Understanding CMMC 2.0 Employee Requirements for Secure Onboarding
Explore the key CMMC 2.0 employee requirements and how to ensure compliance during the onboarding process. Learn practical steps to secure your organization.
March 22, 2026 · Winrove Team
When a New Hire Becomes a Compliance Gap
A mid-size defense subcontractor wins a contract requiring access to Controlled Unclassified Information (CUI). Three engineers start the following Monday. By Friday, two of them have network credentials but no documented security awareness training, no signed acceptable-use agreement on file, and access permissions that exceed what their roles actually require. The prime contractor runs a spot audit six weeks later. The subcontractor cannot produce evidence that those employees were briefed on CUI handling procedures before they touched the network. That is a CMMC finding, and it is entirely preventable.
CMMC 2.0 is not primarily a technology framework. A significant portion of its controls are people controls, and the onboarding window is where most of them either get satisfied or get missed. This post breaks down exactly which employee-facing requirements apply, how they map to the three CMMC 2.0 levels, and what a compliant onboarding workflow looks like in practice.
CMMC 2.0 in Brief: Three Levels, One Workforce Problem
CMMC 2.0 replaced the original five-level model with three levels tied directly to the sensitivity of the information a contractor handles:
- Level 1 (Foundational): 17 practices drawn from FAR 52.204-21. Applies to contractors handling Federal Contract Information (FCI). Annual self-assessment.
- Level 2 (Advanced): 110 practices aligned to NIST SP 800-171. Applies to contractors handling CUI. Triennial third-party assessment (C3PAO) for most contracts, with some allowing self-assessment.
- Level 3 (Expert): 110-plus practices from NIST SP 800-172. Applies to the highest-priority CUI programs. Government-led assessment.
The majority of defense subcontractors will land at Level 2. That is where the employee requirements become detailed enough to require a deliberate onboarding process, not just a checkbox on a new-hire form.
The NIST SP 800-171 Domains That Drive Employee Requirements
CMMC Level 2 maps directly to NIST SP 800-171 Rev 2. Several of its 14 domains place explicit obligations on individual employees, not just on systems or administrators.
Awareness and Training (AT)
This is the most direct people-facing domain. AT.2.056 requires that personnel be made aware of the security risks associated with their activities. AT.2.057 requires that personnel be trained to carry out their assigned information security responsibilities. Both controls require documented evidence: training completion records with dates, employee acknowledgment signatures, and content that is specific enough to be meaningful. Generic annual cybersecurity videos do not satisfy an assessor looking for CUI-specific training tied to the employee's actual role.
In practice, this means a new hire who will access CUI must complete role-appropriate security awareness training before or concurrent with receiving access, not at the next scheduled all-hands session. The training record must be retained and producible on demand.
Access Control (AC)
AC.1.001 limits system access to authorized users. AC.1.002 limits system access to the types of transactions and functions authorized users are permitted to execute. AC.2.006 requires controlling the flow of CUI in accordance with approved authorizations. These controls translate directly into onboarding tasks: provisioning access based on a defined role profile, documenting the authorization decision, and ensuring no employee starts with broader permissions than the role requires.
A common failure pattern is provisioning access based on what a departing employee had, rather than what the new role actually needs. That practice violates least privilege and creates an audit trail that is difficult to defend.
Identification and Authentication (IA)
IA controls require that users be uniquely identified and authenticated before accessing organizational systems. For contractors operating at Level 2, this typically means multi-factor authentication (MFA) is not optional. During onboarding, this means the employee must be enrolled in MFA before their first login to any system that touches CUI, and that enrollment must be documented.
Personnel Security (PS)
PS.2.127 requires screening individuals prior to authorizing access to organizational systems containing CUI. PS.2.128 requires that CUI be protected during and after personnel actions such as terminations and transfers. These two controls bracket the entire employment lifecycle, but they start at onboarding. Background check completion, adjudication status, and the date access was granted must align. Granting system access before a background check clears is a straightforward PS finding.
Configuration Management and Incident Response (CM, IR)
While these domains are more system-focused, they carry employee obligations. IR.2.092 requires that personnel know how to report incidents. CM controls require that employees understand what they are and are not permitted to install or configure on systems handling CUI. Both require documented briefings, not just posted policies.
