Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
Defense Industrial Base

CMMC Workforce Training

Online security awareness training for the employees of defense contractors and subcontractors who handle Federal Contract Information and Controlled Unclassified Information, with the completion records, scored testing, and certificates that assessment evidence requires.

Why Training Is a Requirement

Three of the 110 requirements are about people.

CMMC compliance is usually discussed in terms of systems, but the Awareness and Training domain of NIST SP 800-171 requires that every employee understand the security risks associated with their work, that personnel be trained to carry out their assigned security responsibilities, and that the workforce be able to recognize and report potential indicators of insider threat.

An assessor does not take the organization's word for this. The organization has to show who was trained, on what content, and when. At CMMC Level 2, the Awareness and Training domain contains three requirements:

Awareness and Training (AT) Domain, CMMC Level 2
RequirementWhat it requires
AT.L2-3.2.1Ensure that managers, systems administrators, and users are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures.
AT.L2-3.2.2Ensure that personnel are trained to carry out their assigned information security related duties and responsibilities.
AT.L2-3.2.3Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Level 1 contractors handling only Federal Contract Information have no explicit training requirement among the FAR 52.204-21 safeguards, but the safeguards themselves depend on employee behavior, and many primes now ask their Level 1 suppliers to demonstrate awareness training anyway. The platform supports both situations.

The Courses

Written for the way defense manufacturers actually work.

This practice provides workforce training through a purpose built online platform, available to clients as part of a CMMC engagement. The examples are engineering drawings, inspection records, shop floor travelers, and emails from prime contractors, not generic office scenarios.

Annual Core

CMMC Security Awareness

What the CMMC program is, why the contract carries cybersecurity obligations, and what each employee's role is in protecting the information used to perform defense related work.

CUI Handling

Recognizing and Handling CUI

How CUI appears in daily work: drawings, CAD files, specifications, manufacturing instructions, inspection results, test data, and controlled customer correspondence. How to store, transmit, mark, and dispose of it using the company's approved methods, and what to do when it is not obvious whether information is controlled.

Insider Threat

Incident Recognition and Reporting

What a security incident looks like from an employee's chair, including phishing, mishandled information, and the behaviors that can indicate insider threat, with the steps for reporting through the company's procedures. This course carries the AT.L2-3.2.3 insider threat content.

How It Works

The record keeping is the point.

Each client company receives its own space on the platform. The company designates which employees take which courses, and employees complete the training online in short modules with narration, knowledge checks that must be answered correctly to proceed, and a scored final test.

The platform records what an assessor will ask to see:

  • Which employees were assigned each course, and by whom
  • Completion status and timestamps for every module and course
  • Knowledge check responses and final test scores
  • The course version each employee completed, so content changes are traceable
  • Certificates of completion for every employee
  • Records retained across annual cycles for year over year evidence
Awareness training without documentation does not survive an assessment. The objective is not merely that training occurred, but that the organization can demonstrate it occurred, for the right people, on the right content, within the required cycle.
Access

Provided to clients of this practice.

For most clients the training is one component of a broader CMMC readiness engagement, where the course content is aligned with the policies and procedures being developed for the System Security Plan. Employees are trained on the actual approved methods their company uses rather than on generic guidance. Companies interested in the training on its own can start a conversation the same way.

Get In Touch

Start a Conversation

A 30-Minute Introductory Call

A conversation about your contracts, the training requirements that apply to your workforce, and whether this platform fits your situation. The first conversation carries no commitment and no pitch.

Start a Conversation →