Subcontractor CMMC Tracker

Awareness and Training (AT): the 3 CMMC Level 2 requirements a subcontractor self-assesses

The Awareness and Training family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

3
CMMC L2 AT.L2-3.2.1Role-Based Risk Awareness 5 points in the score

Make managers, system administrators and users aware of the security risks their activities create and of the policies, standards and procedures governing the systems they use.

What an assessor asks to see: Security awareness materials covering risks, policies and procedures; Completion records by role including managers and administrators; Training schedule and refresher frequency
Where subcontractors usually fall short: Awareness aimed at general users only, omitting managers and administrators; Completion not tracked to individuals; Content generic and not tied to organizational policy
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AT.L2-3.2.2Role-Based Training 5 points in the score

Train personnel to perform the specific information security duties and responsibilities assigned to their roles.

What an assessor asks to see: Role to security duty mapping; Role based training content and completion records; Evidence training precedes assumption of the duty
Where subcontractors usually fall short: One generic course used for every role; Training delivered after the duty is already being performed; Specialized roles such as administrators given no additional training
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AT.L2-3.2.3Insider Threat Awareness 1 point in the score

Provide awareness training that teaches staff to recognize potential insider threat indicators and to report them.

What an assessor asks to see: Insider threat awareness content covering indicators and reporting; Completion records; Defined reporting channel communicated to staff
Where subcontractors usually fall short: Insider threat omitted from awareness content; Indicators taught with no reporting route given; Training not refreshed
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)