CMMC control families
CMMC Personnel Security (3.9 PS): 2 requirements, and what happens to the laptop
The smallest family in the standard: screen people before access, and protect CUI when they leave or move. This is the one family where the honest answer is still that there is nothing to quote — screening is not a product. The only thread with a product edge is the encrypted device that has to come back.
- Family
- 3.9 — Personnel Security
- Requirements
- 2 of the 110 Level 2 requirements
- Level 1
- Not in Level 1 — appears at Level 2
- Boundary
- The capability behind the control — never a certification we hold
Two requirements, both about people rather than equipment
Personnel security is the smallest family in NIST SP 800-171: 3.9.1 requires individuals to be screened before authorizing access to systems containing CUI, and 3.9.2 requires CUI and the systems holding it to be protected during and after personnel actions such as terminations and transfers. That is the whole family. It is HR policy, an access-provisioning workflow and an offboarding checklist, evidenced by records — not something a supplier contributes to.
What each level asks of this family
Screening is not a Level 1 question. Personnel security sits outside the six families the 15 FAR 52.204-21 requirements touch, so a Level 1 self-assessment never scores 3.9.1 or 3.9.2 — which makes them unscored at that level, not optional.
At Level 2 both apply. Neither prescribes a specific check — 3.9.1 says screen, and leaves the depth and the criteria to your program to define against the risk and against whatever the contract separately requires. 3.9.2 is the one that gets failed in practice, because access removal and asset recovery on the day someone leaves is an operational habit rather than a policy, and assessors ask to see the record for a named departure rather than the policy document.
Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.
The one family where the answer really is nothing
Across the rest of this standard there is almost always something quotable behind the control — a license, an appliance, integration work. Here there is not, and pretending otherwise would cost us the credibility of every other page. Screening is a background-check process; access removal is an identity workflow; the record that proves both happened is yours. Any supplier pointing a product at 3.9 has relabeled something from another family — a badge reader belongs to physical protection, an authenticator to identification and authentication, and neither of those is what these two requirements are about.
The one thread with a product edge is the tail of 3.9.2. Personnel actions usually mean a device comes back, and if that device holds CUI then what happens to it next is media protection's problem: 3.8.3 on sanitizing or destroying media before reuse, and the encrypted-media question underneath it. Where a departure is part of a wider refresh, the asset recovery and disposition side of that is work our logistics lane already does. That is a real conversation and a real quote — it just belongs one family over.
We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.
Personnel security questions
Does CMMC require background checks?
3.9.1 requires individuals to be screened prior to authorizing access to systems containing CUI. It does not prescribe a particular check, a provider or a depth — that is yours to define, document and apply consistently, and to reconcile with anything the contract separately requires. The evidence an assessor wants is that screening happened before access, for the people who have it.
What are the two personnel security requirements in NIST 800-171?
3.9.1, screen individuals prior to authorizing access to systems containing CUI; and 3.9.2, ensure that CUI and the systems containing it are protected during and after personnel actions such as terminations and transfers. Two of the 110 requirements a Level 2 assessment covers — the smallest family in the standard.
What has to happen to a laptop when an employee leaves?
3.9.2 asks you to protect CUI and the systems containing it during and after the personnel action, so recovery of the device and removal of access are both in scope. What happens to the storage afterwards is governed by media protection — 3.8.3 requires media containing CUI to be sanitized or destroyed before disposal or release for reuse. Reissuing the machine to the next hire without addressing that is a common finding.
Is personnel security assessed at CMMC Level 1?
No. Personnel security is one of the eight Level 2-only families; Level 1's 15 requirements from FAR 52.204-21 touch six others. Contractors handling CUI carry 3.9 through DFARS 252.204-7012 regardless of the level a solicitation names.
Related families and background
Get a CMMC estimate — CMMC Personnel Security (3.9 PS)
Nothing in this family is a purchase, and the page above says so. Tell us where to reach you and a Uniqcli specialist follows up by email about the parts of your program that do have a line behind them — the hardware, software licensing and integration work the rest of your SSP calls for, quoted against the plan you already have.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
The device that comes back
Screening and offboarding are HR and IT process, and we sell nothing against either. The one place a purchase order appears is the machine a departure returns — sanitizing or replacing its storage under media protection's 3.8.3, and the asset recovery around it. Send the fleet size or the SSP section and a Uniqcli specialist replies with an estimate.