Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

CMMC Training Documentation and Evidence

Having a great training program is not enough for CMMC compliance. You must prove it exists and operates effectively. Assessors verify your Awareness and Training controls through documentation and evidence, not just your word that training happens.

CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.

This guide details exactly what documentation assessors expect and how to organize your training evidence for a smooth assessment.

What Assessors Are Looking For

CMMC assessors evaluate three Awareness and Training requirements. For each, they verify:

Existence

Does the training program exist? Is there documented content, policy, and structure?

Implementation

Is the program actually operating? Are people completing training?

Effectiveness

Does training achieve its goals? Do people pass assessments? Does behavior improve?

Documentation and evidence must address all three aspects for each requirement.

Documentation Categories

Organize your training documentation into these categories:

1. Training Policy

A formal document establishing your training program requirements:

What to include:

  • Purpose and scope of the training program
  • Roles required to complete training
  • Training topics required (general awareness, role-based, insider threat)
  • Timing requirements (initial, annual, triggered)
  • Assessment and passing requirements
  • Consequences for non-completion
  • Responsibilities for program management
  • Records retention requirements

Format: Formal policy document, reviewed and approved by management, with effective date and version control.

2. Training Plan or Curriculum

Documentation of what training covers and how it is structured:

What to include:

  • Training modules and their objectives
  • Topics covered in each module
  • Duration of each training element
  • Delivery method (online, in-person, self-study)
  • Assessment approach for each module
  • Role-based training assignments
  • Training calendar or schedule

Format: Training plan document, curriculum outline, or learning management system configuration documentation.

3. Training Materials

The actual content used for training:

What to retain:

  • Presentation slides
  • Training videos or recordings
  • Handouts and reference materials
  • Quiz questions and answer keys
  • Scenario exercises
  • Acknowledgment forms

Format: Electronic files organized by training module and version. Retain historical versions to show what training was delivered at specific times.

4. Completion Records

Evidence that individuals completed required training:

What to capture:

  • Employee name
  • Training module completed
  • Completion date
  • Assessment score (if applicable)
  • Instructor (for live training)
  • Acknowledgment signature

Format: Training management system reports, sign-in sheets, certificates of completion, or training database exports.

5. Assessment Records

Evidence that knowledge was verified:

What to retain:

  • Quiz or test results by individual
  • Passing scores and any retakes
  • Phishing simulation results
  • Practical assessment outcomes

Format: Learning management system reports, quiz score exports, phishing simulation platform reports.

Evidence Mapping to Requirements

Map your documentation to specific CMMC requirements:

AT.L2-3.2.1: Security Awareness

Evidence TypeExample
PolicyTraining policy requiring security awareness for all users
ContentGeneral awareness training materials covering security risks
CompletionRecords showing all users completed awareness training
AssessmentQuiz results demonstrating comprehension

AT.L2-3.2.2: Role-Based Training

Evidence TypeExample
PolicyPolicy identifying roles with security responsibilities
Role mappingDocument assigning training requirements to roles
ContentTraining materials for each identified role
CompletionRecords showing individuals completed role-specific training
AssessmentRole-specific assessment results

AT.L2-3.2.3: Insider Threat Awareness

Evidence TypeExample
PolicyPolicy requiring insider threat training
ContentTraining materials covering insider threat indicators
Reporting proceduresDocumentation of how to report concerns
CompletionRecords showing insider threat training completion
AssessmentQuiz results on insider threat topics

Sample Documentation Package

A well-organized training documentation package might include:

