ClickCerts
Back to all posts

CMMC and Security Awareness Training: What the Framework Actually Requires

CMMC Phase 2 starts November 2026. What the framework requires for security awareness training, what assessors look for, and how ClickCerts fits.

June 11, 2026ClickCerts Team
CMMC and Security Awareness Training: What the Framework Actually Requires

CMMC and Security Awareness Training: What the Framework Actually Requires A guide for defense contractors and subcontractors. What the controls say, what assessors look for, and what evidence wins.

November 10, 2026, is the date most contractors should be circling on a calendar. That’s when CMMC enters Phase 2, and contracts that involve Controlled Unclassified Information (CUI)start requiring a third-party assessment by a C3PAO instead of a self-assessment. No more checking your own work. An accredited assessor walks through your environment, reviews your evidence, interviews your people, and decides whether you get certified. If you don’t, you can’t bid.

If you’re a defense contractor, or a subcontractor, or you’re in any tier of the defense supply chain handling CUI, you’re probably already in some stage of preparation. The window is short. Achieving Level 2 readiness typically takes 12 to 18 months. Phase 1 (self-assessments) has been live since November 2025, and prime contractors are already passing flow-down requirements down to their subs. According to Redspin’s November 2025 report, 47% of contractors surveyed had already received flow-down demands from their primes.

This post is about one specific piece of CMMC: the security awareness training requirement. We’ll walk through what the framework actually says, what assessors look for in practice, why most existing training programs don’t produce the right evidence, and how to satisfy the control without overspending. The CMMC program is much bigger than training, but training is one of the controls assessors will review and one of the easiest places to fail an audit unnecessarily.

CMMC in two minutes

Quick framework refresher for anyone still getting their head around the program.

CMMC stands for Cybersecurity Maturity Model Certification. It’s a Department of Defense program that requires defense contractors and their subcontractors to meet specific cybersecurity standards before they can be awarded contracts that involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The framework has three levels.

Level 1 covers basic safeguarding for FCI. Fifteen practices. Annual self-assessment. Most small commercial contractors handling only FCI fall here. Level 2 is where most contractors land. It aligns directly with the 110 security requirements in NIST 800-171 Revision 2, covering 14 control families from Access Control to System and Information Integrity. Most Level 2 contracts will require a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO), not a self-assessment. Level 3 is reserved for contractors supporting the most sensitive DoD programs and adds enhanced requirements from NIST 800-172. Less than 2% of organizations need Level 3.

If you handle CUI, you almost certainly need Level 2. The DoD has published an estimated cost for the C3PAO assessment alone of $105,000 to $118,000, with total first-year compliance investment for small and midsize contractors typically running $75,000 to $200,000. The assessment fee is roughly 25 to 30% of total spend. Remediation, documentation, and the surrounding controls take up the rest.

What CMMC actually requires for security awareness training

The training requirement lives in NIST 800-171’s Awareness and Training (AT) family. CMMC Level 2 inherits these word-for-word. Three controls.

3.2.1 (Literacy Training and Awareness). Ensure that managers, system administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. Plain English: every employee who touches your systems needs general security awareness training.

3.2.2 (Role-Based Training). Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. Plain English: people in security-relevant roles (admins, security officers, anyone with privileged access) need training specific to their role on top of the general awareness training.

3.2.3 (Insider Threat Awareness). Provide security awareness training on recognizing and reporting potential indicators of insider threat. Plain English: training has to cover insider threat recognition specifically, not just external attacks.

On paper, that’s the entire requirement. Three controls, total. Compared to the rest of the 110 controls in NIST 800-171, this is one of the more straightforward families. But the simplicity is deceptive. The hard part isn’t implementing the training. The hard part is producing the evidence.

What assessors actually look for

CMMC controls aren’t scored on whether you say you do something. They’re scored on whether you can prove it during an assessment. NIST 800-171A (the assessment guide) gives assessors specific determination statements they have to verify. For training, the questions break down roughly like this.

Did the training actually happen? Show me. Not a policy document saying training is required. Actual records of who completed which training, when. Names. Dates. Module names.

Is the training current? When was it last updated? When was it last delivered? Can you show that personnel are receiving training at the frequency your policy says, on an ongoing basis, not just at hire?

Does the content match the requirements? Does it cover security risks of the systems people use? Does it cover applicable policies and procedures? Does it specifically address insider threat recognition (the 3.2.3 requirement that often gets missed)?

Is role-based training happening for personnel in privileged or specialized roles? Can you show that your sysadmins, security officers, or other privileged users are receiving training above and beyond the general awareness baseline?

Is the evidence retrievable? An assessor on a tight timeline isn’t going to wait while you reconstruct a year of training records from email archives. They want clean, accessible records produced in minutes.

Why most existing training programs fail the evidence test

Plenty of companies have security awareness training. Far fewer have security awareness training that produces the audit trail a CMMC assessor will accept.

The most common failure modes look like this. A one-time training session at hire, with no recurrence. The control requires ongoing training; one session in onboarding doesn’t satisfy it. Training is delivered, but no records are kept. Or records are kept in someone’s email inbox, which works fine until that person leaves or the inbox gets archived. Training covers phishing and password hygiene but doesn’t address insider threat (3.2.3 specifically), creating a gap an assessor will catch. Sysadmins and privileged users get the same generic training as everyone else, with no role-based component, missing 3.2.2 entirely.

Then there’s the issue of training content age. Many organizations are running training videos produced three or four years ago. Threats have evolved. AI-generated phishing, deepfake voice attacks, QR-code phishing, polymorphic email patterns. An assessor reviewing your training content for currency may not formally fail you for showing 2022 content, but it will raise concerns and may show up in their notes.

