Awareness & Training (AT) 3.2.1, 3.2.2, 3.2.3

FutureFeed CMMC Education Series · Awareness & Training

Awareness & Training (AT) 3.2.1, 3.2.2, 3.2.3

The short version

If you’re responsible for CMMC compliance, here’s what these three requirements come down to. You need to:

  • Train everyone on basic security awareness
  • Give extra training to people with security responsibilities
  • Teach employees to recognize and report insider threats
  • Keep evidence showing the training actually happened

If you already have those four things and can prove them, you’re well on your way. Now let’s talk about what each one actually looks like.

Applies to: Organizations working toward CMMC compliance · NIST SP 800-171 Rev 2, Awareness and Training (3.2) · Requirements 3.2.1, 3.2.2, and 3.2.3.

Published: July 30, 2026 · Last reviewed: July 30, 2026.

01

In plain English

Awareness and Training: NIST SP 800-171 requirements 3.2.1, 3.2.2, and 3.2.3

If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here?

Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top. Before you can expect employees to protect sensitive information, they need to understand what they’re protecting and why it matters. This is the control family that lays that foundation. Once your people understand their role, the technical controls that come later are far easier to put in place and keep running.

Here’s the whole family in three layers:

  • Everyone gets basic security awareness training.
  • People with security responsibilities get additional, role-specific training.
  • Everyone learns how to recognize and report insider threats.

That’s it. Three layers, one conversation.

Example. Imagine a new engineer starts Monday morning. Before they get access to systems that hold sensitive information, they complete your security awareness training. If they’ll also administer user accounts, they get additional role-based training. During orientation, they learn how to report suspicious behavior and exactly where to report it. That’s what these requirements are asking you to do.

02

What you need to have in place

To be compliant, each of those boxes needs to be real and repeatable:

  • Security awareness training for every employee and contractor, ideally at hire and once a year after that.
  • Role-based training for anyone with security duties: IT admins, your security lead, anyone who manages accounts.
  • Insider threat training that covers the warning signs and, just as important, exactly how to report a concern.
  • Training records that prove who completed what, and when.
  • An annual refresher so none of this quietly lapses after the first year.

Annual refreshers are easy to overlook, but they’re one of the first things an assessor will verify.

03

What you need to prove it

Think in three buckets. An assessor will want all three, so it helps to build them at the same time.

People

  • Someone who owns the training program (often HR paired with your security lead)
  • Managers who make sure their teams complete it
  • The people with security duties who need the deeper, role-based training

Tools

  • Wherever you deliver and track training (a real learning platform, or even a simple tracked spreadsheet with sign-offs to start)
  • Your awareness content itself: slides, videos, or a short course
  • A way to store completion records

Documents

  • A short written policy that says who trains, on what, and how often
  • Your actual training materials, including the insider-threat piece
  • Completion records with names and dates
  • New-hire training records tied to start dates
  • A note in your System Security Plan (SSP) describing the whole program

You don’t need a fancy platform on day one. You need proof that the right people were trained on the right things, and dates that back it up.

04

When should I work on this

This is one of the first things I’d tackle. Training, roles, and responsibilities quietly support almost every other control you’ll get to later. When you reach access control or incident response, those all assume your people already understand the basics and know their part. Build this foundation first and everything after it gets easier. It’s also one of the more approachable families to knock out early, which is a nice confidence win before the heavier technical work.

Read next Why Security Is a Business Decision Before the controls comes the decision. Why this work belongs to leadership, not IT. Tuesday Playbook · 5 min read
The Road to CMMC

A new stop every Tuesday and Thursday.

Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.

05

Common challenges

1

Training happens once, then never again.

Why it happens: It gets treated as a one-time onboarding task instead of a yearly habit, so it slips off everyone’s calendar.

Recommendation: Set a yearly refresher and add training to your new-hire checklist so nobody starts work without it.

2

You can’t prove who actually completed it.

Why it happens: The training happened, but it was informal, so there’s no record with names and dates to hand an assessor.

Recommendation: Keep a simple completion log with names, topics, and dates. A signed roster counts as evidence.

3

Nobody knows how to report a concern.

Why it happens: Insider-threat training covers the warning signs but never tells people the actual steps to raise a flag.

Recommendation: Name the person or inbox to report to, and put those exact instructions inside the training itself.

06

What good looks like

A compliant contractor can usually answer yes to all of these:

  • Do new employees receive awareness training before they touch sensitive information?
  • Can you prove who completed training, and when?
  • Do your IT administrators receive additional security training beyond the basics?
  • Does everyone know how to report suspicious activity?

If any answer is no, that’s your next place to start.

07

How this connects to other controls

This family doesn’t stand alone. A few close relationships:

  • Personnel Security: a natural partner. Training pairs with background checks, NDAs, and offboarding, since they all deal with your people.
  • Incident Response: your team can only report a problem if they were trained to recognize one. This family feeds that one directly.
  • Access Control: the people you train are the same people you’ll be granting and reviewing access for later.
08

The requirements, word for word

For your reference, here’s the exact language so you’re working from the source and not a paraphrase:

  • 3.2.1 Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
  • 3.2.2 Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
  • 3.2.3 Provide security awareness training on recognizing and reporting potential indicators of insider threat.
Live Webinar · Thursday, August 13, 2026 · 1:00 PM ET / 10:00 AM PT

FutureFeed + Teramis, Better Together: A Deep Dive into CUI Discovery

Most CMMC scoping problems start the same way: a CUI boundary drawn around where an organization believes CUI lives, not where CUI has actually been found. On August 13 we are opening up Teramis live and showing you how to replace the assumption with proof. Live on Zoom, register to attend.

Every organization implements these controls a little differently. If you’re not sure whether your approach would satisfy an assessor, join one of our upcoming webinars or schedule a 15 Minutes with FutureFeed session. We’d rather answer your questions now than have you discover them during an assessment.

CMMC: Everything You Need to Know to Get Started, 6th Edition guide cover

CMMC: Everything You Need to Know to Get Started (6th Edition)

Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.

Sources

  • Source: NIST SP 800-171 Rev 2, Awareness and Training (3.2)
  • Related standards: NIST SP 800-53 Rev 5 (AT-2, AT-3, AT-4) · DFARS 252.204-7012