FutureFeed CMMC Education Series · Awareness & Training
Awareness & Training (AT) 3.2.1, 3.2.2, 3.2.3
The short version
If you’re responsible for CMMC compliance, here’s what these three requirements come down to. You need to:
- Train everyone on basic security awareness
- Give extra training to people with security responsibilities
- Teach employees to recognize and report insider threats
- Keep evidence showing the training actually happened
If you already have those four things and can prove them, you’re well on your way. Now let’s talk about what each one actually looks like.
In plain English
If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here?
Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top. Before you can expect employees to protect sensitive information, they need to understand what they’re protecting and why it matters. This is the control family that lays that foundation. Once your people understand their role, the technical controls that come later are far easier to put in place and keep running.
Here’s the whole family in three layers:
- Everyone gets basic security awareness training.
- People with security responsibilities get additional, role-specific training.
- Everyone learns how to recognize and report insider threats.
That’s it. Three layers, one conversation.
Example. Imagine a new engineer starts Monday morning. Before they get access to systems that hold sensitive information, they complete your security awareness training. If they’ll also administer user accounts, they get additional role-based training. During orientation, they learn how to report suspicious behavior and exactly where to report it. That’s what these requirements are asking you to do.
What you need to have in place
To be compliant, each of those boxes needs to be real and repeatable:
- Security awareness training for every employee and contractor, ideally at hire and once a year after that.
- Role-based training for anyone with security duties: IT admins, your security lead, anyone who manages accounts.
- Insider threat training that covers the warning signs and, just as important, exactly how to report a concern.
- Training records that prove who completed what, and when.
- An annual refresher so none of this quietly lapses after the first year.
Annual refreshers are easy to overlook, but they’re one of the first things an assessor will verify.
What you need to prove it
Think in three buckets. An assessor will want all three, so it helps to build them at the same time.
People
- Someone who owns the training program (often HR paired with your security lead)
- Managers who make sure their teams complete it
- The people with security duties who need the deeper, role-based training
Tools
- Wherever you deliver and track training (a real learning platform, or even a simple tracked spreadsheet with sign-offs to start)
- Your awareness content itself: slides, videos, or a short course
- A way to store completion records
Documents
- A short written policy that says who trains, on what, and how often
- Your actual training materials, including the insider-threat piece
- Completion records with names and dates
- New-hire training records tied to start dates
- A note in your System Security Plan (SSP) describing the whole program
You don’t need a fancy platform on day one. You need proof that the right people were trained on the right things, and dates that back it up.
When should I work on this
This is one of the first things I’d tackle. Training, roles, and responsibilities quietly support almost every other control you’ll get to later. When you reach access control or incident response, those all assume your people already understand the basics and know their part. Build this foundation first and everything after it gets easier. It’s also one of the more approachable families to knock out early, which is a nice confidence win before the heavier technical work.
Read next Why Security Is a Business DecisionA new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
Common challenges
Training happens once, then never again.
Why it happens: It gets treated as a one-time onboarding task instead of a yearly habit, so it slips off everyone’s calendar.
Recommendation: Set a yearly refresher and add training to your new-hire checklist so nobody starts work without it.
You can’t prove who actually completed it.
Why it happens: The training happened, but it was informal, so there’s no record with names and dates to hand an assessor.
Recommendation: Keep a simple completion log with names, topics, and dates. A signed roster counts as evidence.
Nobody knows how to report a concern.
Why it happens: Insider-threat training covers the warning signs but never tells people the actual steps to raise a flag.
Recommendation: Name the person or inbox to report to, and put those exact instructions inside the training itself.
What good looks like
A compliant contractor can usually answer yes to all of these:
- Do new employees receive awareness training before they touch sensitive information?
- Can you prove who completed training, and when?
- Do your IT administrators receive additional security training beyond the basics?
- Does everyone know how to report suspicious activity?
If any answer is no, that’s your next place to start.
How this connects to other controls
This family doesn’t stand alone. A few close relationships:
- Personnel Security: a natural partner. Training pairs with background checks, NDAs, and offboarding, since they all deal with your people.
- Incident Response: your team can only report a problem if they were trained to recognize one. This family feeds that one directly.
- Access Control: the people you train are the same people you’ll be granting and reviewing access for later.
The requirements, word for word
For your reference, here’s the exact language so you’re working from the source and not a paraphrase:
- 3.2.1 Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
- 3.2.2 Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.
- 3.2.3 Provide security awareness training on recognizing and reporting potential indicators of insider threat.
FutureFeed + Teramis, Better Together: A Deep Dive into CUI Discovery
Most CMMC scoping problems start the same way: a CUI boundary drawn around where an organization believes CUI lives, not where CUI has actually been found. On August 13 we are opening up Teramis live and showing you how to replace the assumption with proof. Live on Zoom, register to attend.
Every organization implements these controls a little differently. If you’re not sure whether your approach would satisfy an assessor, join one of our upcoming webinars or schedule a 15 Minutes with FutureFeed session. We’d rather answer your questions now than have you discover them during an assessment.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Sources
- Source: NIST SP 800-171 Rev 2, Awareness and Training (3.2)
- Related standards: NIST SP 800-53 Rev 5 (AT-2, AT-3, AT-4) · DFARS 252.204-7012