1Overview
AT.L2-3.2.1 opens the Awareness and Training family and is one of the most heavily weighted requirements in the framework. It requires that managers, systems administrators, and users be made aware of the security risks in their activities and of the policies, standards, and procedures that govern the system. It is a five-point requirement that cannot be deferred on a plan of action, which reflects a simple truth: most of the controls in the framework depend on people who know why they matter.
Awareness is the human layer beneath the technical controls. A locked screen, a reported phishing email, a controlled drawing kept off the public website, each depends on a person who understands the risk and knows the rule. The requirement names three audiences deliberately, because their risks differ: users face phishing and handling mistakes, administrators hold powerful access and face the consequences of misconfiguration, and managers set the tone and the priorities. The control asks the organization to identify the risks and the governing policies, and to make each of these groups aware of both, so that the workforce operates with an informed sense of the threats and the rules rather than in ignorance of them.
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
The requirement has two halves: awareness of risks, and awareness of the policies, standards, and procedures. It is not enough to run a generic training video; the awareness has to connect the risks the organization actually faces and the rules it has actually written to the people whose daily activities those risks and rules concern. The five-point weight signals how much the rest of the program rests on this foundation, because a control the workforce does not understand is a control the workforce will quietly undermine.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.2.1 into four objectives: identify the risks, identify the governing policies, make people aware of the risks, and make people aware of the policies.
Security risks associated with organizational activities involving CUI are identified. The organization knows the risks its own activities create, so awareness can address them specifically.
Policies, standards, and procedures related to the security of the system are identified. The organization knows the rules its people are expected to follow, so awareness can convey them.
Managers, systems administrators, and users are made aware of the security risks associated with their activities. Each audience actually receives awareness of the risks relevant to its role.
Managers, systems administrators, and users are made aware of the applicable policies, standards, and procedures. Each audience is made aware of the rules that govern the security of the system.
The four objectives pair two subjects, risks and policies, with the act of making people aware of each. The common gap is at objectives [c] and [d] for administrators and managers specifically, since organizations often train general users and forget that the requirement names administrators and managers as distinct audiences with their own awareness needs. The assessor looks for awareness that reaches all three groups and covers both risks and rules.
3Failure Patterns
The failures are about awareness that is generic, incomplete in its audience, or delivered once and never refreshed.
Generic training disconnected from the organization
An off-the-shelf awareness video that never mentions the organization's own risks or its own policies can satisfy a box while missing the objectives, which call for awareness of the risks the organization identified and the policies it wrote. Awareness has to connect to the organization's actual exposure and rules, not a generic script.
Administrators and managers left out
The requirement names managers and systems administrators alongside users, yet awareness programs frequently reach only general staff. Administrators hold the most powerful access and managers set priorities, so leaving either group out of awareness fails objectives [c] and [d] for the audiences whose decisions carry the most weight.
One and done
Awareness delivered once at onboarding and never repeated decays as threats change and staff turn over. While the frequency is organization-defined, awareness that never refreshes will not reflect current risks, and an assessor examining records will see a program that stopped rather than one that operates.
No record that it happened
Awareness that occurred informally, without any record of who received it and when, cannot be shown at assessment. The objectives are demonstrated through evidence that the audiences were actually made aware, so completion records and dated materials are what turn a claim of awareness into a met requirement.
4Ownership
This control is owned by whoever runs the security program, with visible support from leadership, since the requirement explicitly reaches managers and the tone they set.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Identifies the organization's risks and governing policies, builds and delivers awareness to all three audiences, and retains the records. Owns the program evidence. |
| Executive and managers | Receive awareness themselves and visibly support it, since the requirement names managers and their engagement sets whether the workforce treats awareness seriously. |
| IT and system administrators | Receive awareness suited to their privileged role and its heightened risk, since administrators are a named audience with distinct exposure. |
| All users | Receive and complete the awareness relevant to their activities, the broad base the control depends on. |
5Tooling
The control is delivered through an awareness program and the records that prove it reached each audience. The tooling supports delivery and tracking rather than replacing the content.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Risk identification and the written policy set | The organization-specific risks and governing policies that the awareness must convey. |
| [c], [d] delivery | Security awareness training platform, tailored briefings for administrators and managers | Delivery of awareness to all three named audiences, with content connected to the organization's risks and rules. |
| Reinforcement | Simulated phishing, periodic reminders | Ongoing reinforcement that keeps awareness current as threats change, supporting the recurring nature of the control. |
| Evidence | Completion tracking and records | The dated records showing who was made aware and when, which demonstrate the objectives. |
The caveat is that a platform delivers awareness but does not by itself make it relevant. The objectives call for awareness of the organization's identified risks and its own policies, so content has to be connected to those rather than left generic, and administrators and managers need awareness suited to their roles rather than the same general module. The assessor examines the awareness content and the completion records for all three audiences, so both relevance and reach have to be demonstrable.
6Evidence
The satisfied version of 3.2.1 shows identified risks and policies, awareness delivered to all three audiences, and records proving it.
| Evidence | What it demonstrates |
|---|---|
| Identified risks and policy set | Objectives [a], [b]. The organization-specific risks and governing policies the awareness conveys. |
| Awareness training content | Objectives [c], [d]. Material connected to the organization's risks and policies, including role-appropriate content for administrators and managers. |
| Completion records | Objectives [c], [d]. Dated evidence that users, administrators, and managers were made aware. |
| Reinforcement records | Objectives [c], [d]. Evidence the program recurs rather than having happened once. |
The evidence should show awareness reaching all three named audiences and covering both risks and rules, with dated records rather than an assumption that people know. Awareness content tied to the organization's own risks and policies, paired with completion records across users, administrators, and managers, is the clearest demonstration, and because this control cannot sit on a plan of action, the awareness has to be real at the time of assessment.
The controls only work if people know why
Awareness is a five-point control because the locked screens, reported phishing, and protected drawings all depend on a workforce that understands the risks and the rules. Building awareness that connects to the organization's own risks and reaches administrators and managers, not just general staff, is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.1[a] through 3.2.1[d]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing AT.L2-3.2.1 among the five-point basic security requirements. ecfr.gov