CMMCpedia Download

Requirements / Awareness and Training (AT)

AT.L2-3.2.1

Role-Based Risk Awareness

Official Source Material

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

Determine if:

  1. [a] security risks associated with organizational activities involving CUI are identified;
  2. [b] policies, standards, and procedures related to the security of the system are identified;
  3. [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities; and
  4. [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Generic government awareness training does not satisfy this requirement on its own.

Objectives [b] and [d] are about your policies, standards, and procedures. A stock DoD Cyber Awareness module says nothing about where your CUI (Controlled Unclassified Information) lives, who your security contact is, or which documents govern your system. Use the stock module if you already own it, then add the part that is about your organization.

Objectives [a] and [b] are documents, not training.

Two of the four objectives are satisfied before anyone sits in a session. Write down the security risks tied to your CUI activities. List the policies, standards, and procedures people must follow, and where each one lives. Skip these and you fail [a] and [b] no matter how good the training is.

Attendance records prove delivery, not awareness.

A completion report shows a person opened the module. Pair it with the material itself and with an acknowledgment that names what was covered. A signed acceptable use policy, a signed handbook, a terms of use consent recorded by your identity provider, or an email requiring an affirmative reply all work. An assessor who interviews a user and hears them name the policy and where to find it has evidence for [d].

Serve all three audiences the requirement names.

Managers, system administrators, and users are called out separately in [c] and [d]. Administrators hold the most risk and get the least tailored material. If one deck serves everyone, say how it addresses each audience, or write a short supplement for administrators.

Do not build a learning management system for this.

A slide deck, a sign-in sheet, and a dated acknowledgment cover all four objectives. Three slides are enough if they say where the policies live, who the security contact is, and what the reader is signing. Buy a platform when headcount makes tracking hard, not before.

Repeat it annually.

The objectives say people are made aware. They do not name a frequency. One session at hire is defensible on the text and weak in practice, because policies change and people forget. An annual refresher with a fresh acknowledgment removes the question.

What falls short

  • The DoD CUI or Cyber Awareness module on its own. It cannot cover your policies, standards, and procedures, so it cannot meet [b] or [d].
  • An email that tells people to read the policy, with no acknowledgment. Nothing shows anyone was made aware, so [c] and [d] have no evidence.
  • A statement signed by the IT department on everyone's behalf. IT cannot direct every employee, so it does not show that each person was made aware under [c] and [d]. The acknowledgment has to come from each person.
  • Training that never names your security contact or says where the governing documents live. It misses [d].

Edge cases

  • Contractors and part-time staff are users if they touch the system, because the requirement says users of organizational systems, not employees. A fractional IT provider who administers your environment is an administrator under [c] and needs the same awareness content, or proof that you reviewed theirs.
  • Staff who only use government furnished equipment covered by the government's own system security plan get their awareness training from the government, not from you. A person who also holds an account on your system is in scope for your system.
  • You do not need a separate document called a standard, even though objective [b] names policies, standards, and procedures. Standard-type content can live in your system security plan or in your procedures, as long as you can list which documents govern the system.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.