Ensure personnel understand their security role — 3 requirements covering 9 total SPRS points.
The Awareness and Training domain has 3 requirements focused on ensuring all personnel who handle CUI receive appropriate security awareness training and understand their security responsibilities. The most sophisticated technical controls fail when users unknowingly enable threats — clicking phishing links, mishandling CUI, using unauthorized storage. Personnel are both the largest attack surface and the first line of defense.
Every NIST SP 800-171 Rev 2 requirement in the AT family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| AT.L2-3.2.1 | Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems. | 5 | Conditional |
| AT.L2-3.2.2 | Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities. | 5 | Conditional |
| AT.L2-3.2.3 | Provide security awareness training on recognizing and reporting potential threats posed by social engineering, including phishing, pretexting, and tailgating. | 1 | Yes |
The Training module delivers role-based security awareness content directly on the appliance. Users complete training, acknowledge policies, and the platform records completion dates with timestamps and user attribution.
Every training event is logged with the user, date, content covered, and acknowledgment status. Assessors can see who completed training, when, and what material was covered. No spreadsheets required.
Training content includes phishing recognition, social engineering indicators, and insider threat awareness. Satisfies 3.2.3 with documented delivery and completion records for every user.
Users must acknowledge security policies before gaining system access. The acknowledgment is timestamped and stored as evidence that personnel are aware of applicable policies per 3.2.1.
These tools are commonly used by defense contractors to satisfy AT requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will request training completion records showing all personnel have completed security awareness training. They’ll look at training content to verify it covers CUI handling, social engineering recognition, and reporting procedures. Expect interview questions about what training covers and how often it is refreshed.
Training is the requirement assessors verify first because it is the easiest to prove or disprove. Either you have dated records showing every user completed security awareness training, or you do not. There is no workaround.
1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.
Request a Demo