Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Awareness and Training (AT)
Awareness and Training (AT)
CMMC Awareness and Training (AT) Requirements
Awareness and Training is the smallest control family in CMMC Level 2, containing just 3 requirements. Do not let the small number fool you—these controls are foundational. Your employees are your first line of defense against cyber threats, and untrained staff create significant security risks.
Awareness and Training means ensuring your workforce understands security threats and knows how to protect sensitive information.
Most successful cyberattacks exploit human error: clicking phishing links, using weak passwords, or mishandling sensitive data. Training prevents these mistakes.
Why Awareness and Training Matters for CMMC
The Department of Defense requires Awareness and Training because technology alone cannot protect Controlled Unclassified Information (CUI). People make decisions every day that affect security:
- Should I click this email link?
- Can I share this file with this person?
- Is this request legitimate?
- How should I handle this technical drawing?
Without training, employees guess at these answers and often guess wrong. With training, they recognize threats and follow proper procedures.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
The 3 Awareness and Training Requirements
AT.L2-3.2.1: Security Awareness Training
“Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.”
This requirement means everyone in your organization who uses systems containing CUI must understand:
- What security threats exist (phishing, malware, social engineering)
- What policies your company has for protecting information
- What procedures they must follow
- What risks their specific activities create
Training must be role-appropriate. A system administrator needs deeper technical training than a general office worker, but everyone needs baseline security awareness.
AT.L2-3.2.2: Role-Based Training
“Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.”
This requirement goes beyond general awareness to job-specific security training:
- System administrators need training on secure configuration
- Users handling CUI need training on proper handling procedures
- Incident responders need training on response procedures
- Managers need training on their oversight responsibilities
If someone has security responsibilities in their job, they need training specific to those duties.
AT.L2-3.2.3: Insider Threat Awareness
“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”
This requirement specifically addresses threats from people inside your organization—employees, contractors, or partners who might intentionally or accidentally compromise security.
Insider threat means security risks posed by people within the organization who have legitimate access but misuse it or are compromised by external actors.
Training must cover:
- What insider threats look like (unusual data access, policy violations, behavioral changes)
- How to report concerns appropriately
- That insider threats are often unintentional, not malicious
Implementing Awareness and Training
Initial Training
Provide security awareness training when employees join your organization and before they access systems containing CUI. Cover:
- Overview of security threats (phishing, social engineering, malware)
- Your company’s security policies
- Proper handling of CUI
- Password requirements and practices
- Incident reporting procedures
- Acceptable use of company systems
Annual Refresher Training
Conduct training at least annually to reinforce concepts and address new threats. Annual training should:
- Review core security concepts
- Cover new or evolving threats
- Address any incidents or near-misses from the past year
- Remind employees of their responsibilities
Role-Based Training
Provide additional training based on job functions:
- IT Staff: Secure configuration, patch management, access control administration
- CUI Handlers: Proper marking, storage, transmission, and destruction of CUI
- Managers: Security oversight responsibilities, incident escalation
- All Staff: Phishing recognition, password hygiene, physical security
Insider Threat Training
Include insider threat awareness in your training program:
- Explain what insider threats are and why they matter
- Describe indicators that might suggest insider threat activity
- Provide clear reporting channels for concerns
- Emphasize that reporting protects everyone, including the person being reported
Documenting Your Training Program
CMMC assessors will verify that training actually occurred. Maintain documentation including:
Training Materials
- Course content or curriculum
- Slides, videos, or other materials used
- Quizzes or assessments
Training Records
- Attendance records showing who completed what training
- Dates training was completed
- Acknowledgment signatures
- Quiz or assessment scores
Training Schedule
- When initial training occurs (new hire onboarding)
- Frequency of refresher training (at least annual)
- Role-based training assignments
Training Options for Small Businesses
Small businesses can deliver effective training without large budgets:
Online Training Platforms
Many vendors offer affordable online security awareness training:
- Self-paced modules that employees complete independently
- Automated tracking and reporting
- Regular content updates for new threats
- Phishing simulation capabilities
Costs typically range from $20-50 per user annually.
In-House Training
Develop your own training using free resources:
- CISA (Cybersecurity and Infrastructure Security Agency) free training materials
- NIST resources and guidelines
- Vendor-provided security awareness content
Lunch and Learn Sessions
Brief, regular training sessions can be effective:
- 15-30 minute monthly sessions
- Cover one topic per session
- Include real examples and discussion
- Document attendance
Common Awareness and Training Mistakes
Mistake 1: One-and-Done Training
Providing training once without refreshers does not meet requirements. Training must be ongoing, at least annually.
Mistake 2: Generic Training Only
Role-based training is specifically required. General awareness training alone is insufficient for people with security responsibilities.
Mistake 3: No Documentation
Training that is not documented cannot be proven to assessors. Keep detailed records of who completed what training and when.
Mistake 4: Skipping Insider Threat
Insider threat training is a specific requirement, not optional. Ensure your program explicitly addresses this topic.
Key Takeaways
Awareness and Training contains only 3 requirements but establishes the human foundation for security. All users need general security awareness training, personnel with security duties need role-specific training, and everyone needs insider threat awareness.
Train employees when they join, refresh training annually, and document everything. Small businesses can meet these requirements affordably through online platforms or in-house programs.
Related Articles:
- What is CMMC Level 2
- CMMC Level 2 Security Controls Overview
- NIST SP 800-171 Rev 2 – Awareness and Training Family
- CISA Cybersecurity Training
- 32 CFR Part 170 – CMMC Program Rule
Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” specifically the Awareness and Training family (Section 3.2), and the DoD CMMC Level 2 Assessment Guide.
Need help building your CMMC training program? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.