AT Domain

Awareness & Training CMMC Level 2

Ensure personnel understand their security role — 3 requirements covering 9 total SPRS points.

3 Requirements
9 SPRS Points at Risk
100% Complete Coverage

Awareness & Training Domain Overview

The Awareness and Training domain has 3 requirements focused on ensuring all personnel who handle CUI receive appropriate security awareness training and understand their security responsibilities. The most sophisticated technical controls fail when users unknowingly enable threats — clicking phishing links, mishandling CUI, using unauthorized storage. Personnel are both the largest attack surface and the first line of defense.

All 3 Awareness & Training Requirements

Every NIST SP 800-171 Rev 2 requirement in the AT family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
AT.L2-3.2.1Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems.5Conditional
AT.L2-3.2.2Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities.5Conditional
AT.L2-3.2.3Provide security awareness training on recognizing and reporting potential threats posed by social engineering, including phishing, pretexting, and tailgating.1Yes

How 1TEN Covers This Domain

Built-In Training Module

The Training module delivers role-based security awareness content directly on the appliance. Users complete training, acknowledge policies, and the platform records completion dates with timestamps and user attribution.

Training Completion Tracking

Every training event is logged with the user, date, content covered, and acknowledgment status. Assessors can see who completed training, when, and what material was covered. No spreadsheets required.

Social Engineering Awareness Content

Training content includes phishing recognition, social engineering indicators, and insider threat awareness. Satisfies 3.2.3 with documented delivery and completion records for every user.

Policy Acknowledgment Workflow

Users must acknowledge security policies before gaining system access. The acknowledgment is timestamped and stored as evidence that personnel are aware of applicable policies per 3.2.1.

Common Tools for AT Compliance

These tools are commonly used by defense contractors to satisfy AT requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will request training completion records showing all personnel have completed security awareness training. They’ll look at training content to verify it covers CUI handling, social engineering recognition, and reporting procedures. Expect interview questions about what training covers and how often it is refreshed.

Why This Domain Matters
Training is the requirement assessors verify first because it is the easiest to prove or disprove. Either you have dated records showing every user completed security awareness training, or you do not. There is no workaround.

Related Domains

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo