Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Awareness and Training (AT)

Awareness and Training (AT)

CMMC Awareness and Training (AT) Requirements

Awareness and Training is the smallest control family in CMMC Level 2, containing just 3 requirements. Do not let the small number fool you—these controls are foundational. Your employees are your first line of defense against cyber threats, and untrained staff create significant security risks.

Awareness and Training means ensuring your workforce understands security threats and knows how to protect sensitive information.

Most successful cyberattacks exploit human error: clicking phishing links, using weak passwords, or mishandling sensitive data. Training prevents these mistakes.

Why Awareness and Training Matters for CMMC

The Department of Defense requires Awareness and Training because technology alone cannot protect Controlled Unclassified Information (CUI). People make decisions every day that affect security:

  • Should I click this email link?
  • Can I share this file with this person?
  • Is this request legitimate?
  • How should I handle this technical drawing?

Without training, employees guess at these answers and often guess wrong. With training, they recognize threats and follow proper procedures.

CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.

The 3 Awareness and Training Requirements

AT.L2-3.2.1: Security Awareness Training

“Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.”

This requirement means everyone in your organization who uses systems containing CUI must understand:

  • What security threats exist (phishing, malware, social engineering)
  • What policies your company has for protecting information
  • What procedures they must follow
  • What risks their specific activities create

Training must be role-appropriate. A system administrator needs deeper technical training than a general office worker, but everyone needs baseline security awareness.

AT.L2-3.2.2: Role-Based Training

“Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.”

This requirement goes beyond general awareness to job-specific security training:

  • System administrators need training on secure configuration
  • Users handling CUI need training on proper handling procedures
  • Incident responders need training on response procedures
  • Managers need training on their oversight responsibilities

If someone has security responsibilities in their job, they need training specific to those duties.

AT.L2-3.2.3: Insider Threat Awareness

“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”

This requirement specifically addresses threats from people inside your organization—employees, contractors, or partners who might intentionally or accidentally compromise security.

Insider threat means security risks posed by people within the organization who have legitimate access but misuse it or are compromised by external actors.

Training must cover:

  • What insider threats look like (unusual data access, policy violations, behavioral changes)
  • How to report concerns appropriately
  • That insider threats are often unintentional, not malicious

Implementing Awareness and Training

Initial Training

Provide security awareness training when employees join your organization and before they access systems containing CUI. Cover:

  • Overview of security threats (phishing, social engineering, malware)
  • Your company’s security policies
  • Proper handling of CUI
  • Password requirements and practices
  • Incident reporting procedures
  • Acceptable use of company systems

Annual Refresher Training

Conduct training at least annually to reinforce concepts and address new threats. Annual training should:

  • Review core security concepts
  • Cover new or evolving threats
  • Address any incidents or near-misses from the past year
  • Remind employees of their responsibilities

Role-Based Training

Provide additional training based on job functions:

  • IT Staff: Secure configuration, patch management, access control administration
  • CUI Handlers: Proper marking, storage, transmission, and destruction of CUI
  • Managers: Security oversight responsibilities, incident escalation
  • All Staff: Phishing recognition, password hygiene, physical security

Insider Threat Training

Include insider threat awareness in your training program:

  • Explain what insider threats are and why they matter
  • Describe indicators that might suggest insider threat activity
  • Provide clear reporting channels for concerns
  • Emphasize that reporting protects everyone, including the person being reported

Documenting Your Training Program

CMMC assessors will verify that training actually occurred. Maintain documentation including:

Training Materials

  • Course content or curriculum
  • Slides, videos, or other materials used
  • Quizzes or assessments

Training Records

  • Attendance records showing who completed what training
  • Dates training was completed
  • Acknowledgment signatures
  • Quiz or assessment scores

Training Schedule

  • When initial training occurs (new hire onboarding)
  • Frequency of refresher training (at least annual)
  • Role-based training assignments

Training Options for Small Businesses

Small businesses can deliver effective training without large budgets:

Online Training Platforms

Many vendors offer affordable online security awareness training:

  • Self-paced modules that employees complete independently
  • Automated tracking and reporting
  • Regular content updates for new threats
  • Phishing simulation capabilities

Costs typically range from $20-50 per user annually.

In-House Training

Develop your own training using free resources:

  • CISA (Cybersecurity and Infrastructure Security Agency) free training materials
  • NIST resources and guidelines
  • Vendor-provided security awareness content

Lunch and Learn Sessions

Brief, regular training sessions can be effective:

  • 15-30 minute monthly sessions
  • Cover one topic per session
  • Include real examples and discussion
  • Document attendance

Common Awareness and Training Mistakes

Mistake 1: One-and-Done Training

Providing training once without refreshers does not meet requirements. Training must be ongoing, at least annually.

Mistake 2: Generic Training Only

Role-based training is specifically required. General awareness training alone is insufficient for people with security responsibilities.

Mistake 3: No Documentation

Training that is not documented cannot be proven to assessors. Keep detailed records of who completed what training and when.

Mistake 4: Skipping Insider Threat

Insider threat training is a specific requirement, not optional. Ensure your program explicitly addresses this topic.

Key Takeaways

Awareness and Training contains only 3 requirements but establishes the human foundation for security. All users need general security awareness training, personnel with security duties need role-specific training, and everyone needs insider threat awareness.

Train employees when they join, refresh training annually, and document everything. Small businesses can meet these requirements affordably through online platforms or in-house programs.


Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” specifically the Awareness and Training family (Section 3.2), and the DoD CMMC Level 2 Assessment Guide.


Need help building your CMMC training program? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Tags:
Table of Contents