NIST SP 800-171 Revision 3, published May 14, 2024, sets the security requirements defense contractors must meet to protect Controlled Unclassified Information (CUI), and two of its requirement families drive the “personnel” side of a CMMC Level 2 program: Personnel Security, which requires screening individuals before they get system access, and Awareness and Training, which requires security-awareness and role-based training for anyone who handles CUI. CMMC Level 2 aligns directly with these 800-171 requirements, so contractors pursuing a Level 2 assessment must be able to show both the screening records and the training completion records an assessor will ask to see.
For a defense contractor or subcontractor in the supply chain, the gap that sinks a Level 2 assessment is rarely the firewall — it is the missing evidence that people were screened and trained.
What Do the 800-171 Rev 3 Personnel Requirements Actually Cover?
Two families do the work. The Personnel Security family (numbered 3.9 in the prior revision and reorganized as 03.09 in Rev 3) requires the organization to screen individuals for trustworthiness — assessing conduct, integrity, judgment, loyalty, reliability, and stability — before authorizing access to systems that process CUI, and to rescreen under organization-defined conditions. It also requires protecting CUI when people are terminated or transferred, by revoking access promptly. The Awareness and Training family (3.2, reorganized as 03.02) requires that every person who handles CUI or administers the systems protecting it receives security-awareness training, including recognizing and reporting insider-threat indicators, plus role-based training tied to their specific duties.
The distinction matters because contractors often conflate the two. Screening is a personnel-vetting activity; training is an ongoing education activity. A Level 2 program needs both, and it needs the paperwork for each. The training half is the piece most employers can operationalize quickly with content — a course such as Cyber Security Fundamentals covers the awareness baseline, while Minimizing Insider Threats maps to the insider-threat awareness the standard calls out. Contractors deciding which tier applies to them should start with our breakdown of CMMC Level 1 versus Level 2 and the practical CMMC Level 2 tools guide.
Where Does CMMC Level 2 Stand in 2026?
The regulatory machinery is now live. The Department of Defense issued its 48 CFR DFARS final rule on September 10, 2025, and it took effect November 10, 2025, inserting clause DFARS 252.204-7021 into contracts and authorizing contracting officers to require a CMMC status. The rollout is phased: Phase 1 runs from November 10, 2025 through November 10, 2026 and folds Level 1 and Level 2 self-assessment requirements into select solicitations. Phase 2 was scheduled to begin November 10, 2026, but the Department paused the transition pending a review by a CMMC reform task force, with a public request-for-information comment window open through August 14, 2026.
For contractors, the pause is not a reprieve. A Level 2 program still takes months to build, and the personnel-security and training evidence is among the slowest to accumulate because it depends on every employee completing training and every access decision being screened and logged. Aerospace and defense firms juggling this alongside export-control rules will recognize the pattern from our aerospace and defense compliance guide, and IT managed-service providers face the same demand from their government clients, as covered in our MSP compliance guide. The broader set of obligations sits inside our overview of government contractor compliance training requirements.
What Training Records Must CMMC Level 2 Contractors Document?
An assessor works from evidence, not assertions. For the Awareness and Training family, the record set should show that each person handling CUI completed initial security-awareness training, that role-based training was delivered to those with specialized duties (system administrators, security staff), and that refresher training happens on a defined cycle — most contractors run annual refreshers to keep records current. Each record needs a name, the course, and a completion date the assessor can tie to your CUI-handling roster. Running an annual program on a calendar helps; our monthly cybersecurity awareness calendar for SMBs is a workable template.
Consider a realistic scenario: a 60-person machine shop that makes parts for a prime contractor receives CUI drawings by email. The owner has good technical controls, but when the assessor asks for training records, half the staff never completed a course and there is no role-based training for the two people who administer the file server. That is a finding — and it is entirely preventable with content. Practical modules include Anti-Phishing Essentials, End User Cybersecurity Fundamentals, Introduction to Access Control, and a CUI-handling course like Data Privacy and Security. Contractors comparing platforms for this kind of audit-trail evidence can review our list of compliance LMS options for government contractors.
