Mapped to NIST 800-171 Requirement: 3.2.1
CMMC Assessment Objective: AT.L2-3.2.1[a]
What This Objective Means
Security awareness training is not optional for anyone who interacts with CUI. This objective ensures you’ve identified all roles and individuals who require such training as part of your security awareness training plan. These may include:
• Full-time and part-time employees
• Contractors and consultants
• Interns or temporary workers
• Remote employees or third-party support staff
The key is to understand who has access to CUI or CUI-handling systems—and ensure they are all accounted for in your training plan.
Why It Matters
Failure to identify all training-required personnel means:
• Some users may access CUI without proper understanding of security risks
• Insider threat risk increases
• You cannot demonstrate full organizational coverage during an audit
This is a foundational step in building a culture of cybersecurity awareness through a comprehensive security awareness training program.
How to Implement It
• Review your organization’s system access lists and user directories
• Identify individuals with:
◦ Physical or logical access to CUI
◦ Access to systems that process, store, or transmit CUI information types
• Work with HR, IT, and team leads to map roles to training requirements
• Maintain a list or registry of users who require security awareness training
Evidence the Assessor Will Look For
• A documented list of training-required personnel
• Role mapping documentation that explains how training requirements are assigned
• Access control lists cross-referenced with training rosters
• HR or onboarding workflows identifying training prerequisites
Common Gaps
• Training only applied to IT staff or “technical users”
• No clear identification of contractors, temp workers, or remote users who need training
• Training is optional, irregular, or not tracked
How Cuick Trac Helps
Cuick Trac supports this control by:
• Helping identify CUI access roles and users through centralized access control
• Providing templates to map roles to awareness training requirements
• Supporting integration with LMS platforms to track and document completion of security awareness training content
• Offering clear documentation to prove that training coverage is comprehensive
With Cuick Trac, you don’t miss anyone—and you have the audit trail to prove it.
Final CTA
Security starts with awareness—and awareness starts with knowing who needs it as part of an effective information security awareness plan.
Schedule a Cuick Trac demo and ensure every user who touches CUI is trained and accountable.