Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

CMMC Security Awareness Training Requirements

Your technology and policies are only as effective as the people using them. CMMC recognizes this by requiring security awareness training for everyone who accesses systems containing Controlled Unclassified Information. The Awareness and Training control family ensures your workforce understands security threats and their responsibilities.

CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.

CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.

Training is not just a checkbox. It is your first line of defense against phishing, social engineering, and insider threats that technical controls alone cannot stop.

The Three Awareness and Training Requirements

CMMC Level 2 includes three requirements in the Awareness and Training (AT) control family. Despite being one of the smallest control families, these requirements are fundamental to your security program.

AT.L2-3.2.1: Security Awareness

“Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.”

This requirement ensures everyone understands:

  • Security risks relevant to their role
  • Your organization’s security policies
  • Procedures they must follow
  • Consequences of security failures

Awareness is not the same as training. Awareness means people understand that threats exist and why security matters. Training teaches them what to do about it.

AT.L2-3.2.2: Role-Based Training

“Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.”

Different roles have different security responsibilities:

  • System administrators need training on secure configuration, access management, and incident response
  • Users handling CUI need training on proper handling, marking, and protection procedures
  • Managers need training on policy enforcement and security oversight
  • Incident responders need training on detection, containment, and reporting

Generic awareness training does not satisfy this requirement. You must provide training specific to each person’s security responsibilities.

AT.L2-3.2.3: Insider Threat Awareness

“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”

Insider threats come from people within your organization—employees, contractors, or partners—who misuse their access intentionally or accidentally. Training must help employees:

  • Recognize warning signs of insider threats
  • Understand reporting procedures
  • Know who to contact with concerns
  • Feel comfortable reporting without fear of retaliation

This requirement acknowledges that external attackers are not your only concern. Trusted insiders with legitimate access can cause significant damage.

Training Frequency Requirements

CMMC does not specify exact training intervals, but industry standards and assessment expectations establish clear norms:

Initial Training

All personnel must receive security awareness training before accessing CUI systems. Do not grant access until training is complete.

Annual Refresher Training

Provide refresher training at least annually. Many organizations train more frequently—quarterly refreshers help keep security top of mind.

Training After Significant Changes

Retrain when circumstances change:

  • New threats emerge (novel phishing campaigns, new attack techniques)
  • Policies or procedures change significantly
  • Systems or tools change
  • Personnel move to new roles with different responsibilities

Continuous Reinforcement

Beyond formal training, reinforce awareness continuously:

  • Security tips in newsletters or emails
  • Posters and reminders in work areas
  • Discussion in team meetings
  • Simulated phishing exercises

Topics Your Training Must Cover

Effective security awareness training addresses threats your employees actually face:

Phishing and Social Engineering

The most common attack vector. Training should cover:

  • Recognizing phishing emails (suspicious links, urgency, sender mismatches)
  • Verifying requests before acting
  • Reporting suspicious messages
  • Voice phishing (vishing) and text phishing (smishing)

Password Security

Despite advances in authentication, passwords remain critical:

  • Creating strong passwords
  • Never sharing passwords
  • Using unique passwords for different accounts
  • Recognizing password theft attempts

Physical Security

Protecting information is not just digital:

  • Securing workstations when away
  • Protecting printed CUI documents
  • Visitor procedures and escort requirements
  • Clean desk practices

CUI Handling

Employees must understand CUI-specific requirements:

  • What CUI is and how to identify it
  • Proper marking and labeling
  • Storage and transmission requirements
  • Disposal procedures

Removable Media

USB drives and portable storage create risks:

  • Dangers of unknown USB devices
  • Approved media usage policies
  • Encryption requirements
  • Proper disposal

Incident Reporting

Employees must know how to report problems:

  • What constitutes a security incident
  • Who to contact and how
  • Importance of prompt reporting
  • Protection from retaliation for good-faith reports

Insider Threat Indicators

Help employees recognize warning signs:

  • Unusual access patterns
  • Attempts to bypass security controls
  • Unexplained changes in behavior
  • Interest in information outside job responsibilities

Measuring Training Effectiveness

Simply delivering training is not enough. You must verify it works:

Knowledge Assessments

Test comprehension after training:

  • Quizzes covering key topics
  • Passing scores required for completion
  • Remedial training for those who fail

Phishing Simulations

Test real-world application:

  • Send simulated phishing emails
  • Track who clicks and who reports
  • Provide immediate feedback
  • Additional training for those who fail

Behavioral Observation

Monitor whether training changes behavior:

  • Clean desk compliance checks
  • Tailgating observations
  • Incident report volume and quality

Metrics to Track

  • Training completion rates
  • Quiz scores
  • Phishing simulation results
  • Time to report actual incidents
  • Security incident trends over time

Documenting Training for Assessors

CMMC assessors will verify your training program exists and operates effectively:

Required Documentation

  • Training policy defining requirements
  • Training materials and content
  • Training records showing completion
  • Role-based training assignments
  • Assessment results

Evidence to Maintain

  • Attendance records or completion certificates
  • Signed acknowledgment forms
  • Quiz or test results
  • Phishing simulation reports
  • Training schedule and calendar

Retention Period

Keep training records for at least three years. Some contracts may require longer retention.

Key Takeaways

CMMC requires security awareness training covering general security awareness, role-based responsibilities, and insider threat recognition. All personnel must receive initial training before CUI access, with annual refreshers thereafter.

Training must address real threats your employees face—phishing, social engineering, CUI handling, and physical security. Measure effectiveness through assessments and simulations, not just completion tracking.

Document everything. Assessors will verify that training happens, people pass, and the program addresses required topics.

Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 Awareness and Training requirements (Section 3.2) and the DoD CMMC Level 2 Assessment Guide.

Need help building your CMMC training program? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Table of Contents