AWS Shared Responsibility: Ultimate Guide for CMMC Teams (AT.L2-3.2.1)

AWS Shared Responsibility: Ultimate Guide for CMMC Teams (AT.L2-3.2.1)

Use this aws shared responsibility cmmc security awareness guide to map AT.L2-3.2.1 risks, responsibilities, policies, training, and evidence.

LakeRidge Team
July 18, 2026
10 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

An aws shared responsibility cmmc security awareness guide for AT.L2-3.2.1 should teach managers, administrators, and users which security responsibilities AWS performs, which responsibilities remain with your company, and how their daily actions can protect or expose CUI. For CMMC 2.0 Level 2, your evidence must show that personnel understand relevant risks and the policies, standards, and procedures governing the AWS systems they use. AWS compliance reports and security features help, but they do not satisfy the awareness requirement on your behalf.

What does CMMC AT.L2-3.2.1 require?

NIST SP 800-171 Rev. 2 practice AT.L2-3.2.1 requires an organization to ensure that managers, system administrators, and users are made aware of security risks associated with their activities and of applicable security policies, standards, and procedures. The practice applies to organizational systems that process, store, or transmit CUI, including AWS-hosted workloads and the endpoints used to access them.

For an ISSO or FSO, the practical question is not whether employees completed a generic annual cybersecurity course. You need to be able to show that people who interact with your AWS environment understand the risks relevant to their access and know which internal rules govern their work.

  • Security risks are identified: Personnel understand risks such as phishing, credential theft, public cloud storage exposure, improper CUI sharing, weak MFA practices, and unapproved data transfers.
  • Security documentation is identified: Personnel know where to find and how to use the company’s security policies, AWS access procedures, incident reporting process, CUI handling rules, and acceptable use requirements.
  • Managers are included: Supervisors and project managers understand their role in approving access, identifying workforce changes, and escalating suspected security events.
  • System administrators are included: Administrators understand risks associated with privileged AWS access, IAM changes, logging, backups, and configuration errors.
  • Users are included: General users understand secure authentication, CUI handling, approved collaboration methods, and how to report suspicious activity.

How does AWS shared responsibility affect CMMC awareness training?

AWS operates under a shared responsibility model: AWS is responsible for security of the cloud, while your organization is responsible for security in the cloud. Your awareness content must make this distinction understandable to nontechnical users and precise enough for administrators and managers.

AWS protects the physical facilities, hardware, networking infrastructure, and virtualization layers that support AWS services. Your company remains responsible for identities, access permissions, data classification, data handling, endpoint security, cloud configuration, encryption choices, monitoring decisions, and employee behavior.

Area AWS responsibility Your organization’s awareness responsibility
Physical data centers Facility access, power, environmental controls, hardware disposal Explain that AWS facility controls do not authorize employees to place CUI in any AWS service.
Identity and access Availability of IAM, IAM Identity Center, and MFA capabilities Teach users to protect MFA methods and passwords; teach admins least privilege, role review, and access removal procedures.
S3 data storage Underlying service infrastructure Teach owners not to create public buckets, not to share presigned URLs improperly, and to follow approved CUI storage procedures.
EC2 workloads Host hardware and hypervisor security Teach administrators patching, security group review, hardened AMIs, logging, and incident escalation procedures.
Cloud logging CloudTrail and CloudWatch service operation Teach administrators where logs are retained, who reviews alerts, and how to preserve evidence during an incident.

This boundary is central to an AWS shared responsibility CMMC awareness program. A statement such as “AWS is FedRAMP authorized” is not a substitute for explaining what employees must do to protect CUI within the company’s authorized AWS architecture.

Which AWS-related risks should employees understand?

Awareness topics should be relevant to the employee’s activities, not merely a list of cloud service names. Build training around the actions that could cause unauthorized disclosure, loss of availability, or compromise of CUI.

  • Phishing messages that imitate AWS, Microsoft 365, a supplier portal, or an internal IT request.
  • MFA fatigue attacks and the risk of approving unexpected push notifications.
  • Sharing CUI through personal email, personal cloud drives, unapproved file-transfer sites, or consumer AI tools.
  • Using an unapproved device or browser session to access AWS-hosted CUI.
  • Uploading technical files to the wrong S3 bucket, Teams site, or external collaboration workspace.
  • Making a storage bucket, snapshot, security group, or application endpoint publicly accessible.
  • Creating long-lived IAM access keys when an approved role or IAM Identity Center access method is available.
  • Failing to report a lost device, misdirected email, suspicious login prompt, or suspected account compromise immediately.

For example, Northstar Printed Electronics, a 64-person PCB and electronics manufacturer, stores controlled fabrication packages, revision-controlled drawings, and customer purchase data in an AWS environment. Its engineers use AWS Client VPN and Amazon WorkSpaces to review manufacturing files; its production managers approve access for new programs. Their awareness training should address the risk of sending a Gerber package to an external fabricator without using the approved encrypted transfer process, as well as the risk of approving access for a former project engineer whose program assignment has ended.

Which policies, standards, and procedures must people be aware of?

AT.L2-3.2.1 does not require every employee to memorize every policy. It does require that affected people are made aware of the rules applicable to the systems and activities they perform. Make your documentation available in a controlled location and cite its title, version, and acknowledgement requirement in training records.

For AWS-supported CUI operations, most small contractors need awareness of the following documents:

  • CUI Handling and Marking Policy
  • Information Security Awareness and Training Policy
  • Acceptable Use Policy
  • Access Control Policy and user access request procedure
  • Identity and MFA standard for AWS and corporate applications
  • AWS Cloud Security Standard, including approved services and account boundaries
  • Incident Response Plan and incident reporting procedure
  • Media Protection and secure data transfer procedure
  • Remote Access and mobile device procedure
  • Change management procedure for AWS administrators

Give employees a short, usable answer to “what do I do?” For example: report suspected phishing to the security mailbox or ticket queue; notify the ISSO immediately when CUI is sent to an unintended recipient; request AWS access through the approved workflow; and never create a new cloud storage location for CUI without authorization.

