It is tempting to treat CMMC as a technology problem — firewalls, encryption, logging. But an entire family of requirements is about people, and it is often the least expensive to satisfy and the easiest to neglect: awareness and training.

What the AT family asks

NIST SP 800-171’s Awareness and Training requirements (the 3.2 family) call for two things: that everyone who touches your systems understands the security risks and their responsibilities, and that people in specific roles are trained to carry out their security duties. In plain terms — your whole team gets awareness, and the people with special access get role-specific training.

Why it matters more than it looks

Most incidents start with a person, not an exotic exploit: a convincing phishing email, a reused password, a document sent to the wrong address. No amount of technical control fully compensates for a workforce that cannot recognize the attempt. This is also a requirement an assessor can test just by talking to your staff.

Making it real, not a checkbox

Annual click-through training technically satisfies the letter and misses the point. The programs that hold up are continuous and specific: short, frequent reminders, phishing simulations, and training tied to the actual CUI your people handle. Keep records — completion dates and content — because ‘we talk about security’ is not evidence.

See how we build a security culture, not just a slide deck.