CMMC 3.2.2 Role-Based Security Training

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

Awareness and Training / Basic Security Requirement / CMMC Level 2
What this control requires

CMMC 3.2.2 in plain English

Control 3.2.2 sits in the Awareness and Training family. It ensures that the humans operating your systems understand the risks, the policies, and the part they play in protecting CUI.

NIST text (verbatim)

  • Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
  • Family: Awareness and Training (3.2.x)
  • Requirement type: Basic Security Requirement

What that means in practice

  • Annual general security awareness training tracked per user.
  • Role-based deep-dive training for sysadmins, developers, and CUI handlers.
  • Insider-threat indicators built into the awareness curriculum.
Who must train

Who must be trained under CMMC 3.2.2

NIST SP 800-171 Rev 2 states the requirement in one sentence, and it reaches everyone who holds assigned information security duties inside your CUI environment. Assessments sample evidence from this family against the practice statements, so breadth of coverage across roles matters as much as depth in any single course. Here is how organizations inside the CMMC Level 2 scope usually draw that map before an assessment.

Personnel in scope

  • Every employee with authorized access to Controlled Unclassified Information (CUI) on or from your systems.
  • IT and security staff who administer the systems that store, process, or transmit CUI.
  • Executives who own the security program, including the Affirming Official who submits the annual affirmation under 32 CFR Part 170.
  • New hires taking on CUI duties, and contractors or service providers operating inside your assessment scope.

Roles that usually get their own track

  • System administrators and network engineers, whose privileged accounts carry the most risk if mishandled.
  • Developers and engineers who build or maintain the systems that hold or move CUI.
  • Help desk and support staff who reset access and field security questions.
  • Contracts and finance staff who handle DFARS 7012 flowdown clauses and CUI markings on deliverables.

The role map is the artifact that ties all of this together: a document that names each role, lists its security duties, and points to the course assigned to it. Assessors use the role map to connect your completion records back to the requirement, and it doubles as the reference you update whenever duties change.

Assessment evidence

What CMMC assessors typically ask to see for 3.2.2

The assessment methods for 3.2.2 include examining documents and records, interviewing personnel, and testing. Translated into plain language: training exists, it matches duties, and you can prove who completed it and when.

Records assessors request

  • A training policy or procedure that states who trains, how often, and on which topics.
  • The role map connecting every role to its assigned courses or modules.
  • Completion records showing names, completion dates, and the course version each person took.
  • Certificates of completion, including the records from prior annual cycles.

Interviews and demonstrations

  • Trained staff describe their information security duties and where they learned them.
  • The training owner explains how completion is tracked and how overdue learners are chased down.
  • A senior executive explains how leadership receives training on its own duties.
  • A walkthrough of how new hires are enrolled and how the curriculum is refreshed.
Records

Training records that hold up under assessment

A completion record is more than a screenshot. Assessments go smoother when every record answers the same four questions: who, what role, which course, and when.

What a complete record contains

  • The learner's name and the role the training was assigned to.
  • The course title and version, so the content traces back to the curriculum in your policy.
  • The completion date, which anchors the record to an annual cycle.
  • The certificate, verifiable at /training/verify/, with its 12-month expiry stated.

Keeping records assessor ready

  • Export a roster CSV with completion dates after each cycle and file it with your other evidence.
  • Update the role map whenever duties change, and record who took the replacement module.
  • Report overdue completions to the program owner and track them in your training log until they close.
  • Keep records for departed staff covering the cycles when they were in scope, so past coverage stays provable.
Where to get the training

Where to get role-based security training for CMMC practice AT.L2-3.2.2

Petronella Technology Group, Inc. (Cyber AB Registered Provider Organization #1449) sells two self-paced role-based CMMC Level 2 courses that map to AT.L2-3.2.2: one for general users and one for executives. The executive course covers Senior Official duties under DFARS 7012 and 32 CFR Part 170, the annual affirmation, False Claims Act exposure, POA&M limits and 72-hour DFARS reporting. The courses support this practice; they do not by themselves make you CMMC compliant.

How Petronella implements 3.2.2

Our build pattern for Awareness and Training

We deploy this control through ComplianceArmor®, our turnkey CMMC and NIST 800-171 program. Here is the play we run when an MSP client onboards.

1

Roll out KnowBe4 or Hoxhunt with the Petronella curriculum baseline plus role-based modules.

2

Track completion in our LMS-of-record and surface noncompliant users to the engagement team weekly.

3

Wire phish-test and insider-threat reporting into ComplianceArmor® evidence packs.

Annual plan

How to build an annual role-based training plan

A training program that passes assessment is a calendar, not a one-time event. Six steps turn requirement 3.2.2 into a repeatable annual cycle.

1

Inventory every role that touches CUI or administers in-scope systems.

2

Map each role to a common awareness course plus role-based modules, and write the map down.

