Uniqcli

CMMC control families

CMMC Personnel Security (3.9 PS): 2 requirements, and what happens to the laptop

The smallest family in the standard: screen people before access, and protect CUI when they leave or move. This is the one family where the honest answer is still that there is nothing to quote — screening is not a product. The only thread with a product edge is the encrypted device that has to come back.

Family
3.9 — Personnel Security
Requirements
2 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

Two requirements, both about people rather than equipment

Personnel security is the smallest family in NIST SP 800-171: 3.9.1 requires individuals to be screened before authorizing access to systems containing CUI, and 3.9.2 requires CUI and the systems holding it to be protected during and after personnel actions such as terminations and transfers. That is the whole family. It is HR policy, an access-provisioning workflow and an offboarding checklist, evidenced by records — not something a supplier contributes to.

Levels

What each level asks of this family

Screening is not a Level 1 question. Personnel security sits outside the six families the 15 FAR 52.204-21 requirements touch, so a Level 1 self-assessment never scores 3.9.1 or 3.9.2 — which makes them unscored at that level, not optional.

At Level 2 both apply. Neither prescribes a specific check — 3.9.1 says screen, and leaves the depth and the criteria to your program to define against the risk and against whatever the contract separately requires. 3.9.2 is the one that gets failed in practice, because access removal and asset recovery on the day someone leaves is an operational habit rather than a policy, and assessors ask to see the record for a named departure rather than the policy document.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

Limits

The one family where the answer really is nothing

Across the rest of this standard there is almost always something quotable behind the control — a license, an appliance, integration work. Here there is not, and pretending otherwise would cost us the credibility of every other page. Screening is a background-check process; access removal is an identity workflow; the record that proves both happened is yours. Any supplier pointing a product at 3.9 has relabeled something from another family — a badge reader belongs to physical protection, an authenticator to identification and authentication, and neither of those is what these two requirements are about.

The one thread with a product edge is the tail of 3.9.2. Personnel actions usually mean a device comes back, and if that device holds CUI then what happens to it next is media protection's problem: 3.8.3 on sanitizing or destroying media before reuse, and the encrypted-media question underneath it. Where a departure is part of a wider refresh, the asset recovery and disposition side of that is work our logistics lane already does. That is a real conversation and a real quote — it just belongs one family over.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Personnel security questions

Does CMMC require background checks?

3.9.1 requires individuals to be screened prior to authorizing access to systems containing CUI. It does not prescribe a particular check, a provider or a depth — that is yours to define, document and apply consistently, and to reconcile with anything the contract separately requires. The evidence an assessor wants is that screening happened before access, for the people who have it.

What are the two personnel security requirements in NIST 800-171?

3.9.1, screen individuals prior to authorizing access to systems containing CUI; and 3.9.2, ensure that CUI and the systems containing it are protected during and after personnel actions such as terminations and transfers. Two of the 110 requirements a Level 2 assessment covers — the smallest family in the standard.

What has to happen to a laptop when an employee leaves?

3.9.2 asks you to protect CUI and the systems containing it during and after the personnel action, so recovery of the device and removal of access are both in scope. What happens to the storage afterwards is governed by media protection — 3.8.3 requires media containing CUI to be sanitized or destroyed before disposal or release for reuse. Reissuing the machine to the next hire without addressing that is a common finding.

Is personnel security assessed at CMMC Level 1?

No. Personnel security is one of the eight Level 2-only families; Level 1's 15 requirements from FAR 52.204-21 touch six others. Contractors handling CUI carry 3.9 through DFARS 252.204-7012 regardless of the level a solicitation names.

Get a CMMC estimate — CMMC Personnel Security (3.9 PS)

Nothing in this family is a purchase, and the page above says so. Tell us where to reach you and a Uniqcli specialist follows up by email about the parts of your program that do have a line behind them — the hardware, software licensing and integration work the rest of your SSP calls for, quoted against the plan you already have.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Personnel Security (3.9 PS)

The device that comes back

Screening and offboarding are HR and IT process, and we sell nothing against either. The one place a purchase order appears is the machine a departure returns — sanitizing or replacing its storage under media protection's 3.8.3, and the asset recovery around it. Send the fleet size or the SSP section and a Uniqcli specialist replies with an estimate.