NIST SP 800-53 Revision 5 · Contingency Planning
Quick-reference card
| Field | Value |
|---|---|
| Control ID | CP-03 |
| Control Name | Contingency Training |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Contingency Planning |
| Baselines | LOW MODERATE HIGH |
| Implementation Level | Organization |
| Relevance | First Party and Third Party |
| Risk Severity | Medium |
What this control requires
CP-03 requires organizations to train every system user on their contingency role before they’re expected to perform it. Training must happen within an organization-defined time period of someone assuming a contingency responsibility, again whenever system changes affect those responsibilities, and on a recurring schedule after that.
The requirement goes beyond a one-time onboarding module. Different roles need different depth: a general user might only need to know where to report and whether their daily work shifts during a disruption. A system administrator needs hands-on practice standing up services at an alternate processing site. An executive needs to understand how to maintain mission-essential functions from a remote location and coordinate with external agencies. Training content must mirror the specific continuity requirements in your contingency plan, not a generic slide deck.
Organizations must also review and update training content at a defined frequency and after specific events — including contingency plan tests, actual incidents, audit findings, or regulatory changes. Participating in a contingency plan exercise, including the lessons learned session that follows, can count as training at the organization’s discretion.
Why it matters
Most organizations treat contingency training as a compliance checkbox — an annual slide deck that staff click through without absorbing. The gap between that approach and what CP-03 actually demands is where operational risk accumulates. When a disruption hits and people don’t know their role, recovery timelines stretch from hours to days.
The problem compounds in environments with high staff turnover or frequent system changes. A sysadmin who joined six months ago and never received contingency training doesn’t know how to bring services back online at a failover site. A department head who wasn’t briefed on communication protocols can’t coordinate with the agencies that need to know about the outage. These gaps aren’t theoretical — they’re the patterns that turn a manageable disruption into an extended outage.
Failure to maintain this control introduces audit risk across every baseline tier. Because CP-03 appears in LOW, MODERATE, and HIGH baselines, assessors check it regardless of system categorization. Organizations that reduce cybersecurity risk proactively find that contingency training is one of the most cost-effective controls to sustain, requiring process discipline rather than expensive tooling.
What untrained staff get wrong
- Reporting locations and chains of command — staff default to normal routines instead of contingency roles
- Alternate site procedures — administrators attempt to rebuild production instead of following documented failover steps
- Communication protocols — teams use unauthorized channels, delaying coordination with external entities
- Data handling during disruption — users bypass security controls under pressure, creating secondary incidents
- Recovery priority — staff restore low-priority services first because they don’t know the restoration sequence
How to implement
The most common failure mode for CP-03 isn’t the absence of training — it’s training that doesn’t reflect actual contingency roles. Organizations build a generic business continuity awareness module and call it done, then discover during an exercise that nobody knows what to do.
For your organization
1. Map roles to training tiers. Start with your contingency plan’s roles-and-responsibilities section. Create at least three training tiers: general awareness (all users), technical recovery (system administrators and IT operations), and leadership coordination (executives and contingency plan coordinators). Each tier gets content matched to what they’ll actually do during a disruption.
2. Define training triggers and frequency. Set your organization-defined parameters: time period for initial training after role assignment (common choices are 30, 60, or 90 days), recurring frequency (annually is the minimum most assessors accept), and the events that trigger content review — at a minimum, after every contingency plan test, after any actual contingency activation, after audit findings, and after significant system changes.
3. Build role-specific content. General users need: where to report, who to contact, what changes to their daily work, and how long the disruption may last. Technical staff need: alternate site activation procedures, system restoration sequences, backup verification, and communication with vendors. Leaders need: mission-essential function priorities, external coordination protocols, and delegation of authority chains.
4. Integrate with exercises. Use contingency plan tests (CP-04) as live training opportunities. A tabletop exercise where staff walk through their roles counts as training when you include a structured lessons-learned session. Document attendance and observations.
5. Track and maintain records. Use a learning management system or equivalent to record who completed which tier, when, and what version of the content they received. Auditors will ask for these records by name.
Common mistakes:
- Using the same training for all roles regardless of contingency responsibilities
- Training only IT staff and skipping business unit leaders
- Never updating content after plan revisions or exercise lessons learned
- Relying on a single annual session with no reinforcement
For your vendors
When assessing a vendor’s CP-03 compliance, you’re checking whether their staff actually know what to do during a disruption — not just whether a training policy exists on paper.
What to ask in a security questionnaire:
- Does your organization provide role-based contingency training to all personnel with continuity responsibilities?
- How quickly after assuming a contingency role does a new employee receive training?
- How often is contingency training conducted, and when was the last session?
- Do you update training content after contingency plan tests, actual incidents, or audit findings?
- Can you provide evidence of training completion records?