The CMMC ecosystem reports show this gap clearly. Redspin’s 2025 study found that 60% of defense contractors increased their training spending in the past year, up from 37% the prior year. The pattern is unmistakable. Contractors are realizing during preparation that their existing training programs don’t produce the evidence assessors will demand.

What a training platform needs to do to satisfy the controls Strip the marketing copy off whatever you’re evaluating and the platform needs to do five things to satisfy the AT family controls cleanly.

Cover the right topics. General security awareness, phishing, social engineering, password and credential hygiene, data handling, incident reporting, and insider threat recognition. The last one is non-negotiable. 3.2.3 calls it out specifically and a platform that doesn’t address insider threat will leave you with a gap.

Stay current. The threat landscape changes fast. Training content needs to be refreshed at least annually, ideally with a quarterly cadence of new modules, so you can show an assessor that what your people are taking now reflects what attackers are actually doing now.

Produce verifiable records. Names, dates, module titles, completion status, certificates with serial numbers. The platform should let you export these in formats an assessor can review without explanation.

Support recurring delivery. Quarterly is the cadence that satisfies “ongoing” for most assessors. The platform should automate the cadence so training continues without admin intervention.

Handle role-based training. Either through dedicated role-specific modules or through documented policy that admins and privileged users complete the same training plus additional materials specific to their duties. 3.2.2 requires a story here even if the requirements are met informally.

What ClickCerts is, and what it isn’t

ClickCerts is purpose-built for the security awareness training requirement specifically. Four certificate-awarding courses per user per year, released one per quarter, all aligned with current threats and CMMC and NIST 800-171 frameworks. Each course refreshes annually so the content tracks the threat landscape, not last year’s. Insider threat is built into the curriculum, not an add-on. Every employee who completes a course gets a real certificate with a serial number, an issue date, and an expiration date that automatically triggers recertification when it’s due.

Admins get a clean dashboard that shows who’s completed what, who’s overdue, and who’s currently certified. When an assessor asks for evidence, you export it. When they want to verify a specific certificate, there’s a public verification page they can hit themselves to confirm it’s real and not fabricated.

Pricing is $18 per user per year for small teams, dropping to $12 for larger ones. Everything is included. Compared to the $105,000+ you’re going to spend on the C3PAO assessment alone, the training piece becomes a rounding error.

To be clear about what ClickCerts is not. It’s not a complete CMMC compliance solution. CMMC requires 110 security controls under Level 2, covering 14 control families. ClickCerts handles the three controls in the Awareness and Training family cleanly. The other 107 controls (access management, audit logging, encryption, configuration management, incident response, and many more) require other tools, processes, and documentation. Most contractors will engage a Registered Practitioner Organization (RPO) or a CMMC consultant to drive the broader program. ClickCerts handles the training piece so you can check that family off and focus your budget where the real complexity lives.

What you’ll need beyond training Quick reality check on the broader CMMC program for anyone using this post as a starting point.

System Security Plan (SSP). The foundational document describing how your organization implements each of the 110 controls. Required. Most contractors take 50 to 200 hours to develop one, or pay $5,000 to $25,000 to outsource it. If you’re handling CUI, you should already have started this.

CUI scope and enclave decisions. Where does CUI live in your environment? Can you isolate it to a smaller enclave (a subset of systems, networks, and applications) instead of trying to certify your entire IT estate? Scoping decisions early in the process can cut compliance costs by 30 to 50%.

Cloud platform compliance. If you process CUI in Microsoft 365, you likely need GCC High or M365 GCC. Standard commercial M365 doesn’t meet the requirements. Same logic for AWS (GovCloud) and other cloud platforms. This decision often dominates the cost discussion.

Multi-factor authentication, encryption, audit logging, vulnerability scanning, incident response procedures, configuration baselines. The technical controls. Some of these you may already have. Most contractors find gaps during their initial gap analysis.

A Plan of Action and Milestones (POA&M). A document tracking any controls you haven’t fully implemented yet, with deadlines for closing the gaps. CMMC allows POA&Ms for some controls but not others, and any POA&M items have to be closed within 180 days for final certification.

This is not a comprehensive list. The full program is detailed, technical, and unforgiving in places. If you’re early in your CMMC journey, the right next step is engaging an RPO or consultant for a gap assessment. They’ll tell you exactly where you stand against all 110 controls, what to prioritize, and how to budget realistically.

++++

CMMC certification is a real investment. The C3PAO assessment alone is six figures. Total first-year spend for most small and midsize contractors lands somewhere between $75,000 and $200,000. The clock is running. Phase 2 starts November 10, 2026. Major primes are already requiring CMMC documentation from their subs.

In the middle of all that complexity, security awareness training is one of the few controls where you can move fast, satisfy the requirement cleanly, produce the audit trail an assessor wants, and keep the cost in proportion to the value. Quarterly delivery, current content, certificates with serial numbers, role-based coverage where it applies. Done.

If you’re working through CMMC preparation and looking at security awareness training as one of the line items on your remediation list, ClickCerts is a clean, focused fit for that specific control family. Email sales@clickcerts.com or schedule a demo to see how the certificate trail and reporting line up against the AT-family evidence requirements.

***Related reading: “*You Don’t Need 1,000 Training Modules. You Need Your Team Trained.” for the broader simplicity argument. “60% of Breaches Start with a Click. Here’s How to Stop Yours.” for the underlying threat data behind why training matters in the first place.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.