/Training Documentation
├── Policies
│   └── SEC-POL-003 Security Awareness Training Policy v2.1.pdf
├── Training Plan
│   └── Annual Training Curriculum 2025.pdf
│   └── Role-Based Training Matrix.xlsx
├── Training Materials
│   ├── General Awareness
│   │   └── Security Awareness 2025.pptx
│   │   └── Security Awareness Quiz.pdf
│   ├── Role-Based
│   │   └── IT Administrator Security Training.pptx
│   │   └── CUI Handler Training.pptx
│   │   └── Manager Security Oversight.pptx
│   └── Insider Threat
│       └── Insider Threat Awareness.pptx
│       └── Reporting Procedures Reference.pdf
├── Completion Records
│   └── Training Completion Report Q1-2025.xlsx
│   └── Training Completion Report Q2-2025.xlsx
│   └── Annual Training Completion Summary 2024.pdf
├── Assessment Records
│   └── Quiz Score Summary 2025.xlsx
│   └── Phishing Simulation Results 2025.pdf
└── Acknowledgments
└── Signed Acknowledgment Forms (by employee)

Using a Learning Management System

Learning Management Systems (LMS) simplify training documentation:

LMS stands for Learning Management System—software that delivers training content, tracks completion, and generates reports.

Benefits for CMMC:

  • Automatic completion tracking
  • Built-in quiz and assessment capability
  • Reporting for assessors
  • Version control for content
  • Assignment by role or group
  • Deadline enforcement

Selecting an LMS:

When choosing an LMS for CMMC training:

  • Ensure it can generate completion reports by individual
  • Verify it tracks assessment scores
  • Confirm it retains historical data for your retention period
  • Check that reports include dates and specific training completed

Even with LMS:

Still maintain documentation outside the system:

  • Exported reports (in case of system changes)
  • Policy documents
  • Training materials (for reference)
  • Evidence of in-person training (sign-in sheets)

Records Retention

Retain training documentation appropriately:

Minimum Retention

Keep training records for at least three years, covering the CMMC certification period plus time for any disputes or audits.

Contract Requirements

Some contracts specify longer retention periods. Check your contracts for specific requirements.

What to Retain

  • All completion records
  • Assessment results
  • Training materials (by version)
  • Policies (by version)
  • Evidence of program reviews and updates

Secure Storage

Protect training records appropriately:

  • Restrict access to HR and security personnel
  • Back up electronic records
  • Protect from unauthorized modification

Preparing for Assessment

Before your CMMC assessment:

Gather Documentation

Compile all training evidence into an organized package that assessors can review.

Verify Completeness

Check that:

  • All personnel have completion records
  • Role-based training is documented by role
  • Insider threat training is specifically documented
  • Assessment scores are available
  • Policy is current and approved

Prepare to Demonstrate

Be ready to show assessors:

  • How training is assigned and tracked
  • Sample completion records
  • How assessments verify knowledge
  • How the program is reviewed and updated

Identify Gaps

Before assessment, verify:

  • Everyone required has completed training
  • All roles have appropriate training defined
  • Documentation is complete and current
  • No one is overdue for refresher training

Common Documentation Mistakes

Mistake 1: No Written Policy

Verbal training requirements are not sufficient. Document your policy formally.

Mistake 2: Missing Completion Records

If you cannot prove someone completed training, they effectively did not complete it. Track completions meticulously.

Mistake 3: Generic Records Without Specifics

“Completed security training” is too vague. Records should show specific modules and dates.

Mistake 4: No Role-Based Evidence

Showing everyone completed the same training does not demonstrate role-based training. Document role-specific completion.

Mistake 5: Outdated Materials

Training materials from three years ago may not reflect current threats or policies. Keep materials current and document updates.

Mistake 6: No Assessment Evidence

Completion without assessment does not demonstrate knowledge transfer. Include quiz or test results.

Key Takeaways

CMMC assessors verify training through documentation, not observation. Maintain formal policy, documented curriculum, training materials, completion records, and assessment results for all three Awareness and Training requirements.

Organize documentation clearly and map evidence to specific requirements. Use a learning management system to simplify tracking, but maintain exported records outside the system.

Prepare documentation packages before assessment and verify completeness. Gaps in training documentation are gaps in compliance evidence.

Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 Awareness and Training requirements, NIST SP 800-171A assessment procedures, and the DoD CMMC Level 2 Assessment Guide.

Need help documenting your training program for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Table of Contents