Understanding Training Requirements in CMMCThe requirement for ensuring thatpersonnel are trained to carry out their assigned information security-related duties and responsibilitiesfirst appears inCMMC Level 2as part ofNIST SP 800-171 control AT.L2-3.2.1.
Key Details on the Training Requirement:✔AT.L2-3.2.1: "Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities."
✔This control is derived fromNIST SP 800-171and applies toCMMC Level 2 (Advanced).
✔It ensures that employees handlingControlled Unclassified Information (CUI)understand theircybersecurity responsibilities.
A. Level 1 → Incorrect
CMMC Level 1 does not include this training requirement.Level 1 focuses on basic safeguarding ofFederal Contract Information (FCI)but doesnot require formal cybersecurity training.
B. Level 2 → Correct
The training requirement (AT.L2-3.2.1) first appears in CMMC Level 2, which aligns withNIST SP 800-171.
C. Level 3 → Incorrect
The training requirementalready exists in Level 2. Level 3 builds on Level 2 with additionalrisk management and advanced cybersecurity controls, but training is introduced at Level 2.
D. All levels → Incorrect
CMMC Level 1 does not include this requirement—it is first introduced in Level 2.
Why is the Correct Answer "B. Level 2"?
NIST SP 800-171 (Requirement 3.2.1)
Defines themandatory training requirementfor personnel handling CUI.
CMMC Assessment Guide for Level 2
ListsAT.L2-3.2.1as a required practice under Level 2.
CMMC 2.0 Model Overview
Confirms thatCMMC Level 2 aligns with NIST SP 800-171, which includes security training requirements.
CMMC 2.0 References Supporting This Answer:
Submit