NIST 800-171 R3 03.02.02 Role-Based Training at a Glance
- Family: 03.02 Awareness and Training (AT)
- Requirement ID: 03.02.02 Role-Based Training
- Assessment Objectives (AOs): Ten (10) total, including the four (4) Organization-Defined Parameters (ODPs) below and six (6) determination statements
- Organization-Defined Parameters (ODPs): Four (4), specified by the Department of Defense (DoD) for the Defense Industrial Base (DIB)
- Source NIST 800-53 R5 Control: AT-03
- NIST 800-171 R3 Kill Chain Phase: Phase 21, Security Awareness Training
Role-Based Training is the targeted counterpart to Literacy Training and Awareness (03.02.01). Where literacy training gives every user the baseline, Role-Based Training (03.02.02) gives people with specific security responsibilities the deeper, duty-specific training they need before they touch the system or Controlled Unclassified Information (CUI). It has two (2) parts: provide role-based security training at defined moments (before authorizing access or assigned duties, on a recurring frequency, and on system changes or defined events), and update the training content on a defined frequency and after defined events. Like literacy training, it wraps four (4) Organization-Defined Parameters (ODPs) around timing and triggers.
A common difficulty with this requirement is treating the general awareness training as if it covers the role-based obligation. It does not. System administrators, security assessors, developers, configuration managers, and others with security-relevant duties need training tailored to those duties, delivered before they perform them, and refreshed on a schedule. A single all-hands training does not satisfy the role-based objectives.
Where things stand for companies facing the transition from NIST 800-171 R2 to R3:
- The National Institute of Standards and Technology (NIST) withdrew R2 on May 14, 2024, the same day R3 was published. The withdrawal notice states that R2 "has been withdrawn (archived), and is provided solely for historical purposes," so it will never receive another correction or clarification from NIST.
- R2 remains the contractual standard for the Department of Defense (DoD) and the Defense Industrial Base (DIB). Cybersecurity Maturity Model Certification (CMMC) assessments reference it directly: per Title 32 of the Code of Federal Regulations (CFR), section 170.14(c)(3), "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
- The rulemaking points the other direction. The proposed Controlled Unclassified Information (CUI) rule for the Federal Acquisition Regulation (FAR), published June 23, 2026 as part of the Revolutionary FAR Overhaul, would apply CUI safeguarding requirements government wide rather than only to DoD contracts, and it sets the baseline at R3. That rule is not final, and DoD has separately signaled an interim rule to move CMMC to R3.
What Does NIST 800-171 R3 03.02.02 Actually Require?
The following is reproduced verbatim from NIST 800-171 R3, requirement 03.02.02 Role-Based Training. Only the formatting has been adjusted for readability. This requirement has two (2) lettered parts, and part a has two numbered sub-parts:
- a. Provide role-based security training to organizational personnel:
- Before authorizing access to the system or CUI, before performing assigned duties, and [Assignment: organization-defined frequency] thereafter
- When required by system changes or following [Assignment: organization-defined events].
- b. Update role-based training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
The source control is AT-03 from NIST 800-53. Per the NIST discussion, organizations determine the content and frequency based on assigned duties, roles, and responsibilities, and provide security-related technical training tailored to roles such as system and network administrators, security architects, software developers, security assessors, and personnel conducting configuration management and auditing. You can read the requirement directly at NIST 800-171 R3, 03.02.02 (p. 20).
What Are the Organization-Defined Parameters (ODPs) Associated with NIST 800-171 R3 03.02.02?
Four (4) values sit inside this requirement. Depending on your contract, your organization may be permitted to define them. Organizations in the DIB subject to CMMC are not, because the DoD has defined them as policy.
The values below come from Attachment A of the DoD Chief Information Officer (CIO) memorandum dated 10 April 2025 (signed David W. McKeown). The memo identifies each parameter by requirement sub-part, while NIST 800-171A R3 identifies the same parameter by ODP number. Both identifiers appear below so you can match your System Security Plan (SSP) language to either document.
- ODP[01] (DoD memo identifier 03.02.02.a.01). the frequency at which to provide role-based security training to assigned personnel after initial training is defined. DoD Position: at least every 12 months.
- ODP[02] (DoD memo identifier 03.02.02.a.02). events that require role-based security training are defined. DoD Position: significant, novel incidents, or significant changes to risks.
- ODP[03] (DoD memo identifier 03.02.02.b.01). the frequency at which to update role-based security training content is defined. DoD Position: at least every 12 months.
