Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Role-Based Training for CMMC Compliance
Generic security awareness training is not enough for CMMC. Requirement AT.L2-3.2.2 mandates that personnel receive training specific to their assigned security responsibilities. A system administrator needs different knowledge than an accountant, even though both may access systems containing Controlled Unclassified Information.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
This guide breaks down training requirements by role and helps you build a program that prepares each person for their specific security responsibilities.
Why Generic Training Falls Short
Standard security awareness training covers common threats everyone faces—phishing, passwords, and physical security. This foundation is necessary but not sufficient.
Consider the difference:
General User Needs to know: Do not click phishing links, lock your computer, and report suspicious activity.
System Administrator Needs to know: Everything above, plus secure configuration, access provisioning, log review, vulnerability management, incident response procedures, backup verification, and much more.
If your system administrator receives only the same training as everyone else, they lack the knowledge to perform their security responsibilities effectively. CMMC assessors will identify this gap.
Core Roles Requiring Specialized Training
While every organization is different, most defense contractors have these security-relevant roles:
System Administrators
People who configure, maintain, and manage IT systems.
Security responsibilities:
- Configuring systems securely
- Managing user accounts and access
- Applying patches and updates
- Monitoring system health and security
- Responding to security alerts
- Managing backups and recovery
Training topics:
- Secure configuration and hardening
- Access control management
- Patch management procedures
- Log review and analysis
- Incident detection and response
- Backup and recovery procedures
- Change management
- Vulnerability management
Training depth: Technical and detailed, covering specific tools and procedures used in your environment.
CUI Handlers
Employees who regularly work with Controlled Unclassified Information.
Security responsibilities:
- Properly handling CUI documents
- Applying correct markings
- Storing CUI securely
- Transmitting CUI appropriately
- Destroying CUI when no longer needed
Training topics:
- CUI categories and marking requirements
- Approved storage locations and methods
- Secure transmission procedures (email, file sharing)
- Physical handling of CUI documents
- Destruction and sanitization procedures
- Incident reporting for CUI exposure
Training depth: Practical and procedure-focused, with specific guidance for your organization’s CUI handling processes.
Managers and Supervisors
People responsible for overseeing employees who access CUI systems.
Security responsibilities:
- Enforcing security policies with their teams
- Reviewing access requests
- Monitoring for policy compliance
- Reporting security concerns
- Supporting incident response
- Ensuring training completion
Training topics:
- Security policy requirements and enforcement
- Access authorization responsibilities
- Recognizing insider threat indicators
- Handling security violations
- Incident escalation procedures
- Security culture and leadership
- Training compliance monitoring
Training depth: Policy and management focused, emphasizing oversight responsibilities rather than technical details.
Incident Response Team
Personnel designated to handle security incidents.
Security responsibilities:
- Detecting security incidents
- Containing threats
- Investigating incidents
- Coordinating response activities
- Documenting and reporting incidents
- Supporting recovery
Training topics:
- Incident detection and classification
- Containment procedures
- Evidence preservation
- Investigation techniques
- Communication during incidents
- Reporting requirements (including 72-hour DoD notification)
- Recovery procedures
- Post-incident review
Training depth: Detailed procedural training with tabletop exercises and hands-on practice.
Remote Workers
Employees who work from home or travel with CUI access.
Security responsibilities:
- Securing home work environment
- Protecting CUI outside the office
- Using VPN and secure connections
- Safeguarding devices during travel
Training topics:
- Home office security requirements
- VPN usage and requirements
- Securing home networks
- Travel security procedures
- Public Wi-Fi risks
- Device protection when traveling
- Reporting incidents while remote
Training depth: Practical guidance specific to out-of-office scenarios.
Help Desk and Support Staff
Personnel who assist users with technical issues.
Security responsibilities:
- Verifying identity before providing assistance
- Recognizing social engineering attempts
- Following secure password reset procedures
- Escalating security concerns
Training topics:
- Identity verification procedures
- Social engineering recognition
- Secure password reset processes
- When to escalate to security team
- Documentation requirements
Training depth: Procedure-focused with emphasis on recognizing manipulation attempts.
Building Role-Based Training
Step 1: Inventory Security Roles
List all roles with distinct security responsibilities:
| Role | Number of People | Primary Responsibilities |
|---|---|---|
| System Administrator | 2 | System management, access control |
| CUI Handler | 15 | Document handling, transmission |
| Manager | 4 | Oversight, policy enforcement |
| Remote Worker | 8 | Remote security practices |
Step 2: Define Training Requirements
For each role, specify:
- Required training topics
- Training depth and duration
- Prerequisite training (general awareness first)
- Recertification frequency
- Assessment requirements
Step 3: Develop or Source Content
For each role’s training:
- Create custom content for organization-specific procedures
- Use vendor training for technical topics (vendor security certifications)
- Leverage industry resources for standard topics
- Combine general awareness with role-specific modules
Step 4: Assign Training by Role
Map training to individuals:
- Identify each person’s role(s)
- Assign required training modules
- Set completion deadlines
- Track completion in training system
Note: Some people may have multiple roles requiring multiple training tracks.
Step 5: Verify Competency
Test that training achieved its goal:
- Role-specific assessments
- Practical demonstrations where appropriate
- Manager verification of competency
- Observation during actual work
Role-Based Training Matrix
A sample matrix showing training by role:
| Training Module | All Users | IT Admin | CUI Handler | Manager | Incident Response |
|---|---|---|---|---|---|
| General Awareness | ✓ | ✓ | ✓ | ✓ | ✓ |
| Phishing Recognition | ✓ | ✓ | ✓ | ✓ | ✓ |
| Insider Threat | ✓ | ✓ | ✓ | ✓ | ✓ |
| CUI Handling | ✓ | ✓ | |||
| Secure Configuration | ✓ | ||||
| Access Management | ✓ | ✓ | |||
| Incident Response | ✓ | ✓ | |||
| Log Analysis | ✓ | ✓ | |||
| Policy Enforcement | ✓ | ||||
| Evidence Preservation | ✓ |
Documenting Role-Based Training
Assessors verify role-based training through documentation:
Training Plan
Document showing:
- Roles identified in your organization
- Training requirements for each role
- How requirements map to job responsibilities
Individual Training Records
For each person:
- Their assigned role(s)
- Required training for those roles
- Completion dates
- Assessment scores
- Next training due date
Training Content
Evidence that content addresses role responsibilities:
- Curriculum for each role
- Learning objectives
- Assessment questions
Common Role-Based Training Mistakes
Mistake 1: One-Size-Fits-All Training
Giving everyone identical training fails the role-based requirement. Differentiate training by responsibility.
Mistake 2: Missing Role Identification
If you have not documented security roles, you cannot demonstrate role-based training. Define roles explicitly.
Mistake 3: No Assessment of Role-Specific Knowledge
Testing only general awareness does not verify role-specific competency. Include role-specific questions.
Mistake 4: Forgetting Role Changes
When people change jobs, their training requirements change. Update training assignments with role changes.
Mistake 5: Overlooking Part-Time Roles
Someone who occasionally handles CUI or fills in for IT still needs appropriate training. Include part-time responsibilities.
Key Takeaways
CMMC requires training tailored to each person’s security responsibilities, not just generic awareness training. Identify security roles in your organization, define training requirements for each role, and document completion by the individual.
Key roles typically include system administrators, CUI handlers, managers, incident responders, and remote workers. Each needs training specific to their responsibilities beyond baseline awareness.
Build a training matrix mapping roles to requirements, track completion individually, and verify competency through role-specific assessments.
Related Articles:
- CMMC Security Awareness Training Requirements
- How to Create a CMMC Training Program
- What is SPRS?
- How to Budget for CMMC Compliance
- CMMC Level 2 Self-Assessment Requirements
- DoD CMMC Level 2 Assessment Guide
Official Sources: This article is based on NIST SP 800-171 Revision 2 requirement 3.2.2 and the DoD CMMC Level 2 Assessment Guide.
Need help developing role-based training for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.