DefenseLogix CMMC Training

CMMC training your people actually finish.

Short, scenario-based lessons built on proven learning science, with the records your CMMC Level 2 assessment asks for.

The My Training portal a new learner sees after signing in: 0 of 6 modules complete, Module 1 up next with a Start button, the six Essentials modules listed with their status, and a locked certificate.
My Training: where each person starts, and picks up their next module. Demo data.
  • 3 of 3AT requirements, 9 of 9 objectives
  • 110 of 110Level 2 requirements taught
  • 7 · 18courses · modules
  • 5graded questions per module
  • 80%closed-book pass mark
  • 12-monthrenewal with test-out
The problem

Most compliance training is endured, not learned.

01

Long reading

Pages of policy, then a click on Next. People skim, and nothing connects to the decisions they make at work.

02

An open-book quiz

When the answers sit on the screen, a pass shows that someone could find them, not that they know them.

03

Nothing remembered by Monday

A vendor email, a USB stick, a visitor at the door: the moment that matters arrives weeks later, with no practice behind it.

The method

The Learn-by-Deciding Method.

A five-step lesson based on Decision-Based Learning and Merrill's First Principles of Instruction. Learners guess first, learn in short chunks, practice with instant feedback, prove it closed book, then apply it to their own job.

01

Start

A quick, ungraded guess about one or two real situations before reading anything. Guessing first, even wrongly, primes people to notice and keep the answer.

Pretesting effect (Richland et al., 2009); Merrill's activation

02

Learn

One short chunk of reading at a time. Each module shows its decision path: the 3 to 5 questions an expert asks, in order, and the cue that settles each one.

Mayer's segmenting principle; cognitive load theory (Sweller)

03

Try it

Two to six practice decisions on that chunk, each explained the moment it's answered. The feedback names the decision it exercised, and says what would change the answer.

Retrieval practice (Roediger & Karpicke, 2006); feedback (Hattie & Timperley, 2007)

04

Check

Five closed-book scenario questions, in situations the practice didn't use. 80% to pass, with retakes. The reading is closed, so a pass reflects what the person knows.

Mastery learning (Bloom, 1968); scenario-based learning (Clark, 2013)

05

Put it to work

Two or three concrete actions for their own job this week, so the lesson turns into a "when X, I'll do Y" plan.

Merrill's integration; implementation intentions (Gollwitzer, 1999)

↺

At renewal

A returning learner can take the check first. Pass, and they're done. If not, they work the lesson and try again. It respects what adults already know and removes the biggest complaint about annual training.

Adult learning (Knowles)

Try a question

Make the call.

Real practice items from the Facilities & Physical Security course. Pick an answer to see the explanation, just as learners do.

Decision path: a person, badge, or piece of CUI media is in front of me. Is this allowed, and what do I do?
  1. Is this person on the current authorized list for this area? Yes: they may enter (3.10.1). Not on the list: go on.
  2. Not authorized: are they escorted, or is CUI cleared away first? Escort and monitor visitors, crews and contractors, or clear and lock away CUI before they come in (3.10.3).
  3. Is every badge, key, fob and combination accounted for? Keep an inventory (3.10.5).
  4. Is CUI media locked away, or accountable while it travels? Lock it away; clear desks at day's end (3.8.1, 3.8.2).
  5. Is the media being disposed of or reused? Sanitize or destroy it first (3.8.3).

1 of 2 · OK or not OK?

The side door to the engineering area is propped open on a hot day.

2 of 2 · OK or not OK?

A contractor fixing the air conditioning works alone in the CUI area for an afternoon.

Why it's different

Built for CMMC, not adapted to it.

How it compares with the options contractors usually weigh.

TopicGeneric security-awareness librariesSlide deck + sign-in sheetLong video coursesDefenseLogix CMMC Training
Written for CMMC and CUIRarely; mostly phishing and passwordsDepends on who wrote itSometimesYes. Teaches all 110 CMMC Level 2 requirements, each cited to NIST SP 800-171
Role-based training (3.2.2)Usually notNoOne size fits allSix role courses, assigned per person
AssessmentOpen book, or answers visible on screenNoneQuiz at the end, often open bookClosed-book scenario check, 80% to pass
Learner experienceLong modules, easy to click throughPassive30–60 minutes of watchingShort chunks, practice with instant feedback, 5 graded questions
Annual renewalRetake everythingSit through it againRewatch everythingTest out by passing the check
Assessor-ready evidenceCompletion reportPaper sign-in sheetCertificateAttestation (time and IP), certificate, compliance panel, CSV exports, control crosswalk

People finish it.

It's short, it respects their time, and it feels like making decisions rather than reading policy.

It actually teaches.

A recognized instructional design model and proven learning-science techniques, not "read, then click next." The check is closed book, so the pass is real.

It proves compliance.

Every completion, attestation and renewal is recorded, exportable for an assessor, and mapped to AT.L2-3.2.1, 3.2.2 and 3.2.3.

Course catalog

The right training for each role.

Essentials for everyone with CUI access, plus six role courses from system administrator to affirming official. 7 courses, 18 modules, 90 graded scenario questions.

Required for everyone with CUI access · 6 modulesCMMC Workforce Training (Essentials)
  1. CMMC, FCI & CUI: Why This Applies to You
  2. Recognizing & Handling CUI
  3. Daily Safeguards
  4. AI, Cloud Tools & CUI
  5. Social Engineering & Insider Threