Regulation and standard

What security awareness training does CMMC require of defense contractors?

Short answer

The Cybersecurity Maturity Model Certification (CMMC) program requires US defense contractors handling Controlled Unclassified Information to meet three awareness and training requirements at Level 2, from NIST SP 800-171 Revision 2: security risk awareness for all system users, role-based training for security duties, and insider threat awareness. Level 3 adds annual, threat-focused training with practical exercises. Level 1 has no training requirement. CMMC entered contracts on November 10, 2025, and is paused in Phase 1.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
9 min
Jurisdiction
United States (federal)
Regulator
US Department of Defense (DoD CIO, CMMC Program Management Office)

Key takeaways

  • CMMC is set by two rules: the program rule at 32 CFR Part 170 (effective December 16, 2024) and the acquisition rule adding DFARS clause 252.204-7021 (effective November 10, 2025).
  • Level 2 includes AT.L2-3.2.1 (security awareness), AT.L2-3.2.2 (role-based training) and AT.L2-3.2.3 (insider threat awareness) from NIST SP 800-171 Rev. 2.
  • AT.L2-3.2.1 and AT.L2-3.2.2 are worth 5 points each in CMMC scoring, so they cannot be deferred on a plan of action and milestones (POA&M); they must be met at assessment.
  • Level 3 adds AT.L3-3.2.1e and AT.L3-3.2.2e: training at hire, after a significant cyber event and at least annually, with role-tailored practical exercises.
  • As at September 2026 the program is paused in Phase 1. On July 13, 2026, DoD suspended the Phase 2 transition scheduled for November 10, 2026, so new requirements are limited to Level 1 (Self) and Level 2 (Self) during a program review.

What is CMMC and who does it apply to?

CMMC is the US Department of Defense (DoD) program for verifying that contractors protect sensitive, unclassified government information on their own systems. It applies when a DoD solicitation or contract specifies a CMMC level and the contractor's systems will process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

For readers outside the United States: federal regulations are published in the Code of Federal Regulations (CFR), organized by title and part. CMMC sits in two places. The program rule at 32 CFR Part 170, effective December 16, 2024, defines the levels, assessments and scoring. The acquisition rule in the Defense Federal Acquisition Regulation Supplement (DFARS), effective November 10, 2025, puts clause 252.204-7021 into contracts so that the requirement actually binds a supplier.

CMMC does not create new security controls. It verifies requirements that already existed: the 15 basic safeguarding requirements in FAR 52.204-21 (Level 1), the 110 requirements of NIST SP 800-171 Revision 2 (Level 2), and 24 selected requirements from NIST SP 800-172 (Level 3). Subcontractors at any tier receive the requirement through flowdown when they will handle FCI or CUI, which is how companies in Europe, the Middle East and Asia come into scope. This page states the position as at September 2026.

What training does each CMMC level require?

Training requirements appear at Level 2 and Level 3 only. The Level 1 requirements in FAR 52.204-21 cover access control, identification and authentication, media sanitization, physical access, boundary protection, flaw remediation and malware protection, and contain no awareness or training requirement.

CMMC awareness and training (AT) requirements by level, from 32 CFR Part 170 and NIST SP 800-171 Rev. 2
RequirementLevelWhat it requiresScoring weight
AT.L2-3.2.1Level 2Managers, system administrators and users are made aware of the security risks of their activities and of the applicable security policies, standards and procedures.5 points (basic requirement)
AT.L2-3.2.2Level 2Personnel are trained to carry out their assigned information security duties and responsibilities.5 points (basic requirement)
AT.L2-3.2.3Level 2Security awareness training on recognizing and reporting potential indicators of insider threat.1 point (derived requirement)
AT.L3-3.2.1eLevel 3Awareness training at initial hire, after a significant cyber event and at least annually, focused on social engineering, advanced persistent threat actors, breaches and suspicious behavior; content updated at least annually.1 point
AT.L3-3.2.2eLevel 3Practical exercises in awareness training for all users, tailored to general, specialized and privileged roles, aligned to current threat scenarios, with feedback to the individual and their supervisor.1 point
NIST SP 800-171 Rev. 2, requirement 3.2.2

"Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities."

What do the Level 2 training requirements mean in practice?