What evidence to request:
- Contingency training policy with defined frequency and triggers
- Training completion records showing dates, attendees, and role-based content
- Training curriculum or syllabus demonstrating role-specific content differentiation
- Evidence of content updates following exercises or incidents
Red flags:
- No distinction between general security awareness and contingency-specific training
- Training records that show 100% completion on the same date annually (suggests a checkbox exercise, not meaningful training)
- No evidence of content updates in over 12 months despite documented plan changes
- Training content that doesn’t reference the vendor’s actual contingency plan
A vendor risk management program should verify that contingency training goes beyond policy — ask to see a sample of training materials and compare them to the vendor’s contingency plan for consistency.
Evidence examples
Auditors pull from both the contingency planning policy documentation and live training records when evaluating CP-03. Organizations managing supply chain cybersecurity programs find that maintaining structured training evidence for both internal teams and vendor oversight simplifies the audit process.
| Evidence Type | Example Artifact |
|---|---|
| Contingency training policy | Policy document defining training tiers, frequency, triggers for content review, and roles responsible for delivery |
| Training curriculum | Role-specific training outlines for general users, technical recovery staff, and leadership covering contingency plan procedures |
| Training completion records | LMS exports or sign-in sheets showing attendee names, dates, role-based module completed, and content version |
| Contingency plan (training sections) | Sections of the contingency plan defining roles, responsibilities, and restoration priorities that training must cover |
| Content review log | Documented review and update history showing dates, triggering events (exercises, incidents, audit findings), and changes made |
| Exercise participation records | After-action reports from contingency plan tests listing participants who received training credit per CP-03a discretionary provision |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 6.3 Information security awareness, education and training | Partial |
ISO 27001 Control 6.3 addresses security awareness and training broadly, covering all personnel who need to understand security policies. CP-03 is narrower — it specifically targets contingency roles and responsibilities, requiring training tailored to each person’s continuity duties. The ISO control partially covers CP-03’s intent but doesn’t mandate the role-specific, event-triggered training cadence that NIST requires.
Related controls
- AT-02 — Literacy Training and Awareness: Provides the baseline security awareness program that CP-03’s contingency-specific training builds upon.
- AT-03 — Role-based Training: Covers role-specific security training broadly; CP-03 narrows this to contingency roles specifically.
- AT-04 — Training Records: Defines the recordkeeping requirements that apply to contingency training completion evidence.
- CP-02 — Contingency Plan: The plan itself — CP-03 training content must reflect the roles, priorities, and procedures documented here.
- CP-04 — Contingency Plan Testing: Exercises that can double as training opportunities under CP-03’s discretionary provision; findings from tests trigger content updates.
- CP-08 — Telecommunications Services: Contingency training should cover alternate communication procedures, which depend on the telecommunications services documented under CP-08.
- IR-02 — Incident Response Training: Parallel training requirement for incident response roles; organizations often coordinate IR-02 and CP-03 delivery schedules.
- IR-04 — Incident Handling: Actual incidents generate lessons learned that trigger CP-03 content reviews and may reveal training gaps.
- IR-09 — Information Spillage Response: Specialized incident response training that may overlap with contingency scenarios involving data exposure during disruptions.
Frequently asked questions
What is NIST SP 800-53 CP-03?
CP-03 requires organizations to provide role-specific contingency training to every system user who has a continuity responsibility, on a defined schedule and whenever system changes or triggering events occur. The control ensures that when a disruption happens, people know their specific duties — from general users who need to know where to report, to system administrators who must activate alternate processing sites, to executives who coordinate mission-essential functions offsite. Training content must be reviewed and updated regularly, especially after contingency plan tests, actual incidents, or changes in regulatory requirements.
What happens if CP-03 is not implemented?
Organizations that skip contingency training face two immediate risks: failed audits and failed recoveries. A robust NIST-aligned supply chain risk program means nothing if the people responsible for executing contingency procedures have never practiced. Because CP-03 is required at every baseline tier — LOW, MODERATE, and HIGH — assessors evaluate it regardless of system categorization. A finding against CP-03 signals a systemic gap in the contingency planning program. Operationally, untrained staff extend recovery times by defaulting to improvisation instead of following documented procedures, restoring services in the wrong order, or failing to coordinate with external stakeholders who depend on timely communication.
How do you audit CP-03?
Auditors assess CP-03 by examining contingency training policies, reviewing training completion records with dates and role-based module identifiers, interviewing personnel with contingency responsibilities about their duties, and testing whether training content reflects the current contingency plan. They specifically check that initial training occurred within the organization-defined time period of role assumption, that recurring training follows the defined frequency, that content was updated after triggering events like plan tests or incidents, and that different roles received appropriately scoped material — not a one-size-fits-all awareness module.
How often should contingency training be conducted?
The frequency is organization-defined, but most federal agencies and compliance programs set annual recurrence as the minimum acceptable cadence. The more important timing requirements are the triggers: training must occur within a defined window of assuming a contingency role, whenever system changes affect contingency procedures, and after events like plan tests, actual disruptions, audit findings, or regulatory changes. Organizations with high turnover or frequent system changes often train more frequently than annually to keep contingency knowledge current across all role tiers.