DKDavid Koran& Associates
Home The CMMC Guide Part III · Awareness and Training AT.L2-3.2.1
The CMMC Guide · Awareness and Training Family

AT.L2-3.2.1  Security Awareness

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

Family
Awareness and TrainingAT, 3 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FourPer NIST SP 800-171A

1Overview

AT.L2-3.2.1 opens the Awareness and Training family and is one of the most heavily weighted requirements in the framework. It requires that managers, systems administrators, and users be made aware of the security risks in their activities and of the policies, standards, and procedures that govern the system. It is a five-point requirement that cannot be deferred on a plan of action, which reflects a simple truth: most of the controls in the framework depend on people who know why they matter.

Awareness is the human layer beneath the technical controls. A locked screen, a reported phishing email, a controlled drawing kept off the public website, each depends on a person who understands the risk and knows the rule. The requirement names three audiences deliberately, because their risks differ: users face phishing and handling mistakes, administrators hold powerful access and face the consequences of misconfiguration, and managers set the tone and the priorities. The control asks the organization to identify the risks and the governing policies, and to make each of these groups aware of both, so that the workforce operates with an informed sense of the threats and the rules rather than in ignorance of them.

The requirement · NIST SP 800-171 Rev 2, 3.2.1

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

The requirement has two halves: awareness of risks, and awareness of the policies, standards, and procedures. It is not enough to run a generic training video; the awareness has to connect the risks the organization actually faces and the rules it has actually written to the people whose daily activities those risks and rules concern. The five-point weight signals how much the rest of the program rests on this foundation, because a control the workforce does not understand is a control the workforce will quietly undermine.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.2.1 into four objectives: identify the risks, identify the governing policies, make people aware of the risks, and make people aware of the policies.

[a]

Security risks associated with organizational activities involving CUI are identified. The organization knows the risks its own activities create, so awareness can address them specifically.

MeetsThe organization has identified the risks its people face, from phishing to mishandling CUI to unsafe use of external systems, as the basis for its awareness.
FailsNo risks are identified, so any training is generic and disconnected from the organization's actual exposure.
[b]

Policies, standards, and procedures related to the security of the system are identified. The organization knows the rules its people are expected to follow, so awareness can convey them.

MeetsThe security policies, standards, and procedures exist and are identified as the material the workforce must be made aware of.
FailsPolicies are absent or unwritten, so there is nothing definite to make people aware of.
[c]

Managers, systems administrators, and users are made aware of the security risks associated with their activities. Each audience actually receives awareness of the risks relevant to its role.

MeetsUsers, administrators, and managers all receive awareness of the risks their activities carry, tracked so it can be shown.
FailsAwareness reaches some staff but not administrators or managers, or happens once and is never repeated.
[d]

Managers, systems administrators, and users are made aware of the applicable policies, standards, and procedures. Each audience is made aware of the rules that govern the security of the system.

MeetsThe workforce is made aware of the governing policies and where to find them, with the awareness recorded.
FailsPolicies exist but the workforce has never been walked through them, so awareness of the rules is assumed rather than delivered.

The four objectives pair two subjects, risks and policies, with the act of making people aware of each. The common gap is at objectives [c] and [d] for administrators and managers specifically, since organizations often train general users and forget that the requirement names administrators and managers as distinct audiences with their own awareness needs. The assessor looks for awareness that reaches all three groups and covers both risks and rules.

3Failure Patterns

The failures are about awareness that is generic, incomplete in its audience, or delivered once and never refreshed.

Generic training disconnected from the organization

An off-the-shelf awareness video that never mentions the organization's own risks or its own policies can satisfy a box while missing the objectives, which call for awareness of the risks the organization identified and the policies it wrote. Awareness has to connect to the organization's actual exposure and rules, not a generic script.

Administrators and managers left out

The requirement names managers and systems administrators alongside users, yet awareness programs frequently reach only general staff. Administrators hold the most powerful access and managers set priorities, so leaving either group out of awareness fails objectives [c] and [d] for the audiences whose decisions carry the most weight.