- ODP[04] (DoD memo identifier 03.02.02.b.02). events that require role-based security training content updates are defined. DoD Position: significant, novel incidents, or significant changes to risks.
The memo states that its values "will be updated as necessary," so confirm against the current version before writing them into policy.
What Are the Assessment Objectives (AOs) For NIST 800-171 R3 03.02.02?
NIST 800-171A R3 breaks 03.02.02 into ten (10) assessment objectives: four (4) Organization-Defined Parameters (ODPs) and six (6) determination statements. These AOs are:
- A.03.02.02.ODP[01]: the frequency at which to provide role-based security training to assigned personnel after initial training is defined.
- A.03.02.02.ODP[02]: events that require role-based security training are defined.
- A.03.02.02.ODP[03]: the frequency at which to update role-based security training content is defined.
- A.03.02.02.ODP[04]: events that require role-based security training content updates are defined.
- A.03.02.02.a.01[01]: role-based security training is provided to organizational personnel before authorizing access to the system or CUI.
- A.03.02.02.a.01[02]: role-based security training is provided to organizational personnel before performing assigned duties.
- A.03.02.02.a.01[03]: role-based security training is provided to organizational personnel <A.03.02.02.ODP[01]: frequency> after initial training.
- A.03.02.02.a.02: role-based security training is provided to organizational personnel when required by system changes or following <A.03.02.02.ODP[02]: events>.
- A.03.02.02.b[01]: role-based security training content is updated <A.03.02.02.ODP[03]: frequency>.
- A.03.02.02.b[02]: role-based security training content is updated following <A.03.02.02.ODP[04]: events>.
The determination statements split the delivery into before-access, before-duties, recurring, and event-driven training, plus the two content-update objectives. If you are a DoD contractor, the four (4) ODPs are specified. Per the DoD-specified ODP values in ComplianceForge's NIST 800-171 R3 Transition Guide, the training frequency after initial training and the content-update frequency are both at least every twelve (12) months, and the events that trigger training and content updates are significant or novel incidents or significant changes to risks. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.02.02 (p. 24).
Assessment Methods and Objects for NIST 800-171 R3 03.02.02
Examine: security awareness and training policy and procedures; procedures for security training implementation; codes of federal regulations; security training curriculum; security training materials; training records; system security plan.
Interview: personnel with responsibilities for role-based security training; personnel with assigned system security roles and responsibilities.
Test: mechanisms for managing role-based security training and awareness.
How Does NIST 800-171 R3 03.02.02 Map From NIST 800-171 R2?
03.02.02 maps from NIST 800-171 R2 requirement 3.2.2 (ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities):
- A.03.02.02.a.01[01], A.03.02.02.a.01[02], A.03.02.02.a.01[03], A.03.02.02.a.02, and A.03.02.02.b[01] map directly to R2 3.2.2[c] (personnel are adequately trained to carry out their assigned duties).
- A.03.02.02.ODP[04] and A.03.02.02.b[02] are net new for R3.
- A.03.02.02.ODP[01], A.03.02.02.ODP[02], and A.03.02.02.ODP[03] have no clear mapping to any R2 AO.
Mapped against the ten (10) AOs, five (5) are direct (minimal effort), two (2) are net new, and three (3) have no clear mapping, with the last two (2) categories both counting as significant effort. The training delivery carries forward cleanly, but the parameters and the event-driven content update are the new work. Five of the ten (10) objectives are significant effort, almost all of it around defining the timing parameters and updating content after events.
How Does NIST 800-171 R3 03.02.02 Map to NIST 800-53 R5 and the SCF?
Source Control in NIST 800-53 R5:
Secure Controls Framework (SCF) Crosswalk
Organizations running a single control set across multiple frameworks can satisfy 03.02.02 through the following SCF controls:
- HRS-04 Defined Roles & Responsibilities
- HRS-05.1 Roles With Special Protection Measures
- HRS-08.1 Formal Indoctrination
- SAT-03 Maintaining Workforce Development Relevancy
- SAT-05 Role-Based Security, Compliance & Resilience Training
- SAT-05.1 Sensitive / Regulated Data Storage, Handling & Processing
- SAT-05.2 Privileged User Training
- SAT-06 Cyber Threat Environment Situational Awareness
The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.
Common Pitfalls with NIST 800-171 R3 03.02.02
The following are issues teams may encounter rather than certainties. They are about timing, parameters, and content maintenance, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:
- Train before access or duties, not after. A.03.02.02.a.01[01] and a.01[02] require role-based training before authorizing access to the system or CUI and before performing assigned duties. Training people after they have already started leaves these objectives unmet.
