Velocity Knowledge Logo

© 2026 Velocity Knowledge. All rights reserved.

Cybersecurity | Federal and Defense Compliance
July 21, 2026
Mark Rogers, President - Velocity Knowledge
9 min

CMMC Compliance Training: What Defense Contractors Need Before November 2026

CMMC Compliance Training: What Defense Contractors Need Before November 2026

CMMC Level 2 third-party certification requirements take full effect in November 2026. Employee cybersecurity training is not a best practice under this framework. It is a documented requirement. Here is what your workforce training program needs to cover, what assessors look for during a C3PAO review, and the documentation gap that catches most contractors off guard.

If your organization holds or is pursuing Department of Defense contracts, the Cybersecurity Maturity Model Certification is no longer something to plan for later. The phased rollout that began with CMMC 2.0 has been moving steadily toward full enforcement, and November 2026 marks the point at which Level 2 certified assessments conducted by third-party C3PAO organizations become a standard part of the DoD contracting process for contractors handling Controlled Unclassified Information, or CUI. CUI refers to information the federal government creates or possesses that requires safeguarding under law, regulation, or government-wide policy, but that does not meet the threshold for classified information. For defense contractors, this typically includes technical data, contract information, export-controlled materials, and sensitive program details shared as part of a DoD engagement.

Most contractors have spent the past two years focused on the technical side of CMMC preparation: access controls, incident response procedures, system security plans, and the 110 practices in NIST SP 800-171 Revision 2 that CMMC Level 2 is built on. That work is essential. But the workforce training requirement sits alongside it as a separately documented obligation, and it is the piece that gets the least attention until an assessor asks for proof.

At Velocity Knowledge, we have worked with defense contractors and federal organizations including Lockheed Martin, the U.S. Army, Air Force, and Marine Corps on cybersecurity training programs built specifically for government and defense environments. What follows reflects what we know about what CMMC assessors actually look for in the workforce training area, and what a program needs to include to hold up under review.

What CMMC Level 2 Requires for Employee Training

CMMC Level 2 maps directly to NIST SP 800-171 Revision 2. The practice domain that governs workforce training is the Awareness and Training domain, referred to as AT. The three practices in this domain that defense contractors need to address are:

  • AT.2.056: Ensure personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems.
  • AT.2.057: Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities.
  • AT.3.058: Provide security awareness training on recognizing and reporting potential indicators of insider threat.

In plain language: every employee with access to CUI or to systems that process or store CUI needs documented security awareness training that covers the security risks tied to their specific activities, the organization's relevant policies, and how to recognize and report threats including insider threats. Employees with specific cybersecurity or information security responsibilities need additional training appropriate to those responsibilities. And all of it needs to happen on a defined, recurring schedule with records that prove it took place.

The word documented is doing a lot of work in that paragraph. The content of the training is one thing. Being able to demonstrate to an assessor that the training happened, who received it, when, and what it covered is what determines whether the practice is considered implemented.

What C3PAO Assessors Actually Look For

Third-party CMMC assessors conducting Level 2 reviews are not checking whether your organization has a cybersecurity training program in theory. They are looking for specific artifacts that demonstrate the program exists in practice. Understanding what those artifacts are before your assessment is what separates organizations that pass from organizations that receive findings.

Assessment Area What the Assessor Needs to See Common Finding
Written training plan A documented plan that identifies who receives training, what it covers, how often it is delivered, and who owns it Training happens but no written plan exists to show it is deliberate and managed
Individual completion records Records tied to specific employees showing training date, content covered, and confirmation of completion Aggregate records showing courses were assigned but not individually completed
New hire process Evidence that new employees complete training before being granted access to CUI or relevant systems No documented new hire training requirement separate from general onboarding
Role differentiation Evidence that employees with elevated access or cybersecurity responsibilities received appropriate additional training All employees received the same training regardless of role or access level
Threat-specific content Documentation showing training covered specific threat categories including phishing, social engineering, and insider threat indicators General security awareness without coverage of the specific threats AT.3.058 requires
Recurring schedule A defined training cadence, typically annual, with records showing it was followed Training happened once and was not repeated on a defined schedule

The most consistent finding in pre-assessment gap reviews is not that training never happened. It is that the documentation to prove it happened is incomplete, inconsistent, or stored in a format that makes it difficult to retrieve and present during an assessment.

What a CMMC-Ready Cybersecurity Training Program Covers

Beyond the documentation, the substance of the training itself needs to address specific content areas that the AT domain practices require. A program built around generic cybersecurity awareness will often miss the specifics that assessors are looking for.

Security awareness foundations specific to CUI handling

Employees need to understand what CUI is, how to identify it in their work environment, what the organization's obligations are when handling it, and what the consequences of a breach or mishandling incident look like. This is not abstract. It needs to be grounded in how CUI actually appears in the employee's day-to-day work, whether that is in documents, emails, file shares, or conversations.

Threat recognition covering current attack methods

AT.3.058 requires training on recognizing and reporting potential indicators of insider threat specifically. But a well-built program also covers the external threat categories that employees in defense contractor environments encounter regularly: phishing attacks including spear-phishing targeting specific roles, pretexting and social engineering over phone and email, impersonation attempts, and anomalous behavior in systems they use. Generic descriptions of these threats are not enough. Employees need examples specific enough to recognize them in a real situation.

