Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC Security Awareness Training Requirements
Your technology and policies are only as effective as the people using them. CMMC recognizes this by requiring security awareness training for everyone who accesses systems containing Controlled Unclassified Information. The Awareness and Training control family ensures your workforce understands security threats and their responsibilities.
CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
Training is not just a checkbox. It is your first line of defense against phishing, social engineering, and insider threats that technical controls alone cannot stop.
The Three Awareness and Training Requirements
CMMC Level 2 includes three requirements in the Awareness and Training (AT) control family. Despite being one of the smallest control families, these requirements are fundamental to your security program.
AT.L2-3.2.1: Security Awareness
“Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.”
This requirement ensures everyone understands:
- Security risks relevant to their role
- Your organization’s security policies
- Procedures they must follow
- Consequences of security failures
Awareness is not the same as training. Awareness means people understand that threats exist and why security matters. Training teaches them what to do about it.
AT.L2-3.2.2: Role-Based Training
“Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.”
Different roles have different security responsibilities:
- System administrators need training on secure configuration, access management, and incident response
- Users handling CUI need training on proper handling, marking, and protection procedures
- Managers need training on policy enforcement and security oversight
- Incident responders need training on detection, containment, and reporting
Generic awareness training does not satisfy this requirement. You must provide training specific to each person’s security responsibilities.
AT.L2-3.2.3: Insider Threat Awareness
“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”
Insider threats come from people within your organization—employees, contractors, or partners—who misuse their access intentionally or accidentally. Training must help employees:
- Recognize warning signs of insider threats
- Understand reporting procedures
- Know who to contact with concerns
- Feel comfortable reporting without fear of retaliation
This requirement acknowledges that external attackers are not your only concern. Trusted insiders with legitimate access can cause significant damage.
Training Frequency Requirements
CMMC does not specify exact training intervals, but industry standards and assessment expectations establish clear norms:
Initial Training
All personnel must receive security awareness training before accessing CUI systems. Do not grant access until training is complete.
Annual Refresher Training
Provide refresher training at least annually. Many organizations train more frequently—quarterly refreshers help keep security top of mind.
Training After Significant Changes
Retrain when circumstances change:
- New threats emerge (novel phishing campaigns, new attack techniques)
- Policies or procedures change significantly
- Systems or tools change
- Personnel move to new roles with different responsibilities
Continuous Reinforcement
Beyond formal training, reinforce awareness continuously:
- Security tips in newsletters or emails
- Posters and reminders in work areas
- Discussion in team meetings
- Simulated phishing exercises
Topics Your Training Must Cover
Effective security awareness training addresses threats your employees actually face:
Phishing and Social Engineering
The most common attack vector. Training should cover:
- Recognizing phishing emails (suspicious links, urgency, sender mismatches)
- Verifying requests before acting
- Reporting suspicious messages
- Voice phishing (vishing) and text phishing (smishing)
Password Security
Despite advances in authentication, passwords remain critical:
- Creating strong passwords
- Never sharing passwords
- Using unique passwords for different accounts
- Recognizing password theft attempts
Physical Security
Protecting information is not just digital:
- Securing workstations when away
- Protecting printed CUI documents
- Visitor procedures and escort requirements
- Clean desk practices
CUI Handling
Employees must understand CUI-specific requirements:
- What CUI is and how to identify it
- Proper marking and labeling
- Storage and transmission requirements
- Disposal procedures
Removable Media
USB drives and portable storage create risks:
- Dangers of unknown USB devices
- Approved media usage policies
- Encryption requirements
- Proper disposal
Incident Reporting
Employees must know how to report problems:
- What constitutes a security incident
- Who to contact and how
- Importance of prompt reporting
- Protection from retaliation for good-faith reports
Insider Threat Indicators
Help employees recognize warning signs:
- Unusual access patterns
- Attempts to bypass security controls
- Unexplained changes in behavior
- Interest in information outside job responsibilities
Measuring Training Effectiveness
Simply delivering training is not enough. You must verify it works:
Knowledge Assessments
Test comprehension after training:
- Quizzes covering key topics
- Passing scores required for completion
- Remedial training for those who fail
Phishing Simulations
Test real-world application:
- Send simulated phishing emails
- Track who clicks and who reports
- Provide immediate feedback
- Additional training for those who fail
Behavioral Observation
Monitor whether training changes behavior:
- Clean desk compliance checks
- Tailgating observations
- Incident report volume and quality
Metrics to Track
- Training completion rates
- Quiz scores
- Phishing simulation results
- Time to report actual incidents
- Security incident trends over time
Documenting Training for Assessors
CMMC assessors will verify your training program exists and operates effectively:
Required Documentation
- Training policy defining requirements
- Training materials and content
- Training records showing completion
- Role-based training assignments
- Assessment results
Evidence to Maintain
- Attendance records or completion certificates
- Signed acknowledgment forms
- Quiz or test results
- Phishing simulation reports
- Training schedule and calendar
Retention Period
Keep training records for at least three years. Some contracts may require longer retention.
Key Takeaways
CMMC requires security awareness training covering general security awareness, role-based responsibilities, and insider threat recognition. All personnel must receive initial training before CUI access, with annual refreshers thereafter.
Training must address real threats your employees face—phishing, social engineering, CUI handling, and physical security. Measure effectiveness through assessments and simulations, not just completion tracking.
Document everything. Assessors will verify that training happens, people pass, and the program addresses required topics.
Related Articles:
- CMMC Incident Response Requirements
- CMMC Personnel Security Requirements
- How to Create a CMMC Training Program
- CMMC for Small Businesses
- NIST SP 800-171 Rev 2 – Awareness and Training
- 32 CFR Part 170 – CMMC Program Rule
Official Sources: This article is based on NIST SP 800-171 Revision 2 Awareness and Training requirements (Section 3.2) and the DoD CMMC Level 2 Assessment Guide.
Need help building your CMMC training program? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.