DKDavid Koran& Associates
Home The CMMC Guide Part III · Personnel Security PS.L2-3.9.1
The CMMC Guide · Personnel Security Family

PS.L2-3.9.1  Screen Personnel

Screen individuals prior to authorizing access to organizational systems containing CUI.

Family
Personnel SecurityPS, 2 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

PS.L2-3.9.1 opens the Personnel Security family with the requirement to vet people before granting access. It requires that individuals be screened prior to authorizing access to organizational systems containing CUI, so that access is extended only to people who have been checked against the organization's criteria. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.

Every technical control assumes that the people granted access can be trusted with it, and screening is what establishes that trust before access is given. This control requires that individuals be screened before they are authorized to reach systems containing CUI, so that the decision to grant access follows a check rather than precedes one. The screening criteria are set by the organization and may reflect the sensitivity of the role and any contractual requirements, but the timing is fixed: the screening comes before the access, not after. Its three-point weight reflects that unscreened access places trust in people who have not been checked.

The requirement · NIST SP 800-171 Rev 2, 3.9.1

Screen individuals prior to authorizing access to organizational systems containing CUI.

The requirement fixes both the action and its timing: individuals are screened, and the screening happens before access is authorized. Screening is the check the organization performs against its own criteria, which can range from identity verification to background checks appropriate to the role. The point that the assessment turns on is the sequence, that access to systems containing CUI is granted only after the screening, so no one reaches CUI before being checked.

2The Assessment Objective

NIST SP 800-171A frames 3.9.1 as a single objective: screen individuals before authorizing CUI system access.

Individuals are screened prior to authorizing access to organizational systems containing CUI. Screening precedes access.

MeetsIndividuals are screened against the organization's criteria before they are authorized to access systems containing CUI.
FailsAccess to CUI systems is granted before, or without, screening.

The single objective couples screening with timing: it is done, and it is done first. The common failure is access granted on hire or role change with the screening lagging behind or skipped. The assessor looks for evidence that screening precedes the authorization of access to CUI systems.

3Failure Patterns

The failures are about access that runs ahead of screening.

Access granted before screening

Where access to CUI systems is set up on a start date while screening is still pending, the person reaches CUI before being checked. Sequencing the screening before the access closes this.

Screening skipped for some roles

Screening applied to some people but not others leaves unscreened access for those who were missed. The screening has to precede access for everyone authorized to CUI systems.

No defined screening criteria

Without criteria for what screening involves, the check is inconsistent or nominal. Defined criteria make the screening meaningful and repeatable.

The common root
This control fails to the pressure to grant access quickly. A new hire or a role change creates immediate need for system access, and screening is easy to treat as a formality that can catch up later, but access granted before the check places CUI in unscreened hands. The control exists to keep the order right.

4Ownership

This is an HR and security-owned control, with IT enforcing the access timing.

RoleResponsibility for this control
Human resourcesPerforms the screening against the organization's criteria before access is authorized. Owns the screening records.
Security or compliance leadDefines the screening criteria and confirms screening precedes CUI access.
IT and system administratorGrants access to CUI systems only after screening is confirmed.
See also: This control pairs with PS.L2-3.9.2, which protects systems when personnel leave or transfer, and connects to the account authorization of the access control family.

5Tooling

The control is largely procedural, delivered by a screening process tied to the access-granting workflow.

ObjectiveToolingWhat it provides
screenScreening process and criteriaA defined check against the organization's criteria.
sequenceOnboarding and access workflowAccess authorized only after screening is confirmed.

The caveat is that the control turns on sequence as much as substance. A screening process that exists but does not gate access lets people through before the check completes. The assessor examines whether screening precedes access, so the onboarding workflow has to make screening a prerequisite for authorization rather than a parallel task.

6Evidence

The satisfied version of 3.9.1 shows screening completed before access is granted.

EvidenceWhat it demonstrates
Screening recordsThe objective. Individuals are screened against the criteria.
Onboarding and access workflowThe objective. Screening precedes authorization of access.
Screening criteriaThe objective. What the screening involves.

The evidence should show individuals screened against defined criteria before access to CUI systems is authorized. The screening records tied to an onboarding workflow that gates access are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

The check comes before the keys

Every access grant places trust in a person, and this three-point control requires that the trust be checked through screening before the access is given, not after. Building screening into onboarding so it gates access to CUI systems is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.9.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.9.1. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing PS.L2-3.9.1 among the three-point basic security requirements. ecfr.gov
← Previous: Media Protection
MP.L2-3.8.9 · Protect Backup CUI
Next in Personnel Security →
PS.L2-3.9.2 · Protect CUI During Personnel Actions
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PS.L2-3.9.1 · Edition 2026.1 · Last reviewed July 12, 2026