In practice, Level 2 expects three distinct streams: general awareness for everyone who uses in-scope systems, deeper role-based training for people with security duties, and insider threat awareness. The discussion text in NIST SP 800-171 Rev. 2 leaves content and frequency to the organization, based on its requirements and the systems people can access.

  • Awareness (3.2.1): NIST describes the content as a basic understanding of the need for information security, user actions to maintain security and respond to suspected incidents, and operations security. Techniques can include formal training, email advisories, logon messages and awareness events. It points to NIST SP 800-50 for program guidance.
  • Role-based training (3.2.2): NIST lists roles that need security-related technical training tailored to their duties, including system and network administrators, developers, architects, procurement officials, configuration management and audit staff, and security assessors.
  • Insider threat (3.2.3): NIST gives indicators such as long-term job dissatisfaction, attempts to access information not needed for the job, and serious policy violations, and says training should cover how to report concerns through the organization's channels. It suggests tailoring by role, for example behavior-change indicators for managers.

The program rule sets a ceiling on vague frequencies. Section 170.14(d) says that where CMMC requirements use "periodically", the interval is organization-defined but no more than one year. An annual refresh cycle is therefore the practical maximum wherever a contractor's own policy uses periodic language.

How are the training requirements assessed and scored?

Each requirement is assessed as MET, NOT MET or not applicable against the assessment objectives in NIST SP 800-171A, and a single unmet objective makes the requirement NOT MET. Level 2 scoring starts at 110 and subtracts 5, 3 or 1 points for each unmet requirement, as set out in 32 CFR 170.24.

The weighting matters for training. Under 32 CFR 170.21, a Level 2 contractor can reach Conditional status with a POA&M only if its score is at least 80% of the maximum and every item on the POA&M is worth 1 point. Because AT.L2-3.2.1 and AT.L2-3.2.2 are 5-point requirements, a gap in general awareness or role-based training cannot be deferred and prevents Conditional status. A gap in insider threat awareness (1 point) can be placed on a POA&M, which must then be closed within 180 days.

CMMC assessment types and cycles (32 CFR Part 170)
CMMC statusWho assessesAssessment cycleAffirmation by a senior official
Level 1 (Self)ContractorAnnual self-assessment, no POA&M allowedAt assessment and annually
Level 2 (Self)ContractorEvery three yearsAt assessment and annually
Level 2 (C3PAO)Certified Third-Party Assessment OrganizationEvery three yearsAt assessment and annually
Level 3 (DIBCAC)Defense Contract Management Agency DIBCACEvery three years, plus a current Level 2 (C3PAO)At assessment and annually

The annual affirmation is where training records become a board-level matter. Section 170.22 requires an Affirming Official, a senior representative with authority over compliance, to attest to continuing compliance in the Supplier Performance Risk System (SPRS) each year. Training that lapses between assessments undermines that attestation. While Phase 2 is suspended, Level 2 status is obtained by self-assessment, so the affirmation carries more weight.

When do CMMC requirements apply?

The rule text phases CMMC into DoD contracts over four phases that started on November 10, 2025, when the DFARS acquisition rule took effect. The phases are defined in 32 CFR 170.3(e), each starting one calendar year after the previous one. However, on July 13, 2026 the Department announced the suspension of the Phase 2 requirements, and the program is paused in Phase 1 while a CMMC reform task force reviews it.

  1. Phase 1, from November 10, 2025: DoD intends to require Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations, and may require Level 2 (C3PAO) at its discretion. This is the phase in effect, and paused, as at September 2026.
  2. Phase 2, scheduled in the rule for November 10, 2026 but suspended: would add Level 2 (C3PAO) as a condition of award for applicable contracts, and Level 3 (DIBCAC) at DoD's discretion.
  3. Phase 3, one year after Phase 2 in the rule text: Level 2 (C3PAO) for all applicable contracts, including as a condition to exercise option periods, and Level 3 (DIBCAC) for all applicable contracts.
  4. Phase 4, one year after Phase 3 in the rule text: full implementation in all applicable solicitations and contracts, including option periods on older contracts.

