Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.02.02OFFICIAL TITLEPENDING NIST SME REVIEW

03.02.02Role-Based Training

03.02 Awareness and Training · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires providing role-based security training to personnel before authorizing access to the system or CUI and before they perform assigned duties, on an organization-defined frequency thereafter, and when required by system changes — and updating the training content on an organization-defined frequency and following organization-defined events (aligned to SP 800-53 AT-3).

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

People with security-relevant duties — administrators, developers, whoever runs backups or triages incidents — get training matched to that duty, before they start doing it and on a refresh cycle. In a small shop this is rarely courseware for its own sake: vendor training on the actual firewall, identity platform, and EDR in use counts, provided you can show who took what and when.

Across revisions

Substantively carried forward from 3.2.2, with the timing made explicit — training before access and duties — and content-update parameters added.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: Role-based training is the practice's core substance: mapping security-relevant roles to required competencies, training before duties begin, and refreshing as the stack changes is what both the practice and the requirement describe.

What this does not claim: The requirement covers everyone with security-relevant duties, including non-technical roles — the person who approves accounts, the office manager who handles visitor access — and outsourced ones; a program scoped only to the IT team leaves those populations unaddressed. Timing matters too: training must precede access and duties, which a catch-up program does not demonstrate.

Practice-side activities
  • Maintain the role-to-competency matrix, including MSP and non-technical security duties
  • Gate new duty assignments on completion of the role's training
  • Refresh role training when platforms change
Evidence this produces
  • The role-to-training matrix
  • Completion records aligned to role assignment dates

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • List the security-relevant roles first — including the MSP's, contractually — then define what training each requires.
  • Sequence training before access: it is a gate to duties, not an eventual nicety.
  • Refresh when the stack changes; a new security platform with exactly one trained operator is both a readiness gap and a coverage gap.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The role-to-training matrix with the defined refresh frequency
  • Per-person completion records tied to role assignment dates

Suggested owners, derived from the mapped practices and artifacts: Executive sponsor · Executive sponsor or HR lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated