8.1 Awareness & Training (AT) & Personnel Security (PS) Domains: Screening & Training

Key Takeaways

  • Awareness and Training has three Level 2 requirements covering risk and policy awareness, role-based training, and recognition and reporting of insider-threat indicators.
  • Personnel Security has two Level 2 requirements: screen individuals before authorizing access to systems containing CUI, and protect CUI during and after personnel actions such as termination and transfer.
  • CMMC does not universally prescribe a screening product, citizenship rule, investigation tier, training duration, annual cadence, or exit-interview checklist for these five requirements.
  • The organization defines training and screening appropriate to roles, risk, authorities, and contract, then proves that affected personnel completed the required process before access or duty.
  • Assessment evidence should link people, roles, training, access authorization, transfers, and terminations to current system and physical access rather than relying on a policy alone.
Last updated: August 2026

Awareness, Training & Personnel Security

Technology cannot protect CUI when people do not understand their duties or retain access after their role changes. The AT family has three Level 2 requirements and the PS family has two. None maps to Level 1.

Awareness and role-based training

Requirement 3.2.1 ensures that managers, system administrators, and users are aware of security risks associated with their activities and of applicable policies, standards, and procedures. The content should reflect the person’s work and environment. A generic annual video may contribute, but the team verifies that relevant populations and risks are covered.

Requirement 3.2.2 ensures personnel are trained to carry out assigned information-security duties and responsibilities. This is role-based. Administrators, help-desk personnel, developers, incident responders, physical-security staff, procurement personnel, and users may require different instruction depending on assigned duties.

Requirement 3.2.3 provides security-awareness training on recognizing and reporting potential indicators of insider threat. Recognition and reporting paths both matter. The requirement does not turn every mistake into malicious activity or authorize untrained personnel to investigate coworkers.

NIST SP 800-171 does not set a universal course length or annual frequency for these requirements. The organization defines timing based on role entry, changes, risk, policy, and other authorities. Another contract or policy may impose an annual cadence, but the assessor should cite the correct source.

Personnel screening

Requirement 3.9.1 screens individuals before authorizing access to organizational systems containing CUI. The organization defines screening criteria consistent with applicable law, regulation, risk, and contract. CMMC does not universally require one commercial background check, a security clearance, a Tier 3 investigation, citizenship, credit review, or drug test for every system user.

Do not confuse general workforce screening with the separate Tier 3 eligibility requirements that 32 CFR part 170 assigns to certain CMMC ecosystem personnel such as assessors. Export-controlled information may impose nationality or authorization constraints, but those come from the governing export authority and information, not automatically from PS.L2-3.9.1 for all CUI.

The evidence chain shows that screening was completed and accepted before access authorization. It may include defined criteria, adjudication status, approval dates, system-access dates, exception authority, and a focused sample that protects sensitive personnel information.

Termination and transfer

Requirement 3.9.2 protects CUI during and after personnel actions such as termination and transfer. Relevant controls can include disabling or changing logical and physical access, recovering credentials and media, changing shared secrets, transferring ownership, preserving required records, and reviewing the new role’s access.

The requirement does not publish one universal minute limit, demand an exit interview in every case, or prescribe an identical checklist for voluntary departure, urgent termination, leave, or internal transfer. The organization defines coordinated actions appropriate to risk and then carries them out promptly enough to protect CUI.

For transfers, simply leaving prior access in place because the employee remains trusted can violate least privilege and the personnel-action objective. For termination, disabling the directory account may be insufficient if active tokens, cloud sessions, physical badges, shared credentials, provider access, or local data remain.

Evidence sequence

  1. Identify role populations with access to the CMMC scope.
  2. Map awareness and role-specific training to actual duties and risks.
  3. Sample completion, timing, and understanding or operational use.
  4. Compare screening acceptance dates with access authorization dates.
  5. Trace recent terminations and transfers across identity, endpoint, cloud, facility, media, provider, and ownership records.
  6. Protect personnel records and collect only evidence needed for the objective.

A training roster can show attendance but not that administrators received the role-specific instruction they need. An HR termination ticket can show initiation but not that a remote provider account remained active. Cross-source reconciliation turns policy and workflow into defensible assessment evidence.

Insider-threat example

A user repeatedly attempts to copy controlled files after receiving a transfer notice. Awareness training should help coworkers recognize and report indicators without conducting their own investigation. Personnel and security teams follow authorized channels, preserve facts, adjust access according to role and risk, and protect the individual’s privacy. The assessor looks for trained reporting behavior and coordinated personnel actions, not a requirement that every suspicious act be publicly labeled malicious.

For a focused sample, build a timeline with screening acceptance, role assignment, training completion, access approval, role changes, and access removal. Compare HR, learning, identity, badge, endpoint, cloud, and provider records only to the extent needed. The dates reveal whether training and screening preceded the relevant access and whether personnel actions protected CUI across every active path.

Test Your Knowledge

What does PS.L2-3.9.1 require?

A
B
C
D
Test Your Knowledge

What is the focus of AT.L2-3.2.2?

A
B
C
D
Test Your Knowledge

How should transfer evidence be evaluated?

A
B
C
D