- Content updates after events are net new. A.03.02.02.b[02] requires updating role-based content following defined events. A course that never changes fails this objective.
- The parameters are specified for DoD work. The training and update frequencies are at least every twelve months, and the triggering events are significant or novel incidents or significant changes to risks.
- Identify the roles. Per the NIST discussion, role-based training covers administrators, architects, developers, assessors, and configuration and audit personnel. Map your security-relevant roles so the right people get the right training.
What Is Reasonable Evidence For NIST 800-171 R3 03.02.02?
Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.02.02 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.02.02 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.
- E-HRS-02 Assigned Roles - Application Developers. List of employed or contract personnel assigned to application development roles.
- E-HRS-03 Assigned Roles - Cybersecurity Staff. List of employed or contract personnel assigned to cybersecurity roles.
- E-HRS-04 Assigned Roles - Data Privacy Staff. List of employed or contract personnel assigned to data privacy roles.
- E-HRS-11 Role Assignment - Sensitive / Regulated Data. A formal role assignment to personnel who are cleared to handle sensitive/regulated data.
- E-HRS-13 Defined Cybersecurity & Data Privacy Responsibilities. A role-based cybersecurity & data privacy responsibilities to ensure personnel are both educated on the role and are responsible for the associated control execution.
- E-HRS-14 Responsibilities Review. A formal review process to ensure assigned responsibilities currently reflect business needs for the assigned role.
- E-HRS-17 Background Checks. Personnel screening practices, which centers around some form of formalized background check process.
- E-HRS-18 Provisioning Checklist (Onboarding). Personnel management practices to formally onboard personnel into their assigned roles.
- E-SAT-02 Initial User Training. Initial user training for security, compliance and/or resilience topics.
- E-SAT-04 Recurring User Training. Recurring (e.g., annual) user training for security, compliance and/or resilience topics.
- E-SAT-05 Role-Based Training. Specialized user training for privileged users, executives, individuals who handle sensitive/regulated data, etc.
- E-SAT-06 Training Materials. Security awareness training materials (e.g., curriculum, course work, presentations, etc.).
Alongside these, keep the System Security Plan (SSP) narrative for 03.02.02 recording the ODP values you adopted.
Timeline Considerations for NIST 800-171 R3 03.02.02
With five (5) of the ten (10) AOs at significant effort, 03.02.02 needs real transition time even though the delivery carries forward. A realistic sequence:
- Define the four (4) ODPs. For DoD contracts, adopt at least every twelve (12) months for both frequencies and significant or novel incidents or significant changes to risks for the events. For non-DoD scopes, define and document your own.
- Identify the security-relevant roles and the training each requires.
- Deliver role-based training before access and duties, on the recurring frequency, and on system changes or defined events (A.03.02.02.a.01 and a.02).
- Establish the content-update process on the frequency and after events (A.03.02.02.b[01] and b[02]).
- Collect evidence for all ten (10) AOs, including role definitions, training records, and content update history.
Frequently Asked Questions About NIST 800-171 R3 03.02.02
What value does the DoD require for the first parameter in NIST 800-171 R3 03.02.02? R3 leaves the value to the organization. For the DIB, the DoD set it in the 10 April 2025 memorandum under ODP identifier 03.02.02.a.01: at least every 12 months.
How many assessment objectives does NIST 800-171 R3 03.02.02 have? NIST 800-171A R3 breaks 03.02.02 into ten (10) assessment objectives: four (4) Organization-Defined Parameters (ODPs) and six (6) determination statements. An assessor works through each one separately, so each needs its own evidence.
Which NIST 800-53 R5 control does NIST 800-171 R3 03.02.02 come from? AT-03.
Where does NIST 800-171 R3 03.02.02 sit in the NIST 800-171 R3 Kill Chain? Phase 21, Security Awareness Training. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.
Bottom Line on NIST 800-171 R3 03.02.02
03.02.02 Role-Based Training gives people with security responsibilities duty-specific training before they act and keeps the content current. It maps from R2 3.2.2 with the delivery objectives transitioning directly, while the parameters and the event-driven content update are significant effort. The recurring problem is treating general awareness training as sufficient. Define the frequencies and events (for DoD, at least every twelve months and significant incidents or risk changes), identify your security roles, train them before access and duties, keep the content updated, and retain the records.
Authoritative sources:
Authoritative sources:
This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3 and references the DoD ODP memorandum of 10 April 2025. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.