Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC Training Documentation and Evidence
Having a great training program is not enough for CMMC compliance. You must prove it exists and operates effectively. Assessors verify your Awareness and Training controls through documentation and evidence, not just your word that training happens.
CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.
This guide details exactly what documentation assessors expect and how to organize your training evidence for a smooth assessment.
What Assessors Are Looking For
CMMC assessors evaluate three Awareness and Training requirements. For each, they verify:
Existence
Does the training program exist? Is there documented content, policy, and structure?
Implementation
Is the program actually operating? Are people completing training?
Effectiveness
Does training achieve its goals? Do people pass assessments? Does behavior improve?
Documentation and evidence must address all three aspects for each requirement.
Documentation Categories
Organize your training documentation into these categories:
1. Training Policy
A formal document establishing your training program requirements:
What to include:
- Purpose and scope of the training program
- Roles required to complete training
- Training topics required (general awareness, role-based, insider threat)
- Timing requirements (initial, annual, triggered)
- Assessment and passing requirements
- Consequences for non-completion
- Responsibilities for program management
- Records retention requirements
Format: Formal policy document, reviewed and approved by management, with effective date and version control.
2. Training Plan or Curriculum
Documentation of what training covers and how it is structured:
What to include:
- Training modules and their objectives
- Topics covered in each module
- Duration of each training element
- Delivery method (online, in-person, self-study)
- Assessment approach for each module
- Role-based training assignments
- Training calendar or schedule
Format: Training plan document, curriculum outline, or learning management system configuration documentation.
3. Training Materials
The actual content used for training:
What to retain:
- Presentation slides
- Training videos or recordings
- Handouts and reference materials
- Quiz questions and answer keys
- Scenario exercises
- Acknowledgment forms
Format: Electronic files organized by training module and version. Retain historical versions to show what training was delivered at specific times.
4. Completion Records
Evidence that individuals completed required training:
What to capture:
- Employee name
- Training module completed
- Completion date
- Assessment score (if applicable)
- Instructor (for live training)
- Acknowledgment signature
Format: Training management system reports, sign-in sheets, certificates of completion, or training database exports.
5. Assessment Records
Evidence that knowledge was verified:
What to retain:
- Quiz or test results by individual
- Passing scores and any retakes
- Phishing simulation results
- Practical assessment outcomes
Format: Learning management system reports, quiz score exports, phishing simulation platform reports.
Evidence Mapping to Requirements
Map your documentation to specific CMMC requirements:
AT.L2-3.2.1: Security Awareness
| Evidence Type | Example |
|---|---|
| Policy | Training policy requiring security awareness for all users |
| Content | General awareness training materials covering security risks |
| Completion | Records showing all users completed awareness training |
| Assessment | Quiz results demonstrating comprehension |
AT.L2-3.2.2: Role-Based Training
| Evidence Type | Example |
|---|---|
| Policy | Policy identifying roles with security responsibilities |
| Role mapping | Document assigning training requirements to roles |
| Content | Training materials for each identified role |
| Completion | Records showing individuals completed role-specific training |
| Assessment | Role-specific assessment results |
AT.L2-3.2.3: Insider Threat Awareness
| Evidence Type | Example |
|---|---|
| Policy | Policy requiring insider threat training |
| Content | Training materials covering insider threat indicators |
| Reporting procedures | Documentation of how to report concerns |
| Completion | Records showing insider threat training completion |
| Assessment | Quiz results on insider threat topics |
Sample Documentation Package
A well-organized training documentation package might include:
/Training Documentation
├── Policies
│ └── SEC-POL-003 Security Awareness Training Policy v2.1.pdf
├── Training Plan
│ └── Annual Training Curriculum 2025.pdf
│ └── Role-Based Training Matrix.xlsx
├── Training Materials
│ ├── General Awareness
│ │ └── Security Awareness 2025.pptx
│ │ └── Security Awareness Quiz.pdf
│ ├── Role-Based
│ │ └── IT Administrator Security Training.pptx
│ │ └── CUI Handler Training.pptx
│ │ └── Manager Security Oversight.pptx
│ └── Insider Threat
│ └── Insider Threat Awareness.pptx
│ └── Reporting Procedures Reference.pdf
├── Completion Records
│ └── Training Completion Report Q1-2025.xlsx
│ └── Training Completion Report Q2-2025.xlsx
│ └── Annual Training Completion Summary 2024.pdf
├── Assessment Records
│ └── Quiz Score Summary 2025.xlsx
│ └── Phishing Simulation Results 2025.pdf
└── Acknowledgments
└── Signed Acknowledgment Forms (by employee)
Using a Learning Management System
Learning Management Systems (LMS) simplify training documentation:
LMS stands for Learning Management System—software that delivers training content, tracks completion, and generates reports.
