CMMC requires security training.
It does not require a training vendor.

Level 2 demands annual awareness training, role-based training for admins, and insider threat awareness — with records an assessor can verify. CMMCMAP Pro builds all three courses in, and writes the evidence for you.

Start Free Trial →
Courses, quizzes, certificates & completion records included in Pro — $149/mo. No per-seat training fees.

What CMMC Level 2 actually requires

Three practices in the Awareness & Training (AT) family of NIST SP 800-171. Assessors verify each one with objective evidence — your training records.

AT.L2-3.2.1

Security Awareness — everyone

All users must be made aware of the security risks of their activities and the policies and procedures that apply. In practice: annual training plus refresh on role change, covering CUI handling, phishing, passwords, physical security, and incident reporting.

AT.L2-3.2.2

Role-Based Training — admins & managers

Anyone with assigned security duties — system administrators, IT staff, supervisors — needs training matched to those duties: least privilege, account lifecycle, change control, log review, patching.

AT.L2-3.2.3

Insider Threat Awareness — everyone

Users must be trained to recognize and report potential insider threat indicators. The DIB is a standing target for foreign intelligence collection — small subs included.

✓ No "authorized training company" required

NIST SP 800-171 lets your organization define its own training content and delivery. What gets scored is the record: dated, named, role-tagged completions tied to your documented policies. The CMMC "approved training provider" ecosystem (CCP/CCA) applies only to people becoming assessors — never to your workforce. A documented in-house program with tracked completions fully satisfies the AT family.

Built into CMMCMAP Pro — courses, records, and proof

Other tools track whether you bought training somewhere else. CMMCMAP just includes it.

3 ready-to-run coursesSecurity Awareness Fundamentals, Privileged User & Administrator Security, and Insider Threat Awareness — mapped slide-by-slide to the AT practices.
Quizzes with a pass bar80% to pass. Records save only on a passing score — comprehension evidence, not "watched a video."
Assessor-ready recordsPer-user, dated, scored, mapped to AT.L2-3.2.1/2/3 — exported automatically into your audit evidence bundle.
CertificatesBranded completion certificates per user, per course, with validity dates and record IDs.
Annual renewal trackingDashboard shows who's current, who's expiring, who's lapsed — with email reminders before records expire.
Policy acknowledgmentsOne-click "read & accept" sign-offs on your generated policies — timestamped evidence for AC, AT, and PS controls.

Common questions

Does the training have to come from a certified or authorized provider?

No. The organization defines content and delivery under NIST SP 800-171. Assessors examine your training material, your policy mandating it, and your completion records. "Authorized training providers" exist only in the assessor-certification ecosystem (CCP/CCA candidates), not for contractor workforces.

How often does training have to happen?

The rule says "periodically." The cadence assessments consistently accept is annually, plus training before system access for new hires and refresh when roles change. CMMCMAP records carry a 12-month validity date and the app flags expirations ahead of time.

What will a C3PAO actually ask for?

Typically: the training content itself, the policy that mandates it, and completion records showing each person — by name, date, and role — completed the right courses. CMMCMAP exports training records and policy acknowledgments straight into the audit bundle alongside your SSP and POA&M.

We already use KnowBe4 / another LMS. Can we still use CMMCMAP?

Yes — external training works fine for CMMC, and CMMCMAP's document and evidence tooling doesn't care where training happened. The built-in courses just mean one less subscription and records that flow into your evidence bundle automatically.

Does this cover Level 1?

Level 1 has no explicit training practice, but training your team is still the cheapest risk reduction available — and if CUI ever enters your environment, you'll already meet the L2 AT family.

Training, handled. Records, written.

Three courses, every completion tracked, evidence exported — inside the same tool that writes your SSP.

Start Free Trial See Pricing