What a Compliant Onboarding Sequence Looks Like
The following sequence reflects what a Level 2 assessment would expect to see documented for each new hire with CUI access:
- Pre-start background screening: Initiate the background check at offer acceptance. Document the scope (federal, state, criminal, employment verification) and retain the adjudication result. Do not provision CUI system access until the check clears.
- Role definition and access profile: Before day one, define the specific systems, data types, and permission levels the role requires. This becomes the authorization baseline for provisioning and for future access reviews.
- Security awareness training (CUI-specific): Deliver training that covers CUI identification, handling, marking, and destruction requirements under 32 CFR Part 2002 and the applicable contract's DD Form 254. Record completion with a timestamp and employee signature or electronic acknowledgment.
- Policy acknowledgment: Have the employee sign (wet or electronic, with ESIGN/UETA-compliant audit trail) the acceptable-use policy, remote work policy if applicable, and any mobile device policy. File these with the training record.
- MFA enrollment and credential provisioning: Enroll the employee in MFA before issuing credentials. Document the enrollment date and the systems to which access was granted.
- Least-privilege access provisioning: Grant access strictly per the role profile defined in step 2. Document who authorized the provisioning and when.
- Incident reporting briefing: Confirm the employee knows the organization's incident reporting procedure, including the 72-hour reporting window to the Government under DFARS 252.204-7012 if applicable. Retain a briefing acknowledgment.
Each of these steps produces a record. The record is the compliance artifact. An assessor will not take your word that training happened. They will ask for the log.
Access Reviews and Ongoing Obligations
CMMC compliance does not end at day one. AC controls require periodic access reviews to confirm that permissions remain appropriate. A practical cadence is quarterly for high-privilege accounts and annually for standard user accounts, with an immediate review triggered by any role change or transfer.
Training recurrence is equally important. AT controls do not specify an exact frequency, but assessors expect evidence of regular refreshers, not a single training event at hire. Annual role-specific training with documented completion is the defensible standard. When threat landscapes shift (a new phishing campaign targeting defense contractors, for example) supplemental briefings with dated acknowledgments strengthen the record.
Where Onboarding Workflows Break Down
Most CMMC findings related to personnel are not the result of bad intentions. They are the result of manual, fragmented processes. Training is tracked in one spreadsheet, access provisioning in a ticketing system, policy acknowledgments in a shared drive, and background check results in an email thread. When an assessor asks for a complete personnel file for a specific employee, assembling it takes hours and still produces gaps.
The operational fix is to centralize the onboarding record so that every required step, training completion, access authorization, policy signature, background check status, is captured in one place with timestamps and audit history. Winrove, built by IT Custom Solution LLC, is designed specifically for this workflow in federal contractor environments. It consolidates the documentation trail that CMMC assessors and contracting officers expect, without requiring contractors to stitch together generic HR tools that were not built with DFARS or NIST 800-171 in mind. For specifics on what the platform covers and current pricing, visit winrove.com.
A Practical Takeaway
Map every CMMC Level 2 personnel control to a specific step in your onboarding checklist. Assign an owner to each step. Define the record that step produces and where it is stored. Run a tabletop exercise: if an assessor asked for the complete compliance file for your last three hires today, how long would it take to produce it, and would it be complete? The answer to that question tells you exactly where your onboarding process needs work before your C3PAO assessment does.
Preserved Field Notes article. Original path /blog/understanding-cmmc-2-0-employee-requirements-for-secure-onboarding/. No unrelated help guide has been substituted.
Related Field notes
Reading a DPAS Priority Rating on a Federal Order: What Contractors Must Know ↗
Wide Area Workflow (WAWF) Invoicing Basics for New Federal Contractors ↗
Provisional Billing Rates and Indirect Rate Structures, Explained Simply ↗
Cost Realism: Surviving the Government Price Analysis ↗
The compliance matrix step most small contractors skip (and how it loses bids) ↗
NAICS Code Selection and Recertification: Avoiding the Small-Business Size-Standard Trap ↗