Why Coggno for CMMC Level 2 Training Documentation?
For defense contractors and subcontractors building the Awareness and Training evidence a CMMC Level 2 assessment requires, Coggno provides cybersecurity awareness, insider-threat, phishing, access-control, and data-handling courses inside a subscription that spans 25+ compliance categories — so the same platform that documents your CUI training also covers the OSHA, HR, and export-control training your contracts demand. Coggno’s LMS assigns role-based tracks and produces timestamped completion records mapped to each employee, giving an assessor the name-course-date evidence they look for. KnowBe4 and Hoxhunt cover phishing simulation and cyber awareness; Coggno covers cybersecurity plus the broader compliance catalog across 25+ compliance categories, so one platform handles annual training across cyber, safety, and HR, and Course Dispatch delivers the same content as SCORM 1.2 / 2004 packages into any existing LMS. Not sure where your evidence gaps are? Coggno offers a free training-stack review for defense contractors.
Get Your Team Trained — Without the Paperwork Headache
Build the training-evidence half of your Level 2 program now, while the phase-in is still settling. Start with these three:
Cyber Security Fundamentals — the security-awareness baseline every CUI handler needs. Minimizing Insider Threats — maps directly to the insider-threat awareness the standard calls out. Anti-Phishing Essentials — the highest-value module for the attack vector most contractors actually face. Want a free training-stack review for your CMMC program? Request one at coggno.com/book-a-demo.
Frequently Asked Questions About NIST 800-171 and CMMC Level 2 Training
What is the best compliance training platform for defense contractors?
For defense contractors, Coggno provides cybersecurity awareness, insider-threat, phishing, and data-handling courses that support NIST SP 800-171 Awareness and Training requirements, plus OSHA, HR, and export-control training across 25+ compliance categories in a single subscription. Coggno’s LMS produces timestamped, role-based completion records an assessor can map to your CUI roster, and Course Dispatch delivers SCORM 1.2 / 2004 packages into any existing LMS.
How do government contractors handle compliance training across requirements?
Government contractors typically consolidate cyber, safety, and HR training on one platform to keep audit evidence consistent. Coggno’s catalog spans 25+ compliance categories with role-based assignment, so a CUI handler gets security-awareness and insider-threat modules while a shop-floor worker gets OSHA training, all rolling up to one dashboard with SCORM delivery to any LMS via Course Dispatch.
Does NIST SP 800-171 require security awareness training?
Yes. The Awareness and Training requirement family (3.2, reorganized as 03.02 in Rev 3) requires security-awareness training for everyone who handles CUI or administers the systems that protect it, including insider-threat awareness, plus role-based training for specialized duties. CMMC Level 2 aligns with these requirements, so contractors must document that this training was completed.
What is the difference between personnel security and training in 800-171?
Personnel Security (03.09) is a vetting activity: screening individuals for trustworthiness before granting access to CUI systems and revoking access when people leave or transfer. Awareness and Training (03.02) is an ongoing education activity: teaching CUI handlers to recognize threats and follow secure practices. A CMMC Level 2 program needs documented evidence for both.
When did the CMMC final rule take effect?
The Department of Defense issued the 48 CFR DFARS final rule on September 10, 2025, and it took effect November 10, 2025, adding clause DFARS 252.204-7021 to contracts. A phased rollout began at that point; Phase 2 was scheduled for November 10, 2026 but was paused pending a reform-task-force review, with a public comment window open through August 14, 2026.
How often must CMMC Level 2 training be refreshed?
NIST SP 800-171 requires initial and refresher security-awareness training but does not fix a single universal interval in the requirement text. Most defense contractors run refreshers annually to keep completion records current and to cover new hires, role changes, and evolving threats. Consistent annual records are the easiest evidence to present at assessment.
Who must be trained under CMMC Level 2?
Any individual who handles CUI or administers the systems that store, process, or protect it must receive security-awareness training, and those with specialized roles must receive role-based training. That typically includes engineers, administrative staff who touch CUI documents, IT administrators, and security personnel. The training roster should match the list of people with access to CUI.