NIST SP 800-171 Rev 2 · 3.2 Awareness & Training
3.2.1 Security awareness for all users
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
- SPRS weight
- 5
- 5 points deducted from 110 when not implemented.
- CMMC level
- L2
- Level 2 only; not among the 17 Level 1 practices.
- Assessment objectives
- 4
- From NIST SP 800-171A, each one a “determine if” an assessor answers.
What an assessor checks
NIST SP 800-171A breaks 3.2.1 into 4 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.
- [a]Determine if security risks associated with organizational activities involving CUI are identified.
- [b]Determine if policies, standards, and procedures related to the security of the system are identified.
- [c]Determine if managers, systems administrators, and users of the system are made aware of the security risks associated with their activities.
- [d]Determine if managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.
- Examine
- [SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; relevant codes of federal regulations; security awareness training curriculum; security awareness training materials; security plan; training records; other relevant documents or records].
- Interview
- [SELECT FROM: Personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel composing the general system user community].
- Test
- [SELECT FROM: Mechanisms managing security awareness training; mechanisms managing role-based security training].
If it is open: POA&M eligibility
Not POA&M-eligible: above the 1-point ceiling · 5 points deducted
Worth 5 points. No requirement over 1 point may appear on a Level 2 POA&M, so this has to be closed before the assessment.
A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.
Where 3.2.1 maps
NIST SP 800-53 Rev 5
- PM-14 Testing, Training, and Monitoring
- PM-16 Threat Awareness Program
NIST CSF 2.0
- Security awareness is provided Awareness and Training
SOC 2
- CC2 Communication and Information - Obtain, generate, and use relevant information
Query it from your own tools
This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.
lookup_control 3.2.1 get_assessment_objectives 3.2.1 generate_poam_entries ["3.2.1"]
Install the MCP server, free, no account.
From MacZine