Policy and procedure compliance

Employees need working knowledge of the organization's specific information handling policies. That means how CUI is stored, labeled, transmitted, and destroyed. Password and authentication requirements. Incident reporting procedures and the timeline for reporting. Remote work and mobile device policies. Acceptable use of external systems and cloud services. These policies vary by organization, which is why training that is not customized to the organization's actual policies cannot fully satisfy AT.2.056.

Role-specific information security training

Employees with formal cybersecurity responsibilities, system administrators, IT staff with elevated access, personnel responsible for incident response, and security officers need training that goes beyond general awareness. AT.2.057 requires that these employees are trained to carry out their assigned information security responsibilities. That standard requires content specific to what those responsibilities actually are, which means role-based training modules separate from the general workforce program.

The Documentation Problem That Trips Up Most Contractors

Walk through the following scenario. Your organization runs annual security awareness training. Employees complete it through an online platform. Completion rates are tracked. Most employees finish the course. The IT team handles the records.

A C3PAO assessor arrives. They ask for documentation of your AT domain practices. You pull the completion report from the platform. The assessor asks several follow-up questions. Does the training cover CUI handling specifically? Is there evidence that new employees complete training before being granted access? Do employees with cybersecurity responsibilities receive additional training documented separately? Is the training content reviewed and updated on a defined schedule? What is the process when an employee misses the training deadline?

If any of those questions produce a hesitation or a search through multiple systems for an answer, that is a finding. Not because the training did not happen, but because the program is not documented thoroughly enough to demonstrate it is managed.

The documentation layer is not something to build after the training content is in place. It needs to be designed alongside the training from the beginning. That means a written training plan, a process for tracking individual completion and exceptions, a new hire procedure tied to access provisioning, a content review schedule, and a separate record of role-specific training for employees with cybersecurity responsibilities.

How to Close the Gap Before November 2026

If your organization has not already completed a gap assessment of your AT domain status, that is where to start. A gap assessment maps your current training program against the specific requirements of NIST SP 800-171 AT practices and surfaces the specific gaps that need to be closed before a C3PAO assessment.

From the gap assessment, the preparation sequence typically runs as follows:

  1. Identify every employee with access to CUI or to systems that process CUI. This list should be maintained and reviewed at a defined interval, not created once and forgotten.
  2. Audit your existing completion records. Can you produce individual records tied to specific employees, dates, and content? Would those records satisfy an assessor's request without additional explanation?
  3. Review your training content against the specific requirements of AT.2.056, AT.2.057, and AT.3.058. Does it cover CUI handling, insider threat indicators, and role-specific responsibilities? Generic security awareness content may address some of these but not all.
  4. Establish a documented new hire training procedure that ties completion to access provisioning. New employees should complete training before receiving access to CUI systems, with a record that confirms this happened.
  5. Document role-specific training for employees with elevated access or cybersecurity responsibilities separately from the general workforce training records. Assessors look for this differentiation.
  6. Create or update your written training plan to reflect the current program, ownership, schedule, and update process. This document does not need to be long, but it needs to exist and match what actually happens.

Velocity Knowledge delivers cybersecurity training programs built specifically for defense contractors and federal organizations. Our Certified CMMC Professional program, Cybersecurity First Responder training, and security awareness programs are designed around the NIST SP 800-171 framework and delivered instructor-led by practitioners with real federal and defense sector experience. We also help organizations build the documentation layer that assessors look for, not just the training content.

Frequently Asked Questions

What employee training does CMMC Level 2 require?

CMMC Level 2 requires security awareness training for all employees with access to CUI or to systems that handle CUI, covering the security risks tied to their activities, applicable organizational policies, and threat recognition including insider threat indicators. Employees with specific information security responsibilities need additional training appropriate to those responsibilities. All training must be conducted on a recurring schedule and documented with individual completion records.

How often does cybersecurity training need to happen under CMMC?

NIST SP 800-171 requires training to occur on a defined and documented schedule. Annual training is the standard that most C3PAO assessors expect and the cadence that most compliant programs follow. New employees must complete training before being granted access to CUI or to systems that process it. Refresher training may also be appropriate after significant changes to organizational policy, a security incident, or the introduction of new threats or systems.

Can self-paced online training satisfy CMMC awareness and training requirements?

Self-paced online training can satisfy the content requirements if it covers the right material and is properly documented. The platform must produce individual completion records tied to specific employees, showing the date of completion and the content covered. Many organizations use self-paced training for general security awareness and supplement with instructor-led training for role-specific and technical content. The format matters less than the documentation and the coverage of the required content areas.

What is the difference between CMMC Level 1 and Level 2 training requirements?

CMMC Level 1 does not include specific awareness and training practices. The AT domain requirements, AT.2.056, AT.2.057, and AT.3.058, apply at Level 2 and above. If your organization is pursuing or maintaining a Level 2 certification, the documented workforce training requirement applies in full. If your organization is at Level 1, employee training is still a sound operational practice, but it is not a separately assessed requirement under the CMMC framework.

Ready to Get Compliant?

If your organization is in active CMMC preparation and wants to discuss your workforce training program, contact the Velocity Knowledge team. We work directly with defense contractors on both the training content and the documentation structure that C3PAO assessors look for.

Ensure your team is fully prepared with our Cybersecurity pillar page for a comprehensive overview of our offerings.

Explore our Certified CMMC Professional (CCP) program to build core compliance competencies.

Explore our Cybersecurity First Responder program.

Discover our Integrating AI in Cybersecurity program.

Build Future Skills

Empower your workforce with expert-led training in AI technologies, IT leadership, and secure adoption strategies.