3

Enroll new hires when they take on duties, and put existing staff on a schedule you control.

4

Track completion centrally with names, dates, and course versions in one system of record.

5

Report overdue completions to the program owner and log each gap until it closes.

6

Re-enroll everyone as certificates expire at 12 months so records never go stale.

The 12-month certificate expiry on the CMMC courses lines up with this rhythm: every certificate you verify at /training/verify/ doubles as dated evidence for the annual cycle that issued it. For whole teams, the Awareness and Training License covers all three CMMC courses with one enrollment code, and buyers can export a roster CSV with completion dates for the assessor.

Common audit findings

Where assessors flag 3.2.2 gaps

Patterns we see during DIBCAC and CMMC C3PAO assessments inside the Awareness and Training family. Treat these as your gut-check before a Joint Surveillance Voluntary Assessment.

Typical gap

Finding 1

Annual training that does not include role-specific content for sysadmins or developers

Finding 2

No training records retained to prove completion during assessment

Petronella fix

Fix 1

Build a role-based curriculum (sysadmin, dev, CUI handler) on top of the general awareness module.

Fix 2

Capture training completion centrally and tie it to access-renewal workflow.

Common mistakes

Program habits that turn into 3.2.2 findings

Weak role-based evidence usually comes down to missing records and mapping rather than to course content. Each pairing below shows the habit and the correction.

Mistake

One generic course for everyone

A single all-hands module is delivered to every employee, with no role-specific depth for the people who administer or build CUI systems.

No completion dates retained

Training happened at some point, but nobody can show who completed what and when, so the evidence cannot be verified.

Training never refreshed

Completion certificates from a single past cycle are the only artifacts, with nothing current for the period under assessment.

Correction

Map roles to modules

Publish a role map that names each role, its duties, and the course assigned to it, then keep the map with the training policy.

Keep dated records

Export a roster with completion dates after every cycle and file it with the rest of your assessment evidence.

Set an annual cadence

Re-enroll staff as certificates expire at 12 months so a current record always exists for every person in scope.

Related controls

Other Awareness and Training controls in the 3.2.x family

Controls in the same family typically share evidence artifacts and audit interview targets. Address them as a set during your SSP build.

Beyond CMMC

The same structure supports HIPAA and FTC Safeguards training duties

Role-based security training is not a CMMC-only idea. Two other frameworks that small organizations commonly carry impose training duties of their own, and one annual role-based program can support all of them. See the dedicated HIPAA training and security awareness training pages for the full programs.

HIPAA Security Rule, 45 CFR 164.308(a)(5)

  • Requires a security awareness and training program for all members of the workforce, including management.
  • Implementation specifications add topics such as security reminders, protection from malicious software, log-in monitoring, and password management.
  • Role-specific depth is a common way to cover staff who handle protected health information every day.

FTC Safeguards Rule, 16 CFR 314.4(e)

  • Paragraph (e)(1) requires security awareness training for all personnel, updated as necessary to reflect risks identified by the risk assessment.
  • Paragraph (e)(3) is the role-based layer: information security personnel receive security updates and training sufficient to address relevant security risks.
  • Paragraph (e)(4) requires verifying that key information security personnel take steps to maintain current knowledge of changing threats and countermeasures.

If your practice carries HIPAA duties, the HIPAA Rescue Manual for Healthcare Practices ($999) and HIPAA Compliance and Cybersecurity Mastery ($2,997) are self-paced options with certificates of completion. For financial institutions working toward the Safeguards Rule, FTC Compliance Mastery ($149) covers the program requirements in depth. Certificates and rosters work the same way across programs, so one export can serve more than one audit.

Choosing a provider

How to choose a role-based security training provider

Course quality varies, and assessors will read your training evidence with 3.2.2 in mind. Ask every provider these five questions before you enroll anyone.

Question 1

Does the content map to specific practices?

Ask which practices each module maps to, such as AT.L2-3.2.1, AT.L2-3.2.2, and AT.L2-3.2.3, and get the mapping in writing so you can file it with your evidence.

Question 2

Can you export dated records?

You need names, completion dates, and course versions in a portable format. A roster CSV export turns an assessment conversation into a simple file handoff.

Question 3

Do certificates carry an expiry?

An expiry date keeps the program honest: it forces the annual cycle and shows the record belongs to the period the assessor is sampling.

Question 4

Are executive duties covered?

Executives carry duties the general user never sees, such as the annual affirmation under 32 CFR Part 170, risk acceptance, and incident reporting. Confirm the executive track covers them.

Question 5

Can a whole team enroll at once?

Ask how enrollment works at your headcount: whether one code covers the organization, what per-user pricing looks like, when invoicing starts, and how long seats stay redeemable.