Benefits for CMMC:
- Automatic completion tracking
- Built-in quiz and assessment capability
- Reporting for assessors
- Version control for content
- Assignment by role or group
- Deadline enforcement
Selecting an LMS:
When choosing an LMS for CMMC training:
- Ensure it can generate completion reports by individual
- Verify it tracks assessment scores
- Confirm it retains historical data for your retention period
- Check that reports include dates and specific training completed
Even with LMS:
Still maintain documentation outside the system:
- Exported reports (in case of system changes)
- Policy documents
- Training materials (for reference)
- Evidence of in-person training (sign-in sheets)
Records Retention
Retain training documentation appropriately:
Minimum Retention
Keep training records for at least three years, covering the CMMC certification period plus time for any disputes or audits.
Contract Requirements
Some contracts specify longer retention periods. Check your contracts for specific requirements.
What to Retain
- All completion records
- Assessment results
- Training materials (by version)
- Policies (by version)
- Evidence of program reviews and updates
Secure Storage
Protect training records appropriately:
- Restrict access to HR and security personnel
- Back up electronic records
- Protect from unauthorized modification
Preparing for Assessment
Before your CMMC assessment:
Gather Documentation
Compile all training evidence into an organized package that assessors can review.
Verify Completeness
Check that:
- All personnel have completion records
- Role-based training is documented by role
- Insider threat training is specifically documented
- Assessment scores are available
- Policy is current and approved
Prepare to Demonstrate
Be ready to show assessors:
- How training is assigned and tracked
- Sample completion records
- How assessments verify knowledge
- How the program is reviewed and updated
Identify Gaps
Before assessment, verify:
- Everyone required has completed training
- All roles have appropriate training defined
- Documentation is complete and current
- No one is overdue for refresher training
Common Documentation Mistakes
Mistake 1: No Written Policy
Verbal training requirements are not sufficient. Document your policy formally.
Mistake 2: Missing Completion Records
If you cannot prove someone completed training, they effectively did not complete it. Track completions meticulously.
Mistake 3: Generic Records Without Specifics
“Completed security training” is too vague. Records should show specific modules and dates.
Mistake 4: No Role-Based Evidence
Showing everyone completed the same training does not demonstrate role-based training. Document role-specific completion.
Mistake 5: Outdated Materials
Training materials from three years ago may not reflect current threats or policies. Keep materials current and document updates.
Mistake 6: No Assessment Evidence
Completion without assessment does not demonstrate knowledge transfer. Include quiz or test results.
Key Takeaways
CMMC assessors verify training through documentation, not observation. Maintain formal policy, documented curriculum, training materials, completion records, and assessment results for all three Awareness and Training requirements.
Organize documentation clearly and map evidence to specific requirements. Use a learning management system to simplify tracking, but maintain exported records outside the system.
Prepare documentation packages before assessment and verify completeness. Gaps in training documentation are gaps in compliance evidence.
Related Articles:
- CMMC Security Awareness Training Requirements
- How to Create a CMMC Training Program
- What is SPRS?
- How to Budget for CMMC Compliance
- CMMC Level 2 Self-Assessment Requirements
- DoD CMMC Level 2 Assessment Guide
Official Sources: This article is based on NIST SP 800-171 Revision 2 Awareness and Training requirements, NIST SP 800-171A assessment procedures, and the DoD CMMC Level 2 Assessment Guide.
Need help documenting your training program for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.