Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · AT

Awareness & Training

That the people handling CUI know the risks and their responsibilities, including insider-threat awareness.

3
requirements in this family
What it requires

The 3 requirements, in plain language.

3.2.1 Role-Based Risk Awareness

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems

3.2.2 Role-Based Training

Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities

3.2.3 Insider Threat Awareness

Provide security awareness training on recognizing and reporting potential indicators of insider threat

NIST SP 800-171 Rev 2 — Family AT. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.