FAQ

CMMC 3.2.2 questions buyers ask

Short answers to the questions defense contractors raise most about role-based security training. For the neighboring practices, read the Awareness and Training family overview, the 3.2.1 guide, and the insider threat program guide. If you are unsure where your program stands, start with a CMMC readiness assessment.

What does CMMC 3.2.2 require?

Control 3.2.2 requires that personnel are trained to carry out their assigned information security related duties and responsibilities. In practice that means training matched to the security duties each role carries, on top of the awareness training every user receives under 3.2.1, for roles such as system administrators, developers, general users who handle Controlled Unclassified Information, and executives.

How is 3.2.2 different from 3.2.1?

3.2.1 asks that managers, system administrators, and users be made aware of security risks and the applicable policies, standards, and procedures, while 3.2.2 asks for training specific to the duties of each role. Most organizations satisfy 3.2.1 with a common core course and then add role-based modules, such as general user and executive tracks, to satisfy 3.2.2.

Who must be trained under 3.2.2?

Everyone with information security duties inside a CMMC Level 2 scope. That includes employees who handle Controlled Unclassified Information, system administrators, developers, help desk staff, and the executive who submits the annual affirmation. Contractors operating inside your scope are typically enrolled in the same program with the same records.

What do CMMC assessors ask to see for 3.2.2?

Assessors typically examine your training policy, the role map connecting each role to its courses, and completion records showing who was trained and when. They interview trained personnel about their duties and interview the training owner about how completion is tracked, documented, and refreshed year to year.

How often should role-based training be repeated?

Most organizations run awareness and role-based training annually. CMMC course certificates from Petronella expire 12 months after issue, which lines up with an annual re-enrollment cycle and produces dated records for every period an assessor may sample.

What do the courses cost and how long do they take?

The CMMC Level 2 Security Awareness Common Core is $49 per learner and runs about 63 minutes. Role-Based Training for General Users is $59 and for Executives is $149, each about 30 minutes. The Awareness and Training License is $300 per user per year and includes all three CMMC courses.

What records should we keep for an assessor?

Keep a roster with completion dates, the course version each person took, and the role map that explains each assignment. Buyers can export a roster CSV with completion dates, and every certificate can be verified at /training/verify/ before it is filed with your evidence.

Do the courses map to specific CMMC practices?

The Common Core maps to AT.L2-3.2.1 and AT.L2-3.2.3. The General Users and Executives role-based courses map to AT.L2-3.2.2. Mapping statements describe how course content aligns with the practices; they support your implementation and do not by themselves make an organization CMMC compliant.

Does role-based training help with HIPAA or the FTC Safeguards Rule?

Yes. HIPAA Security Rule 45 CFR 164.308(a)(5) calls for a security awareness and training program for all members of the workforce, including management, and the FTC Safeguards Rule at 16 CFR 314.4(e) requires security awareness training for personnel plus security updates and training for information security personnel. The same annual role-based structure supports both.

How do we train a whole team at once?

Use the Awareness and Training License at $300 per user per year: one enrollment code covers 1 to 500 users across all three CMMC courses, with card checkout or invoice at 25 or more users. Smaller groups can use team packs of 10 seats for $290, 25 seats for $625, 50 seats for $999, or 100 seats for $1,499, and seats stay redeemable for 12 months.

Can contractors be trained under the same program?

Yes. Anyone operating inside your assessment scope with security duties can be enrolled the same way as employees, and their records belong in the same evidence set. The role map should list contractors alongside employees so the assessor can trace their training back to the requirement.

What happens if someone has not finished training?

Record the gap, assign the correct module, and capture the completion date when it closes. Gaps in completion records are easy for an assessor to spot in a sample, so some organizations tie training completion to access renewal until every learner is current.

Where does insider threat awareness fit?

Insider threat awareness is its own practice, AT.L2-3.2.3, which corresponds to NIST SP 800-171 control 3.2.3. The Common Core course covers insider threat awareness alongside general security awareness, so one course maps to both practices for every learner in your organization.

Ready to close the gap? Enroll individual learners in General Users or Executives, or start with the Common Core for awareness and insider threat coverage. If you want a clear picture of your Awareness and Training evidence before a C3PAO arrives, a CMMC readiness assessment shows what assessors will sample.

CP
By Craig Petronella
Founder, Petronella Technology Group, Inc. | CMMC-RP | DFE #604180 | CCNA | CWNE | MIT-Certified in AI and Blockchain
Craig founded Petronella Technology Group, Inc. in 2002 and now helps defense contractors prepare for CMMC assessments as a Cyber AB Registered Provider Organization (RPO #1449). He authored the CMMC 2.0 Certification Guide. Read the LinkedIn profile or verify the RPO listing at the CyberAB Marketplace.

Need help proving 3.2.2 for your CMMC assessment?

Petronella Technology Group runs ComplianceArmor® for defense contractors across North Carolina and nationwide. We close Awareness and Training gaps before your C3PAO does.