Personnel security is small in control count but high in operational consequence: 3.9.1 addresses screening before access, while 3.9.2 requires protection of CUI systems during and after personnel actions.
The working question for a small business under CMMC is concrete: within the defined FCI/CUI boundary, who is responsible for this requirement, and what evidence today shows it is functioning as intended?
The rule in plain English
Screening should occur before authorization consistent with the organization's risk and obligations. Termination and transfer controls should prevent a former or changed-role user from retaining access that is no longer justified.
Rev. 2 does not prescribe one universal commercial background-check product. The organization should define the screening it relies on and consistently apply it to the people who receive access.
How to implement it without overbuilding
Connect HR events to identity and physical-access actions. A termination workflow should cover user and privileged accounts, VPN, SaaS, badges, keys, tokens, company devices, and shared secrets.
Transfers matter too. Moving from engineering to sales can require removal of repository, file-share, VPN, or administrative access even when employment continues.
What evidence to keep
Keep screening completion, access approvals, termination/transfer tickets, account-disable timestamps, badge/key return, device return, and exception approvals.
Sample one recent separation and prove the actual access list was checked rather than relying on memory.
Where teams get into trouble
HR and IT often maintain separate checklists that never reconcile. Another failure is disabling the main directory account while VPN, local accounts, applications, badges, or shared credentials remain active.
Small-contractor walkthrough
An engineer transfers to business development but remains employed. The personnel-security trigger should remove engineering repository, VPN, and privileged tool access that the new role no longer needs instead of waiting for a later annual review.
- Define pre-access screening.
- Create one personnel-action trigger.
- Inventory identity and physical access.
- Record revocation timestamps.
Decisions to document before assessment
Before marking this topic ready, make four decisions explicit: define pre-access screening; create one personnel-action trigger; inventory identity and physical access; and record revocation timestamps. Assign an owner and an evidence location to each decision.
Manual deep review: prove screening timing and personnel-action timing
3.9.1 requires individuals to be screened before they are authorized to access systems containing CUI. The organization should define what screening applies to each position or access level, considering applicable law, contract requirements, and role risk. The CMMC requirement itself does not prescribe one commercial background-check package for every contractor. The strongest implementation is a gating workflow where the required screening status is recorded before IT or a system owner can authorize CUI-system access.
For 3.9.2, termination and transfer should use the same personnel-action trigger but lead to different access decisions. A termination usually disables or revokes directory, application, VPN, privileged, token, badge, key, device, and other access. A transfer keeps the person employed but removes access no longer justified by the new role. Transfers are a common source of stale engineering repository, lab, VPN, and administrative permissions.
Create one workflow that reaches HR, IT, facilities, system owners, and the MSP if those parties control access. Avoid separate spreadsheets that depend on somebody remembering who must be notified. Include standalone SaaS accounts, firewalls, vendor portals, Git repositories, local application accounts, and physical credentials where relevant; disabling the central identity alone may not remove them.
Before assessment, choose one current employee and compare the screening date with the first CUI-access authorization. Then choose one termination and one transfer and trace the personnel action through technical and physical access records. The evidence should demonstrate when the action happened, not merely that the policy says access is removed promptly.
- Screening criteria and completion evidence.
- Access authorization date.
- Termination/transfer trigger record.
- Technical deprovisioning evidence.
- Physical access/device return evidence.
Manual assessment cross-check
Compare one employee's screening date to first CUI access and one personnel-action timestamp to the actual technical and physical access changes.
Use CMMC Personnel Security: Screening, Termination, and Transfer Actions (3.9.x) as an operating guide, not as a substitute for the controlling source. Before publication or assessment use, re-open the current NIST SP 800-171 Rev. 2 requirement, the corresponding NIST SP 800-171A assessment objectives, and the DoD CMMC Level 2 Assessment Guide. Confirm that every mandatory statement on the page maps to those sources or to a clearly labeled organizational implementation choice.
Additional objective-level implementation notes
Minimize sensitive HR data in the evidence package. The assessor needs proof that required screening occurred before CUI-system authorization, not every underlying record collected by a screening provider. A dated screening-status record, access approval, and controlled HR process can prove sequence while reducing unnecessary exposure of personal information.
For terminations and transfers, build the action list from the real access inventory. Check local administrator accounts, SaaS applications, VPN certificates, badges, shared secrets, third-party portals, and provider-managed accounts in addition to the main directory. The key question is whether the person's effective access changed with the personnel action, not whether one central account was disabled.
Final manual spot check
For a final spot check, compare one routine hire, one transfer, and one departure. The hire should show screening before authorization; the transfer should show permissions reduced or changed with the new duties; the departure should show technical and physical access removed according to the personnel action. If an MSP controls any account or remote-access component, include the provider ticket or export so the company can prove the action without relying on verbal confirmation.
One more edge case to verify
Include any provider-managed identity or physical-access dependency in the personnel-action record so the company can prove completion across organizational boundaries.
A short working check
- ✓Define pre-access screening.
- ✓Create one personnel-action trigger.
- ✓Inventory identity and physical access.
- ✓Record revocation timestamps.
- ✓Rotate shared secrets when needed.
- ✓Test a recent separation case.
Common questions
Does CMMC require a specific background check?
Rev. 2 requires screening before authorizing access but does not name one universal commercial check for all contractors.
Do transfers count?
Yes. Access should be reviewed when duties change so users retain only what the new role requires.
Is disabling Microsoft 365 enough?
Only if that actually removes every relevant access path.
What is good evidence?
A completed personnel-action record tied to dated technical and physical revocation evidence.
Do transfers count even when the person stays employed?
Yes. 3.9.2 includes transfer actions, so access should be adjusted to the new role rather than waiting for termination.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.




