3.2.1Make sure people know the risks in Rev. 3
Reworded: 03.02.01 Literacy Training and Awareness. Gains organization-defined parameters.
Status as of 2026-09-08
Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.
Side by side
Rev. 2 · in force 3.2.1 Role-Based Risk Awareness
Assessment objectives · 800-171A
- [a] security risks associated with organizational activities involving CUI are identified
- [b] policies, standards, and procedures related to the security of the system are identified
- [c] managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities
- [d] managers, systems administrators, and users of organizational systems are made aware of the applicable policies, standards, and procedures related to the security of the system
Rev. 3 · not adopted 03.02.01 Literacy Training and Awareness
a. Provide security literacy training to system users:
01. As part of initial training for new users and [Assignment: organization-defined frequency] thereafter,
02. When required by system changes or following [Assignment: organization-defined events], and
03. On recognizing and reporting indicators of insider threat, social engineering, and social mining.
b. Update security literacy training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
Determination statements · 800-171A Rev. 3
- 03.02.01.a.01[01] security literacy training is provided to system users as part of initial training for new users.
- 03.02.01.a.01[02] security literacy training is provided to system users <A.03.02.01.ODP[01]: frequency> after initial training.
- 03.02.01.a.02 security literacy training is provided to system users when required by system changes or following <A.03.02.01.ODP[02]: events>.
- 03.02.01.a.03[01] security literacy training is provided to system users on recognizing indicators of insider threat.
- 03.02.01.a.03[02] security literacy training is provided to system users on reporting indicators of insider threat.
- 03.02.01.a.03[03] security literacy training is provided to system users on recognizing indicators of social engineering.
- 03.02.01.a.03[04] security literacy training is provided to system users on reporting indicators of social engineering.
- 03.02.01.a.03[05] security literacy training is provided to system users on recognizing indicators of social mining.
- 03.02.01.a.03[06] security literacy training is provided to system users on reporting indicators of social mining.
- 03.02.01.b[01] security literacy training content is updated <A.03.02.01.ODP[03]: frequency>.
- 03.02.01.b[02] security literacy training content is updated following <A.03.02.01.ODP[04]: events>.
Organization-defined parameters
- A.03.02.01.ODP[01] the frequency at which to provide security literacy training to system users after initial training is defined.
- A.03.02.01.ODP[02] events that require security literacy training for system users are defined.
- A.03.02.01.ODP[03] the frequency at which to update security literacy training content is defined.
- A.03.02.01.ODP[04] events that require security literacy training content updates are defined.
Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.
Word by word
The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.
removed in Rev. 3 added in Rev. 3
Rev. 2 3.2.1 → Rev. 3 03.02.01 Literacy Training and Awareness
6 words kept, 30 removed, 51 added. Rev. 3 statement labels omitted for the comparison.
What NIST says changed
- New security requirement title
- Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for literacy training and awareness
- Added new ODP: frequency after intial training to provide security literacy training to users
- Added new ODP: events that necessitate re-taking training
- Added new ODP: frequency to update training content
- Added new ODP: events that necessitate updating training
- Includes withdrawn requirement: 03.02.01
NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.
NIST's Rev. 3 discussion for 03.02.01
Organizations provide basic and advanced levels of security literacy training to system users (including managers, senior executives, system administrators, and contractors) and measures to test the knowledge level of users. Organizations determine the content of literacy training based on specific organizational requirements, the systems to which personnel have authorized access, and work environments (e.g., telework). The content includes an understanding of the need for security and the actions required of users to maintain security and respond to incidents. The content also addresses the need for operations security and the handling of CUI. Security awareness techniques include displaying posters, offering supplies inscribed with security reminders, generating email advisories or notices from organizational officials, displaying logon screen messages, and conducting awareness events using podcasts, videos, and webinars. Security literacy training is conducted at a frequency consistent with applicable laws, directives, regulations, and policies. Updating literacy training content on a regular basis ensures that the content remains relevant. Events that may precipitate an update to literacy training content include assessment or audit findings, security incidents or breaches, or changes in applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines. Potential indicators and possible precursors of insider threats include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information that is not required for job performance; unexplained access to financial resources; sexual harassment or bullying of fellow employees; workplace violence; and other serious violations of the policies, procedures, rules, directives, or practices of organizations. Organizations may consider tailoring insider threat awareness topics to roles (e.g., training for managers may be focused on specific changes in the behavior of team members, while training for employees may be focused on more general observations). Social engineering is an attempt to deceive an individual into revealing information or taking an action that can be used to breach, compromise, or otherwise adversely impact a system. Social engineering includes phishing, pretexting, impersonation, baiting, quid pro quo, threadjacking, social media exploitation, and tailgating. Social mining is an attempt to gather information about the organization that may be used to support future attacks. Security literacy training includes how to communicate employee and management concerns regarding potential indicators of insider threat and potential and actual instances of social engineering and data mining through appropriate organizational channels in accordance with established policies and procedures.
What this means for you now
Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.2.1 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.
Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.
Where this page's facts come from
- Rev. 2 text and objectives
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Mapping and change class
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Rev. 3 03.02.01
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]