about assessments.
Part 170 writes a precise screening standard for the assessment ecosystem while leaving your CMMC workforce screening organization-defined. Take the freedom seriously: write the standard down, apply it before access, prove the sequence, and set an offboarding clock you can actually hit.
If we removed every link on this page, we'd still want it to be the clearest thing written on this topic. That was the goal.
This page is educational research, not legal, contractual, employment, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or Registered Provider Organization (RPO) and, where screening is involved, a qualified employment attorney. The solicitation, resulting contract or flow-down language, and your actual FCI/CUI handling set your required path — not a website checklist.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Already know the category you need? Request source-checked provider options →
⚠️ Do not submit CUI, drawings, export-controlled technical data, account credentials, background reports, or sensitive contract details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
Sources and further reading
- 32 CFR Part 170 — CMMC Program (eCFR)
- 32 CFR §170.14 — CMMC Model, including Table 1 of Level 3 requirements
- 32 CFR §170.21 — POA&M requirements
- 32 CFR §170.24 — CMMC Scoring Methodology
- 32 CFR §170.8 — Accreditation Body
- 32 CFR §170.9 — CMMC Third-Party Assessment Organizations
- 32 CFR §170.11 — CMMC Certified Assessor
- 32 CFR §170.13 — CMMC Certified Professional
- 32 CFR §170.16 — Level 2 self-assessment and affirmation
- 32 CFR §170.17 — Level 2 certification assessment and affirmation
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
- Class Deviation 2026-O0025 — DFARS Part 240 and 252.240-7997
- DFARS 252.204-7021 — Contractor Compliance With CMMC Level Requirements
- NIST SP 800-171 Revision 2
- NIST SP 800-171A (June 2018; incorporated by CMMC Level 2)
- NIST SP 800-172 (February 2021)
- CMMC Assessment Guide – Level 2 (DoD CIO)
- CMMC Assessment Process (CAP) v2.0 (Cyber AB)
- Cyber AB Marketplace
- EEOC and FTC — Background Checks: What Employers Need to Know
Corrections? We publish them. See our corrections policy and editorial standards.