Skip to main content
Trusted by Hundreds of MSPs

CMMC security awareness training requirements

CMMC Level 2 — Awareness and Training (AT), per NIST SP 800-171. What the controls say, how often you have to train, what an assessor will ask to see, and the detail that fails most assessments.

app.hooksecurity.co/dashboard
Security Overview

Last 30 days

↓ 73% risk reduction
1,247
Phishing Tests
+12%
94.2%
Pass Rate
+8%
3,892
Trained Users
+156
Recent Activity
Phishing simulation completed
Marketing Team
2m ago
Training module finished
john.doe@company.com
15m ago
Suspicious click detected
sarah.smith@company.com
1h ago

Who this applies to

Defense industrial base contractors and subcontractors handling Controlled Unclassified Information.

The controls

AT.L2-3.2.1Security awareness

Managers, system administrators and end users are made aware of the security risks associated with their activities, and of the policies, standards and procedures related to system security.

AT.L2-3.2.2Role-based training

Personnel are trained to carry out their assigned information-security-related duties. Generic awareness content covers the floor but does not satisfy this control on its own.

AT.L2-3.2.3Insider threat awareness

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

How often you have to train

Annually at minimum, plus additional training when a user changes role or a significant new threat emerges.

What an assessor will ask to see

  • Awareness training records for all users, managers and administrators
  • Separate role-based training evidence for personnel with security duties
  • Insider threat awareness content and completion records
  • Evidence of event-driven training when roles changed or threats emerged

The detail that fails most assessments

AT.L2-3.2.2 is the one that fails assessments. Organizations run a single awareness course for everybody and have nothing separate to show for personnel with specific security responsibilities.

How Hook Security fits

Hook Security covers AT.L2-3.2.1 and AT.L2-3.2.3 directly, including insider threat content. Role-based training under AT.L2-3.2.2 needs deliberate assignment — talk to us about how to structure it rather than assuming a single course covers it.

Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.

The same records answer a cyber insurance questionnaire — see what underwriters ask for.

Show us your CMMC scope. We will tell you what we cover.

Thirty minutes, a live account, and an honest answer about the gaps.