CMMC Training Services

Train for the
assessment.

Security awareness training is one of the most consistently cited deficiencies in DoD contractor assessments, not because organizations don't do training, but because they can't prove they did. 1TEN delivers training with verifiable completion records built for C3PAO review, and readiness programs that prepare your compliance leads for what assessors actually ask.

AT.L2 requirements 3.2.1, 3.2.2, and 3.2.3, all satisfied by documented, verifiable training
100% of personnel who handle CUI must complete role-based security awareness training
Verify assessors interview personnel and ask for completion records, not just whether training happened
3yr certification cycle with annual affirmations; training is an ongoing obligation

AT.L2 compliance with records that prove it.

CMMC AT.L2 requires that all personnel are aware of security risks, trained to carry out their responsibilities, and able to recognize and report threats. Most organizations do some version of this. Almost none can produce the documented, dated, per-person completion records that C3PAO assessors require. 1TEN's training is delivered through the platform and tracked at the individual level, with every completion timestamped and attributed.

CUI Awareness

What Controlled Unclassified Information is, how to identify it in your work, what handling requirements apply, and the consequences of improper handling.

Media Protection

Physical and digital media handling, storage, transport, and sanitization requirements, covering the controls your organization has implemented for each.

Threat Recognition & Reporting

Recognizing phishing, social engineering, and insider threat indicators. Who to report incidents to, how to report them, and what your IR process requires.

Role-based assignments & records

Courses assigned by role, tracked by individual, with timestamped completion records exportable for C3PAO review. Overdue items flagged automatically.

Set up training for your team

Prepare your compliance lead for the real process.

Your IT manager or compliance lead is about to sit across from a C3PAO assessor and answer questions about 110 security requirements. Most have never been through a formal assessment. Our readiness training is a structured program that walks through the assessment methodology, the specific questions assessors ask domain by domain, and how to present evidence effectively. This isn't a CMMC overview course. It's preparation for a specific professional experience with real consequences for your contracts.

Assessment methodology

How C3PAO assessments are structured: the Examine, Interview, and Test methods, how assessors move through domains, and what they look for at each stage.

Domain-by-domain interview prep

The actual questions from the CMMC Assessment Guide for each domain, walked through with your team so there are no surprises when your assessor asks them.

Evidence presentation

How to organize and present your evidence package so assessors can navigate it efficiently, and what happens when evidence is missing or doesn't match the SSP.

POA&M and findings management

What to do when an assessor identifies a finding, how to respond, document interim mitigations, and build a POA&M that assessors will accept.

Schedule readiness training

How training works.

From needs assessment to ongoing maintenance, training that stays current as your team and environment change.

01
Needs assessment

We understand your timeline, personnel structure, and current training posture, determining which training services apply and in what order.

02
Platform deployment

Security awareness training deployed through the 1TEN platform. Personnel accounts created, courses assigned by role, and the tracking system is live.

03
Completion and records

Personnel complete assigned courses. All completions tracked with timestamps. Records available immediately for C3PAO review, no preparation required.

04
Ongoing maintenance

Training renewals tracked automatically. New personnel onboarded to the program. Annual affirmation requirements supported by the compliance calendar.

Who training services are for.

Defense contractors preparing for C3PAO assessment

If your assessment is approaching and you don't have documented training records for all CUI-handling personnel, this is an urgent gap. AT.L2 is one of the first things assessors verify.

IT managers and compliance leads

If you're responsible for your organization's CMMC program and haven't been through an assessment before, readiness training prepares you for what's coming.

Organizations adding new personnel

Every new hire who accesses CUI-handling systems needs documented training. The 1TEN platform makes onboarding to the training program immediate and automatic.

Contractors with expired training records

Training completed more than a year ago may not satisfy annual renewal requirements. We help you identify who's overdue and get compliant records in place quickly.

MSPs managing DIB client compliance

If you're an MSP responsible for multiple DIB clients, the training module scales across client organizations while maintaining separate tracking and records per client.

Organizations post-certification

CMMC certification requires annual affirmations and ongoing compliance. Training renewals, new hire onboarding, and record maintenance are ongoing obligations.

Do-It-Yourself
Not looking for the full platform? Get all 10 CMMC awareness training templates — editable and control-mapped — for a one-time $799.
View the template set →

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo