StealthTech365

A former subcontractor employee’s Office 365 account sat active for eleven days after his last shift. Nobody used it maliciously. Nobody even noticed it was still there until a CMMC readiness assessment surfaced it during an access review. That single stale account turned a clean AC.L2 review into a finding, and it cost the contractor a full remediation cycle before their scheduled C3PAO assessment. This is the pattern we see over and over at Stealth Technology Group: offboarding gets treated as an HR checklist item, when under CMMC it’s a technical control with a clock attached to it.

Access Revocation Is Not a Courtesy, It’s a Control

Under NIST SP 800-171, account management isn’t satisfied by having a process that exists somewhere in a binder. The control language requires organizations to disable accounts when individuals are terminated or transferred, and it requires that this happen in a timeframe an assessor can actually verify. That distinction matters more than most contractors realize. A policy that says “IT will deactivate access upon separation” reads fine in a SSP, but if the evidence shows a seven-day average lag between separation date and account disablement, the control is not being met in practice, and practice is what gets scored. Our compliance team has sat across the table from assessors who ask for the separation date, the deactivation timestamp, and the delta between them for a sample of former employees. If your organization can’t produce that pairing quickly, you already have a problem, regardless of what your policy document claims.

digital cyber security lock system highlighting data security encryption, cyber password protection

Where Revocation Timing Actually Lives in the Control Set

Access revocation isn’t a single line item — it threads through several control families, and contractors often miss how many places it shows up.

  • Access Control (AC.L2-3.1.1 and 3.1.2): account management requires that accounts are disabled or removed when no longer needed, which includes terminations, role changes, and contract expirations.
  • Personnel Security (PS.L2-3.9.2): this is the control most directly tied to offboarding — it requires that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
  • Identification and Authentication (IA.L2): shared credentials, service accounts, and any authenticator tied to a departing user’s identity need to be addressed, not just their primary login.
  • Audit and Accountability: you need a log trail showing when the account was disabled, who disabled it, and whether any activity occurred on it after the separation date — a requirement that overlaps heavily with what we cover in our piece on audit logging retention under AU.L2.

Contractors who treat this as purely an “IT ticket” problem tend to satisfy AC.L2 while quietly failing PS.L2, because nobody connected the HR trigger to the technical action in a way that’s provable.

The 24-Hour Myth and What Assessors Actually Check

There’s a persistent belief among defense contractors that CMMC mandates a specific number — 24 hours, same-day, immediate — for account deactivation. It doesn’t. NIST SP 800-171 uses language like “in accordance with organizational policies” rather than a hardcoded number, which means the standard your organization sets for itself becomes the standard you’re assessed against. This is both a relief and a trap. It’s a relief because you’re not held to an arbitrary industry benchmark. It’s a trap because if your policy says “within 24 hours” and your actual practice averages three days, you’ve created a documented gap between stated control and observed control, and that gap is worse than having no stated timeframe at all. We advise clients to set a timeframe they can consistently hit — same business day for voluntary departures, immediate for involuntary ones — and then build the automation to make that timeframe realistic rather than aspirational.

Why Offboarding Breaks: The HR-to-IT Handoff Gap

Almost every failure we’ve diagnosed traces back to the same root cause: HR knows about a separation before IT does, and the handoff between those two functions is manual, informal, or dependent on someone remembering to send an email. A manager tells HR verbally that an employee’s last day is Friday. HR processes the paperwork on Monday. IT gets a ticket on Tuesday. The account sits live for four extra days with nobody actively watching it, and if that employee had access to CUI-scoped systems, every one of those days is exposure that has to be accounted for during an assessment. This is precisely the kind of scoping and access boundary issue we walk through when helping clients understand how CMMC asset categories sort their environment — a departing employee’s laptop and credentials don’t stop being in-scope assets just because their employment ended.

The fix isn’t a better email chain. It’s removing the human relay entirely. When HR systems trigger identity platform actions directly — disabling the account, revoking MFA tokens, pulling group memberships — the timing problem resolves itself because there’s no longer a person in the loop who has to remember to act. Our managed IT services team builds this integration as a standard part of onboarding contractors into a CMMC-aligned environment, because manual handoffs are the single most common root cause we find during gap assessments.

Not All Departures Are the Same Risk

Contractors often build one offboarding workflow and apply it uniformly, but the risk profile of a departure changes the urgency of the revocation, and your process should reflect that.

  • Voluntary, amicable departure with notice: lower urgency, but still requires same-day deactivation on the last working day, not “whenever IT gets to it.”
  • Involuntary termination: requires immediate, often pre-emptive revocation — access should be cut at or before the termination conversation, not after, because the exposure window here carries the highest insider-threat risk.
  • Role transfer within the organization: frequently overlooked entirely. An employee moving from engineering to finance doesn’t get “offboarded,” but their old access should be revoked with the same rigor as a true separation, and this is a gap we see constantly when reviewing account privileges for engineering and manufacturing clients whose staff move between program teams.
  • Contractor or subcontractor offboarding: third-party personnel often have access provisioned outside your normal HR system entirely, which means there’s no HR trigger to rely on at all — someone has to own tracking their contract end dates manually or through a vendor management process.

