The AT Domain in CMMC Level 2
The Awareness and Training (AT) domain contains 3 of the 110 NIST SP 800-171 requirements that make up CMMC Level 2. It is one of the smaller domains by requirement count, but it carries real assessment weight: two of the three AT requirements carry no POA&M eligibility, meaning gaps must be closed before certification.
The underlying premise is straightforward. Technical controls protect systems, but people operate those systems. An employee who clicks a phishing link, forwards CUI to a personal email, or plugs in an unknown USB drive can circumvent even a well-architected security environment. Training is what connects policy to behavior.
Security awareness training is also one of the most frequently cited deficiencies in DoD contractor assessments. The problem is rarely that organizations do no training at all. It is that they have no records to prove what was covered, who completed it, and when it was delivered. Assessors need evidence, and informal or undocumented training does not satisfy the requirement.
The 3 AT Requirements
NIST SP 800-171 organizes the AT domain under Section 3.2. Each requirement maps directly to a CMMC practice identifier.
| Practice | Requirement | SPRS Pts | POA&M |
|---|---|---|---|
| AT.L2-3.2.1 | Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems. | 3 | No |
| AT.L2-3.2.2 | Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities. | 3 | No |
| AT.L2-3.2.3 | Provide security awareness training on recognizing and reporting potential threats posed by social engineering, including phishing, pretexting, and tailgating. | 3 | Yes |
AT.L2-3.2.1 covers general security risk awareness. Every employee who touches CUI or operates systems in scope needs to understand the risks associated with their activities and know where to find the policies that govern their behavior.
AT.L2-3.2.2 is role-specific. It requires that personnel are actually trained to perform their assigned security responsibilities, not just told they have them. An IT administrator managing account provisioning needs different training than an engineer reviewing drawings on a CAD workstation.
AT.L2-3.2.3 specifically targets social engineering. CMMC explicitly names phishing, pretexting, and tailgating as threat vectors that training must address. This is the only AT requirement eligible for a POA&M, though having a plan to implement it is not the same as having it in place.
What the Training Content Must Include
CMMC does not specify a curriculum, a minimum duration, or a required vendor. What it requires is that training be sufficient to produce the outcomes stated in each practice. Assessors evaluate content against those outcomes, not against a checklist of topics.
In practice, a training program that satisfies all three AT requirements will cover the following areas.
| Topic | Practice Addressed |
|---|---|
| What CUI is and how to identify it in your environment | AT.L2-3.2.1 |
| Applicable security policies and where to find them | AT.L2-3.2.1 |
| How to handle, store, and transmit CUI correctly | AT.L2-3.2.1 |
| How to report a suspected security incident or CUI spill | AT.L2-3.2.1, AT.L2-3.2.3 |
| Role-specific responsibilities for IT staff, privileged users, and CUI handlers | AT.L2-3.2.2 |
| Phishing recognition and what to do when targeted | AT.L2-3.2.3 |
| Pretexting and social manipulation tactics | AT.L2-3.2.3 |
| Tailgating and physical security awareness | AT.L2-3.2.3 |
| Insider threat indicators and reporting obligations | AT.L2-3.2.1, AT.L2-3.2.2 |
General cybersecurity awareness training from a commercial provider can satisfy portions of 3.2.1 and 3.2.3 if the content addresses your organization's specific policies and the CUI environment your personnel work in. Off-the-shelf training that has no connection to your environment, your policies, or the specific CUI categories you handle is harder to defend to an assessor.
Role-Based Training: Where Most Small Contractors Fall Short
AT.L2-3.2.2 is the requirement most small DIB contractors underestimate. It does not ask whether training happened. It asks whether personnel were trained to carry out their specific security responsibilities. That distinction matters.
A single annual awareness course pushed to all employees does not satisfy 3.2.2 on its own. Consider what different roles are actually responsible for.
| Role | Assigned Security Responsibilities | Training Required |
|---|---|---|
| All personnel | General security awareness, CUI recognition, incident reporting | Annual general security awareness |
| CUI handlers | Correct handling, storage, transmission, and marking of CUI | CUI-specific training at time of access authorization and annually |
| IT administrators | Account management, patch management, access control, log review | System administrator security training, privilege management |
| Privileged account holders | Elevated access controls, separation of duties, audit log responsibilities | Privileged account management and monitoring |
| Incident response personnel | Detection, containment, reporting to DoD DIBCAC if required | Incident handling procedures, DFARS 7012 reporting requirements |
The documentation burden here is not just a record of who completed a course. It is a record showing which roles exist, which security responsibilities those roles carry, what training was assigned to those roles, and who completed that training. That paper trail is what assessors examine under 3.2.2.
Documentation: What You Need to Prove Compliance
Training that is not documented is training that did not happen from an assessor's perspective. The NIST SP 800-171A Assessment Guide specifies that assessors will examine training records as part of evaluating AT domain objectives. That examination has a specific scope.
