1Overview
PS.L2-3.9.1 opens the Personnel Security family with the requirement to vet people before granting access. It requires that individuals be screened prior to authorizing access to organizational systems containing CUI, so that access is extended only to people who have been checked against the organization's criteria. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.
Every technical control assumes that the people granted access can be trusted with it, and screening is what establishes that trust before access is given. This control requires that individuals be screened before they are authorized to reach systems containing CUI, so that the decision to grant access follows a check rather than precedes one. The screening criteria are set by the organization and may reflect the sensitivity of the role and any contractual requirements, but the timing is fixed: the screening comes before the access, not after. Its three-point weight reflects that unscreened access places trust in people who have not been checked.
Screen individuals prior to authorizing access to organizational systems containing CUI.
The requirement fixes both the action and its timing: individuals are screened, and the screening happens before access is authorized. Screening is the check the organization performs against its own criteria, which can range from identity verification to background checks appropriate to the role. The point that the assessment turns on is the sequence, that access to systems containing CUI is granted only after the screening, so no one reaches CUI before being checked.
2The Assessment Objective
NIST SP 800-171A frames 3.9.1 as a single objective: screen individuals before authorizing CUI system access.
Individuals are screened prior to authorizing access to organizational systems containing CUI. Screening precedes access.
The single objective couples screening with timing: it is done, and it is done first. The common failure is access granted on hire or role change with the screening lagging behind or skipped. The assessor looks for evidence that screening precedes the authorization of access to CUI systems.
3Failure Patterns
The failures are about access that runs ahead of screening.
Access granted before screening
Where access to CUI systems is set up on a start date while screening is still pending, the person reaches CUI before being checked. Sequencing the screening before the access closes this.
Screening skipped for some roles
Screening applied to some people but not others leaves unscreened access for those who were missed. The screening has to precede access for everyone authorized to CUI systems.
No defined screening criteria
Without criteria for what screening involves, the check is inconsistent or nominal. Defined criteria make the screening meaningful and repeatable.
4Ownership
This is an HR and security-owned control, with IT enforcing the access timing.
| Role | Responsibility for this control |
|---|---|
| Human resources | Performs the screening against the organization's criteria before access is authorized. Owns the screening records. |
| Security or compliance lead | Defines the screening criteria and confirms screening precedes CUI access. |
| IT and system administrator | Grants access to CUI systems only after screening is confirmed. |
5Tooling
The control is largely procedural, delivered by a screening process tied to the access-granting workflow.
| Objective | Tooling | What it provides |
|---|---|---|
| screen | Screening process and criteria | A defined check against the organization's criteria. |
| sequence | Onboarding and access workflow | Access authorized only after screening is confirmed. |
The caveat is that the control turns on sequence as much as substance. A screening process that exists but does not gate access lets people through before the check completes. The assessor examines whether screening precedes access, so the onboarding workflow has to make screening a prerequisite for authorization rather than a parallel task.
6Evidence
The satisfied version of 3.9.1 shows screening completed before access is granted.
| Evidence | What it demonstrates |
|---|---|
| Screening records | The objective. Individuals are screened against the criteria. |
| Onboarding and access workflow | The objective. Screening precedes authorization of access. |
| Screening criteria | The objective. What the screening involves. |
The evidence should show individuals screened against defined criteria before access to CUI systems is authorized. The screening records tied to an onboarding workflow that gates access are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
The check comes before the keys
Every access grant places trust in a person, and this three-point control requires that the trust be checked through screening before the access is given, not after. Building screening into onboarding so it gates access to CUI systems is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.9.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.9.1. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing PS.L2-3.9.1 among the three-point basic security requirements. ecfr.gov