Jackie Ramsey July 16, 2026 0

A CMMC assessor can’t give credit for a practice that lives only in a manager’s memory. For contractors handling CUI, CMMC personnel screening needs clear proof that people were reviewed before they received access.

I help small defense contractors turn an informal hiring process into evidence that holds up under review. The goal isn’t to collect more private data than necessary. It’s to show a reasonable, repeatable process that matches each person’s access and risk.

Key Takeaways

  • CMMC Level 2 requires organizations to screen people before authorizing access to systems containing CUI.
  • CMMC does not prescribe one universal background check, citizenship requirement, or lookback period.
  • A written policy, dated approvals, access records, and onboarding documents create strong assessment evidence.
  • HR should protect detailed screening results, while security retains a restricted attestation or approval record.
  • Screening must connect to account provisioning, role changes, offboarding, and the company’s risk-based access model.

What CMMC Level 2 Requires for Personnel Screening

CMMC Level 2 includes practice PS.L2-3.9.1, “Screen Individuals.” The requirement is direct: screen individuals before authorizing access to organizational systems containing CUI. This applies to employees, temporary workers, contractors, and relevant third parties.

The official DoD CMMC Level 2 Assessment Guide focuses an assessor on whether the organization screens people before it grants that access. Therefore, I treat the approval to access CUI as a security gate, not a routine IT ticket.

Level 1 does not include this personnel-screening practice. However, many small contractors have mixed environments. Some staff work only with Federal Contract Information, while engineers, program staff, system administrators, and contracts personnel may access CUI. The distinction matters because it lets the company apply controls where they belong.

CMMC does not require a fixed “seven-year check” or a particular screening vendor. It also does not impose a blanket U.S. citizenship requirement. Your process should instead match contractual terms, applicable law, the role’s duties, and the sensitivity of its access.

For example, identity validation, employment verification, and confirmation of role-related qualifications may fit a standard CUI user. A privileged administrator with broad Cloud Infrastructure access may justify a more detailed review. If a contract requires fingerprints, drug testing, citizenship status, or a government clearance, that contract requirement belongs in the screening process.

The evidence must show a decision happened before access was approved, not merely that HR completed a hiring task.

This approach keeps the policy defensible. It also prevents a small company from adopting intrusive checks that don’t fit the role or applicable employment laws.

Evidence Artifacts That Prove Your Process Works

A good evidence set tells a consistent story across HR, security, and IT. I look for records that show the rule, the screening decision, and the access result.

Start with screening policy language. It should state who must be screened, when screening occurs, who reviews results, what happens when a result needs review, and who may approve an exception. The policy should also explain that CUI access stays blocked until the required approval is complete.

Then retain a completed acknowledgment. A signed employee acknowledgment can confirm that the person received the personnel-security policy, understands acceptable use expectations, and must report role or access changes. It doesn’t replace screening, but it supports the process.

Useful evidence artifacts include:

  • A background-check record, a provider completion notice, or an HR attestation that confirms the required review occurred. Limit access to detailed reports because they contain sensitive personal data.
  • A dated onboarding checklist with a screening-complete field, hiring-manager approval, security review, and CUI-access authorization.
  • An access authorization record from Microsoft Entra ID, a ticketing system, or an identity platform that shows when the employee entered the CUI group.
  • A role-change checklist that requires a new review when someone moves into a privileged position or begins handling CUI.
  • An offboarding checklist that records account disablement, device return, badge recovery, and removal from CUI-related groups.

A small contractor doesn’t need to hand an assessor full criminal-history reports or other sensitive files. Instead, HR can maintain restricted source records and provide a controlled attestation, a redacted completion record, or supervised evidence review. That practice limits exposure while still proving the control operated.

For practical templates and examples suited to smaller organizations, this personnel security guide for CMMC Level 2 offers useful context. Still, your own policy must reflect your contracts, workforce, and state employment rules.

Build a Risk-Based Screening Framework

A sleek white desk surface features a closed silver laptop, a spiral-bound notebook, and an open file folder. Soft daylight illuminates the organized setup against a neutral, minimalist wall background.

I recommend defining access categories before choosing screening steps. That makes decisions consistent and helps managers explain why a systems administrator receives a different review than a visitor or a staff member without CUI access.