A complete AT domain documentation package includes the following elements.
| Document | What It Shows |
|---|---|
| Training completion records | Each employee's name, the course completed, and the completion date. Timestamped certificates tied to specific courses are the clearest form of evidence. |
| Training curriculum or course outline | The topics covered, the materials used, and how the content maps to AT domain requirements. A one-line course title is not sufficient. |
| Role-to-training assignment matrix | Which roles exist, which training is required per role, and who occupies each role. This is the foundation for demonstrating 3.2.2 compliance. |
| Annual renewal schedule and completion status | Proof that training is not a one-time event. Annual cadence is the standard expectation. The Compliance Calendar should generate renewal tasks automatically. |
| New hire training records | Evidence that personnel complete required training before or shortly after receiving access to CUI systems. |
Annual retraining is the baseline expectation across all three requirements. Additional training is required when significant changes occur in your security policies, when personnel move into roles with elevated security responsibilities, or when new CUI categories are introduced into your environment.
What Assessors Look For During a C3PAO Assessment
C3PAO assessors evaluate the AT domain using examine, interview, and test methods. For a domain that is primarily about people and process, the interview component carries significant weight alongside documentation review.
Assessors will request training completion records showing all in-scope personnel have completed security awareness training. They will review training content to verify it addresses CUI handling, social engineering recognition, and incident reporting procedures. They will ask interview questions about what training covers, how often it is refreshed, how new hires are trained before receiving access, and what happens when training lapses.
A common assessor finding is a training program that exists on paper but has gaps in completion. If three out of fifteen employees have overdue renewals on assessment day, that is a finding against 3.2.1 even if the other twelve are current. All in-scope personnel must have current records, not most of them.
Assessors also look for whether training content is meaningful or perfunctory. A ten-minute annual course that consists of policy acknowledgment checkboxes with no substantive instruction is harder to defend than a structured program with defined learning objectives. The content review portion of the assessment is where a weak program gets challenged.
Common AT Domain Gaps in Small DIB Companies
Most small defense contractors do some form of security training. The gaps that produce AT domain findings are usually not about effort. They are about documentation, completeness, and role differentiation.
| Gap | Why It Creates a Finding |
|---|---|
| No completion records | Training occurred but cannot be proven. Assessors cannot credit undocumented controls regardless of intent. |
| One-size-fits-all course with no role differentiation | General awareness training does not satisfy 3.2.2's requirement to train personnel on their assigned security responsibilities. Roles with elevated responsibilities need additional training. |
| Training not specific to the organization's environment | Generic vendor training that does not reference your CUI categories, your policies, or your specific systems is harder to defend to an assessor evaluating 3.2.1. |
| Stale completion records | Training completed two or three years ago without annual renewal is a gap. Annual cadence is the baseline expectation. |
| New hires not trained before accessing CUI systems | A pattern of delayed onboarding training creates a condition where personnel have access before training is complete. That is a 3.2.1 gap. |
| Social engineering coverage absent or minimal | 3.2.3 specifically requires training on phishing, pretexting, and tailgating. Omitting any of the three named vectors is a finding. |
Frequently Asked Questions
No. CMMC does not mandate a specific vendor, platform, or curriculum. The requirement is that training produces the outcomes specified in each practice. You can use a commercial security awareness platform, conduct in-house instructor-led training, or use a built-in training module within your compliance platform. What matters is the content, the documentation of completion, and the currency of records.
Annual training is the standard expectation for all in-scope personnel. NIST SP 800-171 does not specify a minimum frequency explicitly, but NIST guidance and assessor practice treat annual completion as the baseline. Additional training is expected when there are material changes to your security posture, policies, or the systems your personnel operate.
Yes, if they have access to CUI or operate within the scope of your assessed environment. AT.L2-3.2.1 applies to "personnel" without limiting that to direct employees. Third-party contractors who regularly access your systems or CUI need to be covered by your training program or demonstrate equivalent training through their own organization. You need documentation either way.
Phishing simulations are useful evidence and assessors view them favorably, but a simulation alone does not satisfy 3.2.3. The requirement is to provide training on recognizing and reporting threats, which requires instructional content explaining the attack vector, how to identify it, and what to do. Simulations that are paired with remedial training content for recipients who fail are the strongest approach. Tracking simulation results also gives you assessor-ready documentation of your program's reach.
Overdue training for any in-scope employee is a finding against AT.L2-3.2.1 or 3.2.2 depending on the nature of the lapse. Because 3.2.1 and 3.2.2 are not POA&M-eligible, gaps cannot be deferred. The assessment will reflect the deficiency. Completing the overdue training before the assessment closes the gap, but the finding must be recorded if the gap existed during the assessment period. Automated renewal tracking and reminder systems prevent this situation from occurring.
Yes. The 1TEN Training module supports role-based course assignment, completion tracking, certificate issuance, and automatic sync into AT domain objectives within the Requirements Browser. Completion records are timestamped and tied to the individual, course, and date, which is the evidence format assessors expect. Annual renewal tasks are generated automatically through the Compliance Calendar. The module ships on the 1TEN appliance with no external platform required.