CMMC control families
CMMC Awareness & Training (3.2 AT): 3 requirements, and the platform behind them
Three requirements. The program is yours to run — we do not teach, write curricula or deliver a course. What is quotable is the platform it runs on: awareness-training and phishing-simulation subscriptions, sourced through authorized US distribution like any other software line.
- Family
- 3.2 — Awareness & Training
- Requirements
- 3 of the 110 Level 2 requirements
- Level 1
- Not in Level 1 — appears at Level 2
- Boundary
- The capability behind the control — never a certification we hold
The shortest family in the standard, and the one people assume has nothing behind it
Awareness and training carries three requirements: managers, systems administrators and users have to be made aware of the security risks their activities carry and of the policies and standards that apply to them (3.2.1); personnel have to be trained to carry out their assigned information-security duties (3.2.2); and insider-threat awareness has to be part of the picture (3.2.3). Every one of those is a program that people complete and you evidence — no device produces it, and a supplier quoting a box against this family is selling you something else. What does exist as a line item is the platform the program runs on: awareness-training and phishing-simulation subscriptions are ordinary software, quoted per seat against your term, and they sit in our licensing catalog alongside everything else. The subscription is the tooling. The completion records are the control.
What each level asks of this family
Awareness and training is a Level 2 family. It is not one of the six families Level 1 touches — a Level 1 self-assessment against the 15 FAR 52.204-21 requirements does not reach 3.2 at all. That does not make training optional for a Level 1 contractor; it makes it something other clauses and ordinary prudence ask for rather than something the Level 1 assessment scores.
At Level 2 all three appear: 3.2.1 through 3.2.3, assessed like the rest of the 110 against the objectives in the DoD assessment guide. Role-based training under 3.2.2 is the one that catches people out, because it is not the same course for everyone — an administrator's assigned duties are different from a shipping clerk's, and the evidence has to show that.
Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.
What you can actually quote against this family
Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Awareness-training subscriptions (3.2.1, 3.2.3)
Seat-based training platforms are software like any other, priced against your headcount and term. Proofpoint carries the deepest security-awareness line in our licensing catalog, with ESET's cybersecurity-awareness training subscriptions alongside it; vendor training courses appear as their own catalog family. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Phishing simulation and role-based content (3.2.2)
Simulation and role-based content usually ship as tiers of the same platform rather than as separate products, which is why the seat count and the tier are the two things a quote needs from you. We price the subscription. We do not deliver instructor-led sessions, write curricula or author content, and role mapping under 3.2.2 — which duty gets which course — is a decision only your program can make.
What no purchase closes here
A subscription that nobody completes evidences nothing. The assessor asks for completion records and role mapping, not for an invoice, and the interval, the audience and the content decisions are yours — we hold no CMMC level to lend to yours. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.
We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.
Families with the deepest equipment behind them
If you arrived here looking for hardware, these are the families where the equipment story is deepest — encrypted portable media, privacy filters and locks, CAC and PIV readers, boundary devices and FIPS-validated cryptography.
Awareness and training questions
Does CMMC Level 1 require security awareness training?
Not as part of the Level 1 assessment. Awareness and training is a Level 2 family — Level 1 covers 15 requirements drawn from FAR 52.204-21 and touches six other families. Contractors handling CUI under DFARS 252.204-7012 have been carrying the full NIST SP 800-171 obligation, including 3.2, since 2017 regardless of what level a solicitation names.
How many awareness and training requirements are in NIST SP 800-171?
Three: 3.2.1 on general awareness for managers, administrators and users; 3.2.2 on training personnel to carry out their assigned information-security duties; and 3.2.3 on insider-threat awareness. Three of the 110 requirements a Level 2 assessment covers.
Who needs role-based security training under CMMC?
Anyone with assigned information-security responsibilities, which 3.2.2 defines by duty rather than by job title. In practice that means administrators, anyone handling CUI directly, and anyone with a defined role in your incident-response or media-handling procedures. The mapping from duty to training is yours to define and evidence.
How often does CMMC awareness training have to be repeated?
NIST SP 800-171 does not name an interval — it says awareness and training have to be provided, and leaves the frequency to your program to define and defend. Most contractors settle on annual with refreshers on change of role, but that is a convention, not a rule you can quote back to an assessor. Write the interval into the SSP and keep the completion records.
Related families and background
Get a CMMC estimate — CMMC Awareness & Training (3.2 AT)
Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Send the seat count and the term
We will not quote you a box against awareness and training, and we will not pretend to deliver the program. What we can price is the platform it runs on — seat-based training and simulation subscriptions, quoted against your term and renewal date — alongside anything else in the same order. A Uniqcli specialist replies with an estimate.