CMMCpedia Download

Requirements / Awareness and Training (AT)

AT.L2-3.2.2

Role-Based Training

Official Source Material

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

Determine if:

  1. [a] information security-related duties, roles, and responsibilities are defined;
  2. [b] information security-related duties, roles, and responsibilities are assigned to designated personnel; and
  3. [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

You define what the training is, and certifications are not required.

The requirement leaves the content to you. Vendor courses, conference sessions, a college class, or a written walkthrough of your own procedures all qualify, as long as they match the duty. So do the free modules from CDSE, the Defense Department's Center for Development of Security Excellence. For a small shop with no certified staff, name the vendor course for each system and record when it was completed.

The three objectives are a sequence: define, assign, track.

Objective [a] asks you to write down the security duties each role carries. Objective [b] asks you to tell named people that those duties are theirs. Objective [c] asks you to show they were trained for them. Do them in that order, because [b] and [c] have nothing to point at until [a] exists.

A role list can be three lines.

Person A administers the domain, the firewall, the VPN, and the GCC High tenant, the government cloud version of Microsoft 365. Person B reviews logs and manages backups. Both hold the incident response role. Point each line at the policy, the procedure, and the training material for that duty, and have each person sign that they received them.

General awareness training does not cover this requirement.

AT.L2-3.2.1 covers what every user needs. This requirement covers the duties that only some people hold: administration, log review, incident handling, backup, and physical security. If your only training is the all-hands module, you have no evidence for [c].

Keep the completion evidence simple and dated.

A PDF certificate, an email that says the course is done, a spreadsheet with material, person, and date, or an export from a learning system all work. The objectives ask whether people are trained, not whether a certificate exists. A record that ties a person to a duty, to a piece of training, and to a date is still the fastest way to answer [c].

What falls short

  • The all-hands awareness module as the only training for the people who administer the system. It shows nothing for [c].
  • The DoD mandatory CUI (Controlled Unclassified Information) training alone. It does not say who to report an incident to in your organization, or how CUI is handled in your environment. It trains no one for the duties in [a].
  • Hiring practices offered as training evidence. A stack of resumes shows who you hired, not what they were trained to do, and [c] asks for the training.

Edge cases

  • Janitorial and other facility staff are outside this requirement when your scoping keeps CUI out of their reach through clean desk rules, locked server rooms, and encrypted endpoints in a locked state. Badges, tailgating, and unlocked screens then belong in awareness training under AT.L2-3.2.1.
  • When unescorted facility staff could come across CUI in trash, printer rooms, or on unlocked screens, treat handling that exposure as an information security duty and train them for it.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.