It is tempting to treat CMMC as a technology problem — firewalls, encryption, logging. But an entire family of requirements is about people, and it is often the least expensive to satisfy and the easiest to neglect: awareness and training.
What the AT family asks
NIST SP 800-171’s Awareness and Training requirements (the 3.2 family) call for two things: that everyone who touches your systems understands the security risks and their responsibilities, and that people in specific roles are trained to carry out their security duties. In plain terms — your whole team gets awareness, and the people with special access get role-specific training.
Why it matters more than it looks
Most incidents start with a person, not an exotic exploit: a convincing phishing email, a reused password, a document sent to the wrong address. No amount of technical control fully compensates for a workforce that cannot recognize the attempt. This is also a requirement an assessor can test just by talking to your staff.
Making it real, not a checkbox
Annual click-through training technically satisfies the letter and misses the point. The programs that hold up are continuous and specific: short, frequent reminders, phishing simulations, and training tied to the actual CUI your people handle. Keep records — completion dates and content — because ‘we talk about security’ is not evidence.