Who needs awareness training and how should it differ by audience?

All managers, system administrators, and users of in-scope systems must receive awareness training, but their examples and acknowledgements should reflect their responsibilities. This is still awareness training, not the role-based skills training required separately by AT.L2-3.2.2.

Audience Awareness emphasis Useful evidence
General users CUI handling, phishing, MFA, approved storage, incident reporting Training completion, quiz results, policy acknowledgement, phishing campaign results
Managers and program leads Access approval, personnel changes, supplier sharing, escalation expectations Manager briefing attendance, acknowledgement, access review records
AWS administrators Privileged account risk, IAM changes, CloudTrail, misconfiguration reporting, change procedures Administrator awareness module completion, acknowledgement, meeting records
Temporary staff and subcontractors Restricted access, CUI boundaries, reporting channels, approved systems Onboarding record, signed rules of behavior, sponsor confirmation

How do you implement this AWS shared responsibility CMMC security awareness guide?

  1. Define the in-scope AWS environment. Document AWS accounts, regions, services, user groups, endpoints, and external systems that process, store, or transmit CUI. Your system security plan should align with this scope.
  2. Identify audience groups. Export user and administrator lists from IAM Identity Center, AWS IAM where applicable, HR onboarding records, and contractor rosters. Include managers who approve access or oversee CUI work.
  3. Create a responsibility matrix. Map AWS responsibilities and company responsibilities for each material service, such as Amazon S3, EC2, WorkSpaces, RDS, CloudTrail, and AWS Backup.
  4. Develop awareness content. Use a general module for all personnel, then add short AWS-specific modules for administrators, managers, and CUI users. Include your actual policy names, reporting address, ticket workflow, and approved file-sharing method.
  5. Deliver training before access and at least annually. Require initial training during onboarding or before granting access to CUI systems. Establish an annual cadence and issue event-driven reminders after phishing campaigns, policy changes, or material AWS architecture changes.
  6. Use reinforcement activities. Send periodic security advisories, conduct simulated phishing, review short case studies during staff meetings, and post reminders in approved collaboration channels.
  7. Collect durable evidence. Retain completion dates, course content, attendee names, quiz results, signed acknowledgements, campaign reports, and copies of advisories. Record exceptions and corrective follow-up.
  8. Review effectiveness. At least annually, assess whether phishing reporting, help-desk tickets, audit findings, and incident lessons show that the training needs revision.

At Northstar Printed Electronics, the ISSO could run a quarterly 15-minute awareness briefing after reviewing AWS CloudTrail alerts and support tickets. One session might cover an engineer’s attempted upload of a controlled assembly drawing to a personal file-sharing account; the lesson is not to shame the employee, but to reinforce the approved encrypted transfer procedure and reporting expectation.

What is the AT.L2-3.2.1 compliance checklist for AWS environments?

  • Confirm the AWS systems and user populations that are within the CUI boundary.
  • Document cloud-specific risks that managers, administrators, and users can create through their activities.
  • Document AWS shared responsibility boundaries in the SSP, cloud security standard, or supporting responsibility matrix.
  • Identify the policies, standards, and procedures applicable to each audience.
  • Provide initial awareness training before or upon granting access to in-scope systems.
  • Provide recurring awareness training at least annually and when significant changes occur.
  • Include phishing, MFA, CUI handling, approved storage, incident reporting, and cloud-sharing risks in general content.
  • Provide AWS administration awareness content for privileged users without treating it as a replacement for role-based training.
  • Use acknowledgements or assessments to confirm personnel received and understood applicable requirements.
  • Retain training rosters, course materials, notices, campaign results, and policy acknowledgements.
  • Track overdue training and remove or suspend access according to your documented process when necessary.
  • Review program effectiveness and update content based on incidents, findings, system changes, and policy revisions.

Frequently asked questions about AWS awareness and AT.L2-3.2.1

Does AWS security training satisfy CMMC AT.L2-3.2.1?

No. AWS training may support your program, but it does not demonstrate that your people understand your organization’s CUI rules, approved AWS architecture, internal procedures, or incident reporting process. Supplement vendor content with company-specific awareness material and retain evidence of completion.

What evidence will a CMMC assessor expect for AT.L2-3.2.1?

Expect to provide awareness policies, training content, completion reports, attendance rosters, acknowledgements, phishing or advisory records, and interviews with personnel. The assessor may ask users how they report a suspected incident or where they may store CUI, so evidence and actual employee knowledge must match.

Is annual security awareness training enough for AWS users?

Annual training is a baseline, not necessarily sufficient by itself. Use event-driven notices when you change AWS access methods, adopt a new CUI workflow, identify a phishing trend, or experience a security incident. Regular reinforcement makes the program more credible and effective.

Do AWS administrators need separate CMMC awareness training?

They need awareness training like everyone else, with examples relevant to privileged cloud activity. They will also usually need separate role-based training under AT.L2-3.2.2 for the skills required to administer IAM, logging, networking, patching, and other technical controls.

Can simulated phishing count toward CMMC security awareness?

Yes. Simulated phishing is specifically consistent with awareness techniques, provided it supports rather than replaces your core training. Keep campaign metrics, follow-up communications, and remediation records as evidence of ongoing reinforcement.

Next step: Have your ISSO, FSO, and AWS administrator review the current training package together and add one documented cloud shared-responsibility module before the next access review cycle.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.