Awareness and Training (AT): the 3 CMMC Level 2 requirements a subcontractor self-assesses
The Awareness and Training family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- SOC 2reuse candidates 2 high, 0 medium; 1 of 3 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 2 high, 1 medium; 0 of 3 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- CIS Controls v8reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
The requirements
3CMMC L2 AT.L2-3.2.1Role-Based Risk Awareness 5 points in the scoreMake managers, system administrators and users aware of the security risks their activities create and of the policies, standards and procedures governing the systems they use.
What an assessor asks to see: Security awareness materials covering risks, policies and procedures; Completion records by role including managers and administrators; Training schedule and refresher frequency
Where subcontractors usually fall short: Awareness aimed at general users only, omitting managers and administrators; Completion not tracked to individuals; Content generic and not tied to organizational policy
CMMC L2 AT.L2-3.2.2Role-Based Training 5 points in the scoreTrain personnel to perform the specific information security duties and responsibilities assigned to their roles.
What an assessor asks to see: Role to security duty mapping; Role based training content and completion records; Evidence training precedes assumption of the duty
Where subcontractors usually fall short: One generic course used for every role; Training delivered after the duty is already being performed; Specialized roles such as administrators given no additional training
CMMC L2 AT.L2-3.2.3Insider Threat Awareness 1 point in the scoreProvide awareness training that teaches staff to recognize potential insider threat indicators and to report them.
What an assessor asks to see: Insider threat awareness content covering indicators and reporting; Completion records; Defined reporting channel communicated to staff
Where subcontractors usually fall short: Insider threat omitted from awareness content; Indicators taught with no reporting route given; Training not refreshed