The DFARS rule also explains that for three years after November 10, 2025, the clause appears only where program managers decide to apply a CMMC requirement; after that, it applies wherever the contractor will handle FCI or CUI, excluding purchases solely of commercially available off-the-shelf items. Under the implementing memo, program managers may designate only Level 1 (Self) or Level 2 (Self) during the suspension, and existing Level 2 (C3PAO) and Level 3 (DIBCAC) requirements are to be removed from solicitations and contracts. DFARS 252.204-7012 remains in effect, and the training requirements themselves are unchanged. Later phase dates depend on the outcome of the review; confirm the position against the solicitation in hand.

How can contractors map CMMC training requirements to learning outcomes and evidence?

Map each requirement to an observable learning outcome and to evidence an assessor can examine, because assessors test the objectives behind each requirement, not the existence of a course. The table below is illustrative and would need tailoring to each contractor's systems, roles and System Security Plan.

Illustrative mapping: CMMC requirement to learning outcome to assessment evidence
RequirementExample learning outcomeAssessment evidence
AT.L2-3.2.1 AwarenessUser identifies a phishing attempt and a mishandled CUI marking, and reports both through the correct channel.Role-scoped completion records for every in-scope user, scenario quiz results, and the policy versions covered.
AT.L2-3.2.2 Role-based trainingSystem administrator applies the organization's configuration baseline and audit log review procedure.Role-to-training matrix, completion and practical assessment records for each role named in the System Security Plan.
AT.L2-3.2.3 Insider threatManager recognizes potential insider threat indicators and knows who to notify.Insider threat module records, including a manager-specific version, and the documented reporting procedure.
AT.L3-3.2.1e Threat-focused trainingUser responds correctly to a current social engineering scenario.Training at hire, annually and after significant cyber events; records of annual content updates.
AT.L3-3.2.2e Practical exercisesPrivileged user completes a role-specific exercise and receives feedback.Exercise results by role, with feedback records to the individual and supervisor.

A training matrix linking each in-scope role to its requirements is the simplest way to show coverage. For a method, see how to map training to compliance obligations, and for assessment readiness, how to prepare training records for an audit. Organizations that also certify to ISO/IEC 27001 can reuse much of the same evidence; see ISO 27001 awareness training requirements.

How does Knowledge Foundry approach this?

Knowledge Foundry models each CMMC requirement and its NIST assessment objectives as nodes in a knowledge framework, then links them to roles, learning outcomes and assessment points. Coverage gaps by role are visible before an assessment, and the evidence trail supports the annual affirmation. See the approach for government and defense organizations.

Frequently asked questions

Does CMMC Level 1 require security awareness training?

No. Level 1 assesses the 15 basic safeguarding requirements in FAR 52.204-21, and none of them is a training requirement. Contractors at Level 1 still benefit from basic awareness training, because several Level 1 requirements, such as escorting visitors and controlling public information, depend on staff behavior.

Does CMMC use NIST SP 800-171 Revision 3?

No. 32 CFR Part 170 incorporates NIST SP 800-171 Revision 2 by reference, and CMMC Level 2 is assessed against its 110 requirements. NIST published Revision 3 in May 2024 and marks Revision 2 as withdrawn on its site, but the CMMC rule text has not been amended to adopt Revision 3 as at September 2026.

Does CMMC apply to companies outside the United States?

It can. The DFARS clause flows down to subcontractors at all tiers whose systems will process, store or transmit FCI or CUI in performance of the subcontract. A foreign supplier handling CUI for a US prime contractor on a DoD program can therefore need a CMMC status, including the Level 2 training requirements.

How often must CMMC awareness training be repeated?

Level 2 lets the contractor set the frequency, but 32 CFR 170.14(d) caps any periodic interval at one year, so annual refresh is the practical standard. Level 3 is explicit: training at initial hire, after a significant cyber event, and at least annually, with content updated at least annually.

Sources

  1. Cybersecurity Maturity Model Certification (CMMC) Program, final rule (89 FR 83092), US Department of Defense, Federal Register
  2. 32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations (eCFR)
  3. DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041), final rule (90 FR 43560), US Department of Defense, Federal Register
  4. Cybersecurity Maturity Model Certification (CMMC) program page, including the July 13, 2026 suspension of Phase II, US Department of Defense, Chief Information Officer
  5. Implementing Suspension of CMMC Phase II (memorandum, July 13, 2026), US Department of Defense, Chief Information Officer
  6. SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, National Institute of Standards and Technology (NIST) CSRC
  7. SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, National Institute of Standards and Technology (NIST) CSRC

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.