13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not

NIST SP 800-171 Rev 2 · 3.2 Awareness & Training

3.2.1 Security awareness for all users

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
SPRS weight
5
5 points deducted from 110 when not implemented.
CMMC level
L2
Level 2 only; not among the 17 Level 1 practices.
Assessment objectives
4
From NIST SP 800-171A, each one a “determine if” an assessor answers.

What an assessor checks

NIST SP 800-171A breaks 3.2.1 into 4 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.

  1. [a]Determine if security risks associated with organizational activities involving CUI are identified.
  2. [b]Determine if policies, standards, and procedures related to the security of the system are identified.
  3. [c]Determine if managers, systems administrators, and users of the system are made aware of the security risks associated with their activities.
  4. [d]Determine if managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.
Examine
[SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; relevant codes of federal regulations; security awareness training curriculum; security awareness training materials; security plan; training records; other relevant documents or records].
Interview
[SELECT FROM: Personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel composing the general system user community].
Test
[SELECT FROM: Mechanisms managing security awareness training; mechanisms managing role-based security training].

If it is open: POA&M eligibility

Not POA&M-eligible: above the 1-point ceiling · 5 points deducted

Worth 5 points. No requirement over 1 point may appear on a Level 2 POA&M, so this has to be closed before the assessment.

A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.

Where 3.2.1 maps

NIST SP 800-53 Rev 5

  • PM-14 Testing, Training, and Monitoring
  • PM-16 Threat Awareness Program

NIST CSF 2.0

  • Security awareness is provided Awareness and Training

SOC 2

  • CC2 Communication and Information - Obtain, generate, and use relevant information

Query it from your own tools

This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.

lookup_control 3.2.1
get_assessment_objectives 3.2.1
generate_poam_entries ["3.2.1"]

Install the MCP server, free, no account.

From MacZine

Working notes on Awareness & Training

The full run →