DKDavid Koran& Associates
Home The CMMC Guide Part III · Awareness and Training AT.L2-3.2.2
The CMMC Guide · Awareness and Training Family

AT.L2-3.2.2  Role-Based Training

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

Family
Awareness and TrainingAT, 3 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
ThreePer NIST SP 800-171A

1Overview

AT.L2-3.2.2 is the second five-point requirement in the Awareness and Training family, and it moves from general awareness to specific competence. Where 3.2.1 makes everyone aware of risks and rules, this control requires that people with assigned security duties be trained to actually carry them out. It too cannot be deferred on a plan of action.

General awareness and role-based training answer different questions. Awareness asks whether the workforce understands the risks; this control asks whether the people who hold security responsibilities can perform them. The administrator who manages accounts and permissions, the person who reviews audit logs, the one who handles incident response, each has duties that generic awareness does not prepare them for. The control asks the organization to define those security-related duties, assign them to specific people, and train those people to carry them out, so that the responsibilities the program depends on are held by people equipped to fulfill them rather than assigned in name only.

The requirement · NIST SP 800-171 Rev 2, 3.2.2

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

The phrase "assigned information security-related duties and responsibilities" is the pivot. The control assumes those duties have been defined and assigned, and it requires training suited to them. That training is role-specific: an administrator needs training in the secure administration of the systems they run, an incident responder in the response process, a reviewer in what the logs should show. The five-point weight reflects that a security program is only as strong as the competence of the people running its moving parts.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.2.2 into three objectives: define the duties, assign them, and train the assigned personnel.

[a]

Information security-related duties, roles, and responsibilities are defined. The organization has articulated the security duties that people are expected to carry out.

MeetsThe security-related duties are defined: administration, log review, incident response, and the rest of the roles the program depends on.
FailsSecurity duties are undefined, so it is unclear who is responsible for what and therefore what training is needed.
[b]

Information security-related duties, roles, and responsibilities are assigned to designated personnel. Those defined duties are given to specific, named people.

MeetsEach defined security duty is assigned to a named individual or role, so responsibility is clear.
FailsDuties are defined in the abstract but assigned to no one, so no one is accountable for carrying them out.
[c]

Personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. The people who hold the duties are trained to perform them.

MeetsThe administrator, reviewer, and responder each receive training suited to their specific duties, tracked so it can be shown.
FailsPeople hold security duties they were never trained for, learning by trial and error on live systems.

The three objectives move from defining duties to assigning them to training the assigned people. The common gap is at objective [c], where duties are assigned but the training is only the same general awareness everyone gets, which does not prepare a person for the specific security work they hold. The assessor looks for training matched to the assigned duties, not generic awareness standing in for it.

3Failure Patterns

The failures are about duties that are unassigned or untrained, and about role-based training collapsed into general awareness.

The accidental administrator

A small shop often has one person who became the system administrator by availability rather than training, holding powerful duties they were never prepared for. The person learns account management, permissions, and hardening by trial on production systems, which fails objective [c] and puts the security of the environment in untrained hands. Training suited to the administration duties is what the control requires.

General awareness standing in for role training

Where the only training anyone receives is the general awareness of 3.2.1, the people with specific security duties get nothing tailored to those duties. The two controls are distinct: awareness for everyone, role-based training for those with assigned responsibilities, and using one to satisfy the other leaves objective [c] unmet.

Duties assigned to no one

Security duties that are written down but assigned to no specific person fail objective [b], and untrained-because-unassigned work tends to fall through entirely. Log review that is nobody's job does not happen, and the control's chain from defined to assigned to trained breaks at the first missing link.

No record of the training

Role-based training that happened informally, with no record of who was trained on what, cannot be demonstrated. The objective is met through evidence that the assigned personnel were trained for their duties, so records tying training to the specific roles are what carry the requirement.

The common root
This control fails when responsibility outruns preparation. Someone holds a security duty, often the accidental administrator, without training for it, and a five-point requirement goes unmet because the person running a critical part of the program was never equipped to run it.

4Ownership

This control is owned by whoever manages the security program and the people in it, since defining and assigning duties is a management act and training follows from it.

RoleResponsibility for this control
Security or compliance leadDefines the security-related duties, ensures they are assigned, and arranges training suited to each. Owns the training records.
Executive sponsorBacks the assignment of duties and the investment in training, since role-based training for administrators and responders often means external courses or certifications that need support.
IT and system administratorsReceive training matched to their administration duties, the role whose untrained exposure is the most common failure of this control.
Anyone holding a security dutyIncident responders, log reviewers, and others receive training for the specific responsibilities they hold.
See also: This control builds on the general awareness of AT.L2-3.2.1 and connects to the duties defined across the framework, including audit review, incident response, and the secure administration that many technical controls assume.

5Tooling

The control is delivered through role-appropriate training and the records that tie it to assigned duties. The tooling is largely the training itself, which for technical roles is often external.

ObjectivesToolingWhat it provides
[a], [b]Role definitions and a responsibility assignmentThe defined security duties and the named people who hold them, the basis for targeted training.
[c] administrationVendor and platform administration training, security configuration coursesTraining the administrator in the secure operation of the systems they run.
[c] specializedIncident response, log analysis, and related role training or certificationsTraining for the specific security duties beyond administration, matched to each assigned role.
EvidenceTraining completion records tied to rolesThe dated records linking training to the assigned duties, which demonstrate the objective.

The caveat is that the training must match the duty, not merely exist. A general course does not satisfy the requirement for a specialized duty, and the objective is met when the person holding a role is trained for that role, which for a small shop often means budgeting for external training the accidental administrator never had. The assessor examines the assigned duties and the training records together, looking for a match between the responsibility and the preparation.

6Evidence

The satisfied version of 3.2.2 shows defined and assigned duties and training records that match them.

EvidenceWhat it demonstrates
Defined security dutiesObjective [a]. The articulated security-related roles and responsibilities.
Responsibility assignmentObjective [b]. The named individuals holding each defined duty.
Role-based training recordsObjective [c]. Dated evidence that assigned personnel were trained for their specific duties.
Certifications or course completionsObjective [c]. Where used, external training demonstrating competence for technical roles.

The evidence should tie training to assigned duties, showing that the people holding security responsibilities were prepared for them rather than only exposed to general awareness. Records matching role-specific training to the named holders of each duty are the clearest demonstration, and because this control cannot sit on a plan of action, the training has to be in place at the time of assessment.

The accidental administrator needs real training

In many shops the person running the systems grew into the role without training for it, which is exactly the gap this five-point control targets. Defining the security duties, assigning them, and getting the people who hold them, the administrator especially, trained to carry them out is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.2.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.2.2[a] through 3.2.2[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing AT.L2-3.2.2 among the five-point basic security requirements. ecfr.gov
← Previous in Awareness and Training
AT.L2-3.2.1 · Security Awareness
Next in Awareness and Training →
AT.L2-3.2.3 · Insider Threat Awareness
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AT.L2-3.2.2 · Edition 2026.1 · Last reviewed July 12, 2026