Treating these as one workflow is how contractors end up with a documented process that technically exists but doesn’t match the actual risk of any specific scenario an assessor might sample.

african american businesswoman in formal wear signing the contract to prevent probability of risks in cyber security

The Accounts Everyone Forgets

Primary directory accounts get disabled reliably in most environments we assess. What gets missed is everything downstream of that primary identity. Shared mailboxes the departing employee had delegate access to. VPN certificates issued outside the identity provider. API keys or service account credentials the employee generated for a project and never rotated. VoIP extensions and voicemail boxes tied to their name, which is a detail that surprises people until they realize cloud-based VoIP platforms often keep extensions active by default unless someone explicitly deprovisions them. Cloud storage shares and third-party SaaS logins that were never centrally provisioned through single sign-on in the first place. None of these show up on a standard “disable AD account” checklist, and every one of them represents a live credential that can technically access CUI-scoped resources long after the person who held it has left the building.

This is exactly why we push clients toward centralized identity management as part of a broader cybersecurity posture rather than as a bolt-on tool. If every credential a user holds is federated through a single identity provider, one disable action actually terminates access everywhere. If it isn’t, offboarding becomes a scavenger hunt through systems nobody fully inventoried, and the Complete CUI Lifecycle approach we recommend treats every one of those access points as something that has to be tracked from provisioning through disposal, not just at the moment of hire.

What Evidence a C3PAO Actually Wants to See

Assessors aren’t interested in your intentions. They want artifacts. For access revocation specifically, expect a request for a sample of separated employees over the assessment period, matched against HRIS termination dates and identity provider deactivation logs, with the gap between the two calculated. They’ll also want to see whether any authentication events occurred on those accounts after the separation date — a single successful login after termination, even an automated background sync, raises immediate questions about whether the account was truly disabled or just had its password reset. This overlaps directly with the audit trail requirements we cover in our incident response guidance, because a login on a supposedly-disabled account is exactly the kind of anomaly your monitoring should flag and your IR plan should address, not something you discover for the first time during an assessment interview.

Assessors will also ask who has the authority to disable an account and whether that authority is documented. If your IT help desk staff can deactivate accounts but there’s no record of who requested it or approved it, you have a control gap even if the timing itself was fine. Evidence needs to show the full chain: trigger, authorization, action, and confirmation.

Building a Workflow That Survives Scrutiny

The contractors who pass this cleanly share a common structure, and it isn’t complicated, but it does require coordination between departments that often don’t talk to each other. HR initiates a termination or transfer record in a system that’s integrated with identity management, not a standalone spreadsheet. That trigger fires an automated deprovisioning workflow that disables the primary account, revokes active sessions and MFA tokens, and pulls group memberships tied to CUI-scoped resources, all within the same business day for standard separations and immediately for involuntary ones. A secondary review — often handled through vCIO services or a co-managed IT arrangement — audits the full list of systems and shared resources the employee had access to, not just the primary directory account, and confirms each one was addressed. The whole sequence gets logged with timestamps, and those logs get retained on the same schedule as your other audit evidence.

Contractors running lean IT teams, particularly smaller finance and legal firms supporting defense primes, often don’t have the internal headcount to build and monitor this kind of workflow alone, which is where a co-managed IT partnership fills the gap without requiring a full internal security team. The goal isn’t more paperwork. It’s removing the manual steps where delay and human error actually live.

What This Actually Costs When It’s Ignored

The direct cost of a failed access revocation control isn’t usually a breach — most stale accounts never get exploited. The cost is remediation timeline. A finding on personnel security controls during a mock assessment or a real C3PAO engagement typically triggers a plan of action and milestones, and depending on your assessment schedule, that can push certification back by months while you rebuild the workflow, generate a clean evidence trail, and demonstrate the new process operating consistently over a meaningful sample period. For contractors racing a contract deadline that requires certification, that delay has direct revenue consequences, not just a compliance headache. It’s also worth remembering that DFARS 252.204-7012 obligations don’t pause while you fix an internal process gap — your safeguarding responsibilities for covered defense information remain in effect regardless of where you are in a remediation cycle.

There’s also a quieter cost: every stale account is a slightly larger attack surface, and while CISA guidance consistently flags credential hygiene as one of the more preventable categories of compromise, it’s exactly the kind of control that gets deprioritized when teams are focused on firewalls and endpoint tools instead of the unglamorous work of identity lifecycle management.

cyber security protects against breaches, hacks, and network attacks using strong infrastructure

Conclusion

Access revocation timing looks like an administrative detail until an assessor asks you to prove it, and by then it’s too late to retrofit a clean evidence trail. The contractors who handle this well aren’t the ones with the longest policy document — they’re the ones who removed the manual handoff between HR and IT entirely, built automated deprovisioning into their identity platform, and can produce a timestamped chain from separation to disablement for any employee an assessor might sample. If your current process depends on someone remembering to submit a ticket, you don’t have a control, you have a hope. Check the CyberAB marketplace for how assessors are trained to evaluate exactly this kind of evidence, and take a hard look at whether your offboarding workflow would survive that scrutiny today.

If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness. 

Add Your Heading Text Here

Scroll to Top