One and done

Awareness delivered once at onboarding and never repeated decays as threats change and staff turn over. While the frequency is organization-defined, awareness that never refreshes will not reflect current risks, and an assessor examining records will see a program that stopped rather than one that operates.

No record that it happened

Awareness that occurred informally, without any record of who received it and when, cannot be shown at assessment. The objectives are demonstrated through evidence that the audiences were actually made aware, so completion records and dated materials are what turn a claim of awareness into a met requirement.

The common root
Awareness fails when it is treated as a formality rather than the foundation it is. This is a five-point control because the technical safeguards depend on a workforce that understands the risks and the rules, and generic, partial, or unrecorded awareness leaves that foundation hollow.

4Ownership

This control is owned by whoever runs the security program, with visible support from leadership, since the requirement explicitly reaches managers and the tone they set.

RoleResponsibility for this control
Security or compliance leadIdentifies the organization's risks and governing policies, builds and delivers awareness to all three audiences, and retains the records. Owns the program evidence.
Executive and managersReceive awareness themselves and visibly support it, since the requirement names managers and their engagement sets whether the workforce treats awareness seriously.
IT and system administratorsReceive awareness suited to their privileged role and its heightened risk, since administrators are a named audience with distinct exposure.
All usersReceive and complete the awareness relevant to their activities, the broad base the control depends on.
See also: This control underlies the whole framework, and connects directly to AT.L2-3.2.2 on role-based training and AT.L2-3.2.3 on insider-threat awareness, as well as to the publicly-posted-CUI control at AC.L2-3.1.22, whose review depends on people knowing what CUI looks like.

5Tooling

The control is delivered through an awareness program and the records that prove it reached each audience. The tooling supports delivery and tracking rather than replacing the content.

ObjectivesToolingWhat it provides
[a], [b]Risk identification and the written policy setThe organization-specific risks and governing policies that the awareness must convey.
[c], [d] deliverySecurity awareness training platform, tailored briefings for administrators and managersDelivery of awareness to all three named audiences, with content connected to the organization's risks and rules.
ReinforcementSimulated phishing, periodic remindersOngoing reinforcement that keeps awareness current as threats change, supporting the recurring nature of the control.
EvidenceCompletion tracking and recordsThe dated records showing who was made aware and when, which demonstrate the objectives.

The caveat is that a platform delivers awareness but does not by itself make it relevant. The objectives call for awareness of the organization's identified risks and its own policies, so content has to be connected to those rather than left generic, and administrators and managers need awareness suited to their roles rather than the same general module. The assessor examines the awareness content and the completion records for all three audiences, so both relevance and reach have to be demonstrable.

6Evidence

The satisfied version of 3.2.1 shows identified risks and policies, awareness delivered to all three audiences, and records proving it.

EvidenceWhat it demonstrates
Identified risks and policy setObjectives [a], [b]. The organization-specific risks and governing policies the awareness conveys.
Awareness training contentObjectives [c], [d]. Material connected to the organization's risks and policies, including role-appropriate content for administrators and managers.
Completion recordsObjectives [c], [d]. Dated evidence that users, administrators, and managers were made aware.
Reinforcement recordsObjectives [c], [d]. Evidence the program recurs rather than having happened once.

The evidence should show awareness reaching all three named audiences and covering both risks and rules, with dated records rather than an assumption that people know. Awareness content tied to the organization's own risks and policies, paired with completion records across users, administrators, and managers, is the clearest demonstration, and because this control cannot sit on a plan of action, the awareness has to be real at the time of assessment.

The controls only work if people know why

Awareness is a five-point control because the locked screens, reported phishing, and protected drawings all depend on a workforce that understands the risks and the rules. Building awareness that connects to the organization's own risks and reaches administrators and managers, not just general staff, is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.1[a] through 3.2.1[d]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing AT.L2-3.2.1 among the five-point basic security requirements. ecfr.gov
← Previous: Access Control
AC.L2-3.1.22 · Control Publicly Posted CUI
Next in Awareness and Training →
AT.L2-3.2.2 · Role-Based Training
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AT.L2-3.2.1 · Edition 2026.1 · Last reviewed July 12, 2026