NIST SP 800-171 Rev. 2 does not require one magic annual course. Requirements 3.2.1–3.2.3 require general security awareness, role-based training for people with security duties, and training on recognizing and reporting potential insider-threat indicators.
For a small defense contractor, the useful test is whether the organization can show how the requirement applies inside the defined FCI/CUI boundary, who operates it, and what current evidence proves it is working.
The rule in plain English
3.2.1 covers awareness of security risks and applicable policies, standards, and procedures. 3.2.2 requires personnel to be trained for assigned information-security duties. 3.2.3 adds insider-threat recognition and reporting.
A defensible program separates general awareness from role-specific training. A bookkeeper who receives CUI by email needs a different depth of instruction from an administrator who manages identity, logging, backups, or firewalls.
How to implement it without overbuilding
Build the roster from the actual CUI environment. Identify who can access CUI, who administers in-scope systems, and who owns security processes. Use onboarding, periodic refreshers, and event-driven training after meaningful role or system changes.
The rule does not impose one universal frequency for every training element, so document the cadence you choose and why. Training should explain the contractor's real reporting path, not just generic cyber risks.
What evidence to keep
Keep completion records showing who completed which module, when, and under what role. Retain the training content/version, role-to-training matrix, onboarding records, overdue follow-up, and any targeted retraining.
Because assessment can include interviews, the retained record should match what users and administrators can actually explain.
Where teams get into trouble
A yearly phishing video is not the whole 3.2 family. Other weak patterns include giving administrators the same generic module as everyone else, leaving temporary staff off the roster, or teaching insider-threat indicators without a usable reporting channel.
Small-contractor walkthrough
A 35-person machine shop has office staff, engineers, two system administrators, and several operators who occasionally receive marked technical data. The useful training design separates general CUI awareness from the administrator and incident-response duties that require deeper instruction.
- List personnel with CUI/security duties.
- Separate general and role-based modules.
- Include insider-threat reporting.
- Record completion dates and content versions.
Decisions to document before assessment
Before marking this topic ready, make four decisions explicit: list personnel with cui/security duties; separate general and role-based modules; include insider-threat reporting; and record completion dates and content versions. Assign an owner and an evidence location to each decision.
Manual deep review: separate the three training outcomes and prove the population
Treat 3.2.1, 3.2.2, and 3.2.3 as three related outcomes rather than one annual course. For 3.2.1, identify the security risks created by the organization's own CUI activities and the policies, standards, and procedures personnel are expected to follow; the named audiences include managers, system administrators, and users. For 3.2.2, define the personnel who have information-security duties and train them for those duties. For 3.2.3, train managers and employees to recognize and report potential insider-threat indicators. A generic awareness video may support part of the family, but it does not automatically prove role-specific competence or a usable insider-threat reporting path.
Build the training roster from the CUI environment, not only the HR directory. Reconcile users, managers, administrators, VPN users, contractors, temporary personnel, incident-response roles, and relevant provider personnel against completion records. Maintain a role-to-training matrix with assigned duties, required content, initial-training trigger, refresher cadence chosen by the organization, and evidence location. Rev. 2 does not impose one universal annual frequency for all three requirements, so document the cadence you actually use rather than repeating a made-up rule.
For assessment, sample one ordinary user, one manager, and one administrator. Trace each person's access or security role to the training they should have received, then verify the completion date and content version. Interview them briefly. The user should know what to do with suspicious email or mishandled CUI; the manager should know the escalation path; the administrator should explain the security duties for which the organization says they were trained. For insider threat, confirm the material teaches both recognition and reporting.
Finally compare current policy to current training. If the company changed its CUI transfer method, remote-work rule, removable-media process, or incident contact but the course still teaches the old workflow, the program is stale even if the LMS shows 100 percent completion.
- Training content with version/date.
- Completion export mapped to named personnel.
- Role-assignment and role-specific training records.
- Insider-threat reporting instructions.
- Documented refresher cadence and change triggers.
Additional objective-level implementation notes
Training evidence should preserve what was taught, not only who clicked complete. Keep the content version or issue date with completion records so a reviewer can connect a person's completion to the actual CUI handling, incident reporting, insider-threat, and security-role instructions in force at that time. When a material process changes, decide whether content must be updated or reissued instead of assuming every document edit requires retraining.
Check the people most likely to fall between systems: contractors, temporary administrators, managers who rarely touch the LMS, and provider personnel who perform security duties. Compare their current access and assigned duties to the roster. If someone is excluded, document why the person is outside the applicable training population rather than letting the omission remain unexplained.
Final manual spot check
For a final spot check, compare the current training matrix with the access list for the CUI environment and the list of assigned security duties. Any manager, administrator, contractor, or user who appears in one list but not the other should have a documented reason. Then verify that the person received the correct content version before or within the organization's defined training window and that any role change triggered the appropriate role-specific update.
A short working check
- ✓List personnel with CUI/security duties.
- ✓Separate general and role-based modules.
- ✓Include insider-threat reporting.
- ✓Record completion dates and content versions.
- ✓Document cadence and triggers.
- ✓Interview a sample of users.
Common questions
Does CMMC require annual awareness training?
Rev. 2 requires awareness and training but does not create one universal annual-frequency sentence for all three requirements. Choose and document a reasonable cadence, then follow it consistently.
Is phishing training enough?
Usually not. The requirements are broader and should address applicable risks, policies, security duties, and insider-threat reporting.
Who needs role-based training?
Personnel assigned information-security duties, such as administrators, incident responders, and others who operate security controls.
What proves training happened?
Dated completion records plus the content actually delivered are much stronger than a policy statement alone.
Does every employee need the same CMMC training?
No. General awareness and role-specific security training serve different purposes; document which populations receive which content and why.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.




