to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.2.2Train people for the security duties they hold in Rev. 3

Reworded: 03.02.02 Role-Based Training. Gains organization-defined parameters.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.2.2 Role-Based Training

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

Assessment objectives · 800-171A

  1. [a] information security-related duties, roles, and responsibilities are defined
  2. [b] information security-related duties, roles, and responsibilities are assigned to designated personnel
  3. [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities

Rev. 3 · not adopted 03.02.02 Role-Based Training

a. Provide role-based security training to organizational personnel:

01. Before authorizing access to the system or CUI, before performing assigned duties, and [Assignment: organization-defined frequency] thereafter

02. When required by system changes or following [Assignment: organization-defined events].

b. Update role-based training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].

Determination statements · 800-171A Rev. 3

  1. 03.02.02.a.01[01] role-based security training is provided to organizational personnel before authorizing access to the system or CUI.
  2. 03.02.02.a.01[02] role-based security training is provided to organizational personnel before performing assigned duties.
  3. 03.02.02.a.01[03] role-based security training is provided to organizational personnel <A.03.02.02.ODP[01]: frequency> after initial training.
  4. 03.02.02.a.02 role-based security training is provided to organizational personnel when required by system changes or following <A.03.02.02.ODP[02]: events>.
  5. 03.02.02.b[01] role-based security training content is updated <A.03.02.02.ODP[03]: frequency>.
  6. 03.02.02.b[02] role-based security training content is updated following <A.03.02.02.ODP[04]: events>.

Organization-defined parameters

  • A.03.02.02.ODP[01] the frequency at which to provide role-based security training to assigned personnel after initial training is defined.
  • A.03.02.02.ODP[02] events that require role-based security training are defined.
  • A.03.02.02.ODP[03] the frequency at which to update role-based security training content is defined.
  • A.03.02.02.ODP[04] events that require role-based security training content updates are defined.

Draws on Rev. 2 3.2.2.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.2.2 → Rev. 3 03.02.02 Role-Based Training

Ensure that Provide role-based security training to organizational personnel: are trained Before authorizing access to carry out their the system or CUI, before performing assigned information security-related duties, and responsibilities. [Assignment: organization-defined frequency] thereafter When required by system changes or following [Assignment: organization-defined events]. Update role-based training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].

5 words kept, 10 removed, 41 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Aligned with SP 800-53, Rev 5 to provide more comprehensive detail on and foundational tasks for role based training
  • Added new ODP: frequency to provide role-based training after initial training
  • Added new ODP: events that require providing role-based training
  • Added new ODP: frequency to update training
  • Added new ODP: events that necessitate updating training

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.

NIST's Rev. 3 discussion for 03.02.02

Organizations determine the content and frequency of security training based on the assigned duties, roles, and responsibilities of individuals and the security requirements of the systems to which personnel have authorized access. In addition, organizations provide system developers, enterprise architects, security architects, software developers, systems integrators, acquisition/procurement officials, system and network administrators, personnel conducting configuration management and auditing activities, personnel performing independent verification and validation, security assessors, and personnel with access to system-level software with security-related technical training specifically tailored for their assigned duties. Comprehensive role-based training addresses management, operational, and technical roles and responsibilities that cover physical, personnel, and technical controls. Such training can include policies, procedures, tools, and artifacts for the security roles defined. Organizations also provide the training necessary for individuals to carry out their responsibilities related to operations and supply chain security within the context of organizational information security programs.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.2.2 as written in Rev. 2, and if you already choose a value for the parameters above in practice, write it down where your system security plan can find it.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.02.02
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]