Training Resource

CUI Awareness Training: CUI-101 for Defense Contractors

A CUI training requirement sounds simple until you have to prove your workforce understands markings, handling, transmission, reporting, and need-to-know. This guide breaks down what your training should actually cover, and includes a free downloadable CUI-101 template.

Request a demo →

Updated April 20, 2026

Why It Matters What It Should Cover Domains Mapped Free Resource Admin Notes FAQ

CUI Training Is Not a Check-the-Box Exercise

Most CUI mistakes do not happen because someone never heard the term. They happen because employees do not recognize markings, do not understand which systems are approved, forward something to the wrong place, leave a document unsecured, or fail to report an incident fast enough. A training slide deck that says "protect CUI" is not enough. Your workforce needs practical instruction tied to how CUI moves through your environment.

A solid CUI-101 course should teach employees what CUI is, how to recognize it, how to handle it in both physical and digital form, how to transmit it properly, and what to do the moment something goes wrong. The free template that accompanies this page covers exactly those basics. It is designed to give small defense contractors a usable starting point rather than another vague policy artifact.

Primary CMMC Alignment
This training most directly supports the Awareness & Training domain, especially the expectation that personnel receive security awareness instruction and that role-based training is provided where responsibilities require it. But once you look at the actual subject matter, storage, transmission, access, incident reporting, and approved systems, the overlap reaches well beyond AT.

What CUI Awareness Training Should Actually Cover

If your training is meant to prepare employees to handle CUI correctly, it should cover the situations they are most likely to face in the real world. The CUI-101 template includes the core topics below.

1. What CUI is

Employees need a plain-language explanation of CUI, how it differs from classified information, and why it still carries legal safeguarding requirements. They also need examples relevant to defense contracting, such as technical data, export-controlled information, proprietary business information, procurement information, and privacy-related records.

2. How to recognize CUI markings

Training should show the actual markings employees are expected to encounter: banner markings such as CUI or CONTROLLED, category indicators like CUI//SP-CTI, and designation indicator blocks that identify the controlling office, category, dissemination instructions, and point of contact.

3. Employee responsibilities

People need direct instruction on what they must do and what they must never do. That includes using approved systems only, protecting access, verifying recipients before sharing, securing workstations, avoiding personal devices and unapproved cloud storage, and treating missing or exposed CUI as a reportable event.

4. Physical handling

A real training program covers storage in locked rooms or containers, securing documents before leaving a work area, retrieving copies from printers, applying markings to reproductions, and destroying CUI with approved methods rather than throwing it in normal trash or recycling.

5. Digital handling and transmission

This is where many organizations get sloppy. Employees need clear rules for email, remote access, file transfer, file storage, screen protection, and approved platforms. If your environment requires encrypted email, VPN, MFA, or specific approved repositories for CUI, the training should say that plainly.

6. Need-to-know and sharing rules

Access to CUI is not automatic just because someone works for the company. Training should reinforce authorization, need-to-know, proper channels, and proper marking before information is shared internally, externally, or with visitors and contractors.

7. Incident reporting

Employees must know how to report lost devices, wrong-recipient emails, unsecured documents, unauthorized access, suspicious copying, or phishing attempts targeting CUI. The reporting path should be named directly in the training so there is no hesitation when something goes wrong.

CMMC Domains This CUI-101 Training Touches

The primary domain here is AT — Awareness & Training. That is the center of gravity. But good CUI training also reinforces controls in other domains because it teaches people how those controls show up in day-to-day work.