Access categoryTypical roleEvidence to retain
No CUI accessReception, general accounting, visitorHiring and acceptable-use records, if applicable
Standard CUI accessProject coordinator, engineer, buyerScreening approval, CUI authorization, onboarding checklist
Privileged CUI accessSystem administrator, security leadEnhanced approval, role-based access record, privileged-access review
External CUI supportMSP technician, subcontractorContract terms, screening attestation, time-limited authorization

The important point is the documented rationale. For a privileged role, I document why the access creates greater risk and what review applies. For a low-risk role, I document why CUI access isn’t needed. This supports least privilege and keeps personnel screening aligned with actual work.

An adjudication process also belongs in the policy. HR, the hiring manager, and the security lead should know who reviews a potentially concerning result. They should apply consistent criteria, document the decision, and protect confidentiality. Fair Credit Reporting Act obligations, consent requirements, state restrictions, and adverse-action procedures may apply when a third-party screening report influences an employment decision.

Rescreening is a business decision unless a contract or organizational policy requires it. Some companies trigger it when someone changes roles, receives privileged access, returns after a long absence, or starts supporting a new contract. Whatever interval or trigger you choose, write it down and retain proof that it occurred.

Connect Screening to Your Technology Controls

Personnel evidence loses force when IT can grant CUI access without checking approval status. I connect the screening workflow to identity and access management, so the hiring or security approval precedes group membership and account provisioning.

In a Microsoft 365 environment, the approval can feed a ticket that authorizes membership in a protected Entra ID group. During an Office 365 Migration, I review inherited shared mailboxes, Teams sites, SharePoint libraries, and legacy administrator accounts. Old permissions often expose a gap between the screening policy and actual access.

The same discipline applies to Endpoint Security, Device Hardening, and a Secure Cloud Architecture. A screened employee still needs a managed device, multifactor authentication, restricted admin rights, and appropriate conditional-access policies. Personnel security and technical security work together.

Small Business IT teams often need one practical owner for these handoffs. A Business Technology Partner can align HR records, access approvals, and Cloud Management without turning the process into paperwork for its own sake. That work may sit within Cybersecurity Services, Technology Consulting, or fractional security leadership.

The technology footprint can be broader than a typical office. A contractor may also provide Restaurant POS Support or Kitchen Technology Solutions to commercial clients. Those systems don’t automatically fall under CMMC. However, personnel who support both customer systems and CUI environments need clearly separated access, devices, and authorization records.

A sound IT Strategy for SMBs also accounts for Data Center Technology, remote support tools, and vendor access. Infrastructure Optimization and Digital Transformation projects should never create unmanaged accounts or copy CUI into unapproved platforms.

Prepare Evidence Before the Assessment Window

Assessment preparation is easier when I build an evidence index. Each entry identifies the practice, artifact owner, storage location, date range, and any sensitive handling restrictions. This prevents a frantic search across email inboxes when the assessor requests proof.

I also test a small sample. Select a recent CUI user, a privileged administrator, a transferred employee, and a departed employee. Trace each person through screening, authorization, access provisioning, and access removal. Any missing date, approval, or ticket reveals a repair task.

Tailored Technology Services should fit the contractor’s size. A 12-person engineering firm doesn’t need a large enterprise HR platform. It does need a documented workflow that people follow every time.

For the broader CMMC compliance cycle, the federal contractor CMMC overview provides helpful context on assessment and affirmation expectations. I keep personnel screening evidence alongside system security plan support, training records, and access-control documentation.

Strong Managed IT for Small Business combines reliable support with accountable governance. That includes Business Continuity & Security, because a former employee’s unrevoked account can create both an operational and compliance problem.

A Defensible Record Is the Goal

CMMC personnel screening becomes manageable when hiring, HR, security, and IT follow one documented handoff. The strongest proof is simple: the company screened the individual, approved appropriate access, and retained records without exposing unnecessary private information.

I focus on a risk-based policy, controlled evidence retention, and access records that match real systems. That combination gives small defense contractors a credible, repeatable foundation for CMMC Level 2.


Discover more from Guide to Technology

Subscribe to get the latest posts sent to your email.

Category: 

Leave a Reply