Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.02.01OFFICIAL TITLEPENDING NIST SME REVIEW

03.02.01Literacy Training and Awareness

03.02 Awareness and Training · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires providing security literacy training to system users as part of initial training, on an organization-defined frequency thereafter, and when system changes or organization-defined events require it — including training on recognizing and reporting indicators of insider threat, social engineering, and social mining — and updating the training content on an organization-defined frequency and following organization-defined events (aligned to SP 800-53 AT-2 with enhancements).

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Everyone who touches your systems gets awareness training when they start, on a recurring schedule, and when something changes — and the content must actually cover spotting and reporting insider-threat indicators and social engineering, because those topics now live inside this requirement rather than beside it. The trap for a small contractor is the recycled generic module: if it never mentions insider threat, social engineering, or your CUI rules, it does not cover what is now asked.

Across revisions

Consolidates Rev. 2's general awareness requirement (3.2.1) and its standalone insider-threat awareness requirement (3.2.3) into a single literacy-training requirement; insider-threat, social-engineering, and social-mining recognition become named content within it, and content-update expectations are explicit and parameterized.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportModerate confidence

Why: A workforce readiness program that trains people on a rhythm and updates content as the threat picture changes is the operating engine this requirement's literacy training runs on — the cadence, the triggers, and the records are shared machinery.

What this does not claim: The requirement names its content: recognizing and reporting insider-threat indicators, social engineering, and social mining, delivered to all system users. The practice centers on technical-staff readiness; unless the general-user curriculum actually carries those named topics, the relationship is partial rather than direct. Coverage of every user population — not just the technical team — must also be demonstrable.

Practice-side activities
  • Extend the readiness rhythm to all-user literacy training, not only technical roles
  • Add insider-threat, social-engineering, and social-mining recognition to the curriculum and date the update
  • Track completion for every system user
Evidence this produces
  • Curriculum showing the required topics with an update history
  • All-user completion records on the defined cadence

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Check the curriculum against the requirement's named topics — insider threat, social engineering, social mining — and close the content gap before polishing delivery.
  • Trigger training on events, not just the calendar: a new phishing technique hitting the sector, a near-miss, a major system change.
  • Track completion per person; awareness training is only demonstrable through records.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Training content showing the required topics, with a dated update history
  • Completion records tying every system user to initial and recurring training

Suggested owners, derived from the mapped practices and artifacts: Executive sponsor · Executive sponsor or HR lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated