What Is a Security Awareness RACI Matrix? (AT.L2-3.2.1)

What Is a Security Awareness RACI Matrix? (AT.L2-3.2.1)

A security awareness RACI matrix assigns ownership for CMMC AT.L2-3.2.1 training, policies, records, and leadership oversight.

LakeRidge Team
July 18, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

A security awareness RACI matrix assigns who is Responsible, Accountable, Consulted, and Informed for meeting NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice AT.L2-3.2.1. It prevents a common small-business failure: everyone assumes awareness training, policy communication, and proof of completion are someone else’s job. Even without dedicated security staff, you can assign these duties to existing people or outside providers while keeping one leader accountable.

AT.L2-3.2.1 requires managers, system administrators, and system users to understand the security risks tied to their activities and the policies, standards, and procedures that protect organizational systems. For a company handling CUI, that means more than sending an annual phishing video. You need clear ownership for identifying relevant risks, communicating rules, delivering awareness activities, tracking participation, and responding when people do not complete required training.

Why does a security awareness RACI matrix prevent control gaps?

RACI is a decision-rights model. Responsible means the person doing the work. Accountable means the person who owns the result and approves decisions; there should normally be one per activity. Consulted means the person whose input is needed before action is taken. Informed means the person who receives updates but does not perform or approve the work.

For AT.L2-3.2.1, control gaps usually occur at the handoffs. IT may know which systems process CUI but not know who must receive notices. HR may distribute onboarding materials but not know which security policies changed. Leadership may approve a training platform but never receive evidence that administrators or managers actually completed awareness activities. Legal may maintain contract obligations without being asked whether a policy notice addresses customer or regulatory requirements.

A RACI matrix turns these vague assumptions into an operating agreement. It also helps an SMB owner distinguish general awareness from role-based training. This control covers broad awareness intended to influence secure behavior, such as phishing simulations, CUI-handling reminders, policy acknowledgments, and incident-reporting notices. Job-specific training for an administrator or security role belongs primarily under AT.L2-3.2.2, not this practice.

What does a full RACI matrix for AT.L2-3.2.1 look like?

In a small business, “Security” does not have to mean a full-time employee. It can be the owner, an IT manager acting as security coordinator, a virtual CISO, or an MSP security lead. The important point is to name a person or contracted role, not a department that does not exist.

AT.L2-3.2.1 Activity IT Security / vCISO HR Legal Leadership
Identify organizational activities and systems that create security risk, including CUI workflows C R I C A
Identify applicable security policies, standards, and procedures to communicate C R C C A
Approve the annual awareness plan, audience groups, and delivery schedule C R C C A
Configure training platform groups, email delivery, and administrator access R A C I I
Assign and track new-hire awareness training and policy acknowledgments I A R C I
Deliver phishing simulations, security reminders, and periodic awareness notices C A/R C C I
Communicate material policy, standard, or procedure changes to affected personnel C R C C A
Escalate overdue training and repeated noncompletion to managers I A R I C
Maintain completion reports, acknowledgments, campaign records, and exception evidence C A R I I
Review effectiveness, exceptions, and corrective actions with management C R C C A

The matrix gives leadership a deliberate role without making the owner personally send every reminder. Leadership is accountable for ensuring the program exists, has adequate resources, and resolves persistent noncompliance. Security coordinates the control, IT enables the systems and communications, HR connects training to onboarding and personnel records, and legal checks whether notices and policy wording align with contractual, privacy, employment, and CUI-related obligations.

If one person fills several columns, keep the RACI logic anyway. For example, an owner may be both Leadership and Security coordinator, but should document which decisions they make as the accountable executive and which tasks they perform as the security operator. That separation makes audits, vacations, and provider transitions easier to manage.

How should the RACI change in small, outsourced, or federated organizations?

What if your company has fewer than 25 employees?

Combine roles, but do not eliminate accountability. A practical arrangement is for the owner or operations director to be Accountable, an IT manager or trusted consultant to be Responsible for security coordination, and the office manager or HR generalist to be Responsible for assignment tracking. If there is no formal legal department, use outside counsel as Consulted when policies, customer terms, export issues, or employment consequences are involved.

