DKDavid Koran& Associates
Home The CMMC Guide Part III · Personnel Security PS.L2-3.9.2
The CMMC Guide · Personnel Security Family

PS.L2-3.9.2  Protect CUI During Personnel Actions

Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Family
Personnel SecurityPS, 2 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
ThreePer NIST SP 800-171A

1Overview

PS.L2-3.9.2 is the family's five-point requirement and it governs what happens when people leave or move. It requires that systems containing CUI be protected during and after personnel actions such as terminations and transfers, so that access does not linger after the person's need for it ends. It is a five-point requirement with three assessment objectives, and it cannot be deferred on a plan of action.

Access granted to a person has to be removed when that person's relationship to the organization changes. A termination that leaves accounts and credentials active creates a departed insider who can still reach CUI; a transfer that carries old access into a new role accumulates permissions the person no longer needs. This control requires that the system be protected through these personnel actions, which means having a process to terminate access and credentials, actually terminating them in step with the action, and protecting the system across transfers. Its five-point weight reflects that lingering access after departure is one of the most exploited insider gaps.

The requirement · NIST SP 800-171 Rev 2, 3.9.2

Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

The requirement covers the whole arc of a personnel action. There has to be a policy or process for terminating access and credentials when personnel actions occur; that termination has to actually happen consistent with the action, whether a departure or a transfer; and the system has to be protected during and after transfers, when access needs change rather than end. The three assessment objectives correspond to the process, its execution, and protection through transfers.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.9.2 into three objectives: establish the process, terminate access consistent with the action, and protect the system through transfers.

[a]

A policy and/or process for terminating system access and any credentials coincident with personnel actions is established. There is a defined way to remove access when personnel actions occur.

MeetsA process exists to terminate access and credentials coincident with terminations and transfers.
FailsThere is no defined process for removing access when people leave or move.
[b]

System access and credentials are terminated consistent with personnel actions such as termination or transfer. Access is actually removed in step with the action.

MeetsAccess and credentials are terminated consistent with the personnel action, promptly and completely.
FailsAccounts and credentials remain active after the person departs or transfers.
[c]

The system is protected during and after personnel transfer actions. Transfers do not leave excess access.

MeetsOn transfer, access is adjusted to the new role, so old permissions do not carry over.
FailsTransferred personnel retain access from their previous role.

The three objectives are the process, its execution, and transfer protection. The common gap is at objective [b], where a process exists on paper but access is not actually terminated promptly, leaving active accounts for departed people. The assessor looks for all three: a process, its real execution, and protection through transfers.

3Failure Patterns

The failures are about access that outlives the person's need for it.

Accounts active after departure

A termination that does not remove access leaves a departed person able to reach CUI, one of the most exploited insider gaps. Terminating access consistent with the departure closes it.

Permissions accumulate on transfer

Transferring a person to a new role without removing old access lets permissions accumulate beyond need. Adjusting access on transfer protects the system through the change.

Process without prompt execution

A termination process that is slow or inconsistently applied leaves a window where departed access is still live. Access has to be terminated in step with the action, not eventually.

Credentials overlooked

Disabling an account while leaving other credentials, such as shared or system credentials the person knew, active leaves a path open. All the person's access and credentials have to be addressed.

The common root
This control fails in the gap between a personnel action and the removal of access. Departures and transfers are HR events, and the system access tied to them is easy to leave for later, but every hour that a departed person's account stays live is an hour of unneeded access to CUI. Protecting the system means closing access in step with the action.

4Ownership

This is a shared HR and IT control, coordinated so access changes track personnel actions.

RoleResponsibility for this control
Human resourcesNotifies IT of terminations and transfers so access changes can be made in step. Owns the personnel action trigger.
IT and system administratorTerminates or adjusts access and credentials consistent with the personnel action. Owns the access change evidence.
Security or compliance leadEstablishes the process and confirms access is removed promptly and completely.
See also: This control pairs with the screening of PS.L2-3.9.1 and depends on the account management of the access control family to execute the access changes.

5Tooling

The control is delivered by a personnel-action process linked to prompt access changes.

ObjectivesToolingWhat it provides
[a]Termination and transfer processA defined way to remove access coincident with personnel actions.
[b]Account and credential deprovisioningActual termination of access in step with the action.
[c]Role-based access review on transferAdjustment of access so transfers leave no excess.

The caveat is that the process has to execute promptly and completely, addressing all of a person's access and credentials. A process that runs slowly, misses credentials, or is applied inconsistently leaves the gap the control targets. The assessor examines all three objectives, so the process, its prompt execution, and transfer protection all have to hold.

6Evidence

The satisfied version of 3.9.2 shows access removed or adjusted in step with personnel actions.

EvidenceWhat it demonstrates
Termination and transfer processObjective [a]. A defined process for access changes.
Access change recordsObjective [b]. Access terminated consistent with the action.
Transfer access reviewObjective [c]. Access adjusted on transfer.

The evidence should show a defined process, records of access actually terminated in step with terminations, and access adjusted on transfers. The process together with the access change records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

Access should end when the need for it does

A departed person with a live account, or a transferred one carrying old permissions, is unneeded access to CUI, and this five-point control requires that the system be protected through those personnel actions. Linking HR events to prompt access changes is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.9.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.9.2[a] through 3.9.2[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing PS.L2-3.9.2 among the five-point basic security requirements. ecfr.gov
← Previous in Personnel Security
PS.L2-3.9.1 · Screen Personnel
Next: Physical Protection →
PE.L2-3.10.1 · Limit Physical Access
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry PS.L2-3.9.2 · Edition 2026.1 · Last reviewed July 12, 2026