DomainWhy this training touches it
AT — Awareness & TrainingThe core purpose of the resource. It teaches personnel how to recognize and properly handle CUI and reinforces workforce awareness obligations.
AC — Access ControlNeed-to-know, recipient verification, approved systems, visitor control, and restrictions on unauthorized sharing all reinforce access control behavior.
MP — Media ProtectionPhysical document storage, reproduction, destruction, print handling, removable media restrictions, and transport rules all sit directly in media protection territory.
PE — Physical ProtectionLocking documents away, protecting visible screens, escorting visitors, and securing areas where CUI is processed all support physical safeguards.
SC — System & Communications ProtectionEncrypted email, approved file transfer methods, VPN use, and secure transmission procedures reinforce communication protection requirements.
IR — Incident ResponseThe training teaches employees when and how to report suspected or actual exposure, loss, theft, or mishandling of CUI.
SI — System & Information IntegritySuspicious activity awareness, phishing indicators, and prompt escalation of anomalies help support integrity and threat response expectations.
Important distinction
This does not mean a CUI awareness deck satisfies those entire domains by itself. It means the training reinforces user-side behavior that supports them. The primary compliance purpose is still AT. The rest is operational spillover, which is exactly why the training matters.

Free Download: CUI-101 Awareness Training Template

The downloadable template is built as a practical awareness deck for defense contractors. It covers the basics employees actually need: defining CUI, common categories, marking recognition, responsibilities, physical handling, digital handling, transmission, need-to-know, incident reporting, and common mistakes to avoid.

It is intentionally written as a baseline template. That means you still need to customize it to your environment. Your reporting contacts, approved systems, mailing instructions, encryption methods, and internal processes should be inserted before you use it.

Free Resource — CUI-101 Awareness Training Template
PowerPoint deck for internal CUI awareness training. Add your security contacts, reporting instructions, approved tools, and acknowledgment workflow before rollout. Download the template →

CUI-101 is one of ten. If you need the full role-based set — Insider Threat, Phishing, Media Protection, Incident Reporting, and more — see the complete CMMC training template library ($799 for all ten).

What Your Organization Still Needs to Add

A training file is not a training program. Before you deploy it, you need to decide how completion will be documented, whether employees must acknowledge the material, how annual retraining will be tracked, and what happens when your handling rules change. Those administrative details matter because assessors do not just ask whether training exists. They ask whether it is assigned, completed, and maintained.

At minimum, customize these sections before use:

  • Security officer name, email, phone number, and after-hours reporting path
  • Approved systems for CUI handling, storage, and transmission
  • Email and file transfer requirements specific to your environment
  • Remote access rules, including VPN and MFA expectations
  • Visitor and contractor handling instructions
  • Training completion, acknowledgment, and annual retraining workflow
The gap most companies miss
They build a decent slide deck, present it once, and never tie it back to a repeatable system. If your training records live in inboxes, spreadsheets, or memory, you are building future assessment pain for yourself.

1TEN is built to close that gap. Training assignments, acknowledgments, evidence, and role-based workflows belong in the same operational system as the rest of your compliance program. That is how you stop training from becoming another disconnected artifact.

Frequently Asked Questions

Does this CUI-101 template satisfy CMMC by itself?

No. It helps satisfy the training side of the requirement, but only after you customize it to your environment, assign it to the right personnel, record completion, and maintain retraining. A slide deck alone is not evidence of an operating program.

Who should receive CUI awareness training?

Anyone who may access, handle, store, transmit, or support the protection of CUI should receive it. In practice, that usually includes engineering, quality, program management, contracts, IT, leadership, and any administrative personnel who may touch controlled data or systems.

How often should CUI awareness training be repeated?

At least annually is the normal baseline, with additional training when responsibilities change, new systems are introduced, or a security event shows the current training is not landing.

Why does this page map more domains than AT?

Because the training topics overlap with real operational controls. Teaching employees not to send CUI over unapproved channels touches SC. Teaching them to secure physical documents touches MP and PE. Teaching them to report exposure touches IR. The primary domain is still AT, but the behavior overlaps are real.

Can I give this training without editing the placeholder slides?

You can, but you should not. Placeholder security contacts, generic instructions, and unspecified approved systems weaken the training and create obvious holes if anyone later asks what employees were actually told to do.

Your SPRS score, live.

1TEN maps your documented controls to all 110 NIST SP 800-171 requirements and scores your posture in real time.

Request a Demo