Do not assign “all employees” as Responsible for the awareness program. Employees are responsible for completing assigned activities and following procedures, but a named role must own the program, evidence, and escalation process.

What if an MSP manages IT and security tools?

An MSP can be Responsible for configuring KnowBe4, Microsoft 365 phishing protections, or a learning platform, and it may be Consulted on current threats. However, the MSP should not automatically become Accountable for your compliance outcome. Your company’s leadership remains accountable for whether its people receive awareness communications and whether records demonstrate completion.

Put the assignment in the managed services agreement or a security addendum. Specify who creates campaign content, who approves messages, who receives overdue-user reports, how quickly the MSP must report platform failures, and where training records will be stored if the contract ends.

What if business units operate independently?

In a federated organization, central security should usually be Accountable for the baseline awareness program and evidence format, while each business-unit leader is Responsible for making local employees complete assigned activities. HR can maintain one authoritative roster, but business units must promptly report transfers, contractors, leaves, and separations. This avoids training reports that show a person as complete after they moved into a role with different CUI exposure.

How do you operationalize the security awareness RACI matrix in a ticketing tool?

A spreadsheet is useful for defining ownership, but a ticketing tool proves that work occurred and exposes stalled handoffs. For an SMB, Jira Service Management, HaloITSM, Freshservice, or ServiceNow can work. Choose the tool your IT and HR teams will actually use rather than buying a platform solely for this control.

Create a recurring ticket type called Security Awareness Program Cycle in a project such as SEC. The parent ticket should represent the quarterly or annual program cycle. Create linked subtasks for risk review, policy review, campaign delivery, completion tracking, management reporting, and evidence retention. Assign each item according to the RACI—not merely to the person who opened the ticket.

Jira Service Management configuration

Project: SEC
Issue type: Security Awareness Program Cycle
Automation schedule: First business day of each quarter

Required fields:
- Control ID: AT.L2-3.2.1
- Program owner: Security / vCISO
- Accountable executive: Owner or COO
- Audience: Managers | Administrators | Users | Contractors
- CUI-related risk addressed
- Policies/procedures communicated
- Delivery method: KnowBe4 | Microsoft 365 email | live session
- Due date
- Evidence link: SharePoint compliance library
- Exception approval and expiration date

Workflow:
Draft -> Security Review -> Leadership Approval -> Delivered ->
Completion Tracking -> Evidence Verified -> Closed

Escalation rule:
If completion is below 95% at due date, notify HR and the accountable executive.
If any administrator is overdue by 14 days, create a linked corrective-action ticket.

Keep evidence links in the ticket rather than attaching sensitive records directly when possible. For example, link to a restricted SharePoint or Google Drive compliance folder containing the campaign message, training roster, completion export, policy acknowledgment report, phishing simulation summary, and meeting minutes. Do not put CUI into ticket descriptions merely to explain why a user needs training.

The ticket should also document decisions. If legal recommends a revised remote-work notice, record the review date and resulting action. If leadership accepts a temporary exception for an employee on leave, record the approver, reason, alternative arrangement, and expiration date. That evidence shows an assessor that your process is managed rather than accidental.

How often should you review awareness RACI assignments?

Review the RACI matrix at least annually and whenever a meaningful organizational change occurs: a new MSP contract, leadership transition, merger, new CUI-bearing contract, major system migration, policy rewrite, or change in HR onboarding software. A yearly review confirms that named people still hold the roles assigned to them and that the tools, policies, and training audiences remain accurate.

Run the awareness program itself more frequently than the annual RACI review. Many SMBs use quarterly awareness communications, monthly or quarterly phishing simulations, onboarding assignments within the first week of employment, and immediate notices after a material policy or procedure change. Review completion and exceptions monthly, then provide leadership a quarterly summary of participation, phishing trends, overdue users, policy updates, and corrective actions.

For CMMC Level 2 readiness, retain the current matrix and prior versions that demonstrate who owned the control during the assessment period. Pair it with evidence that managers, system administrators, and users were actually made aware of risks and applicable rules. A perfect chart without completion records will not establish implementation; complete records without clear ownership will be difficult to sustain.

Next step: Name one accountable executive and one security program owner this week, then load the matrix’s first quarterly awareness cycle into the ticketing tool you already use.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.