CMMC ANSWER ENGINE

What does CMMC require for security awareness training?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Awareness training is a low-complexity practice family that fails surprisingly often because the documentation falls behind the actual practice.

The three governing practices

PracticeRequirement
AT.L2-3.2.1Ensure that managers, system administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
AT.L2-3.2.2Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
AT.L2-3.2.3Provide security awareness training on recognizing and reporting potential indicators of insider threat.

What general awareness training should cover (3.2.1)

  • What CUI is and how the user encounters it in their role.
  • Acceptable use of organizational systems.
  • Phishing recognition and reporting.
  • Password and authentication hygiene.
  • Incident reporting (how, to whom, by when).
  • Physical security expectations.
  • Mobile and remote work expectations.
  • The OSA's relevant policies, standards, and procedures.

Role-based training (3.2.2)

System administrators, security personnel, incident responders, and other personnel with information security duties need training specific to those duties — configuration baselines, IR procedures, log review, MFA enrollment management, evidence collection. Document who needs role-based training and the training they completed.

Insider threat awareness (3.2.3)

Users must be trained to recognize and report potential indicators of insider threat — behavioral, technical, and contextual indicators. The OSA defines what specifically to cover; common content includes:

  • Behavioral indicators (sudden access pattern changes, after-hours activity).
  • Technical indicators (large data transfers to personal storage, attempts to bypass DLP).
  • Reporting paths (HR, security, EAP).
  • The OSA's insider threat program structure.

Cadence and records

Neither NIST 800-171 Rev 2 nor the CAP prescribes a specific training frequency. The OSA defines the cadence in policy — annual training plus on-hire training is the typical pattern. Records should include:

  • Each user's training completion (general, role-based, insider threat).
  • Date of completion.
  • Training content version.
  • Acknowledgment of relevant policies (Acceptable Use, CUI Handling, etc.).

Common errors

  • Annual training that no one tracks. Without a register, the assessor can't verify completion.
  • Generic phishing training without CMMC content. Off-the-shelf training that never mentions CUI or DoD-specific obligations may not satisfy 3.2.1's "applicable policies" requirement.
  • No insider threat module. 3.2.3 is a separate practice from 3.2.1 and requires its own content.
  • Role-based training assumed but not documented. System administrators may know how to do their jobs, but 3.2.2 requires training that's actually delivered and recorded.
  • Training records that don't link to specific users. Aggregate "95% of employees completed training" doesn't satisfy the assessor — per-user records do.

Sources

  • NIST SP 800-171 Rev 2 — § 3.2.1, § 3.2.2, § 3.2.3 — link
  • NIST SP 800-171A — Assessment Objectives for AT family — link
Rulebook version: NIST SP 800-171 Rev 2

Track training completion against AT.L2-3.2.x.

The CMMC Compliance Engine includes the AT-REC-01 Training Completion Register for documenting general awareness, role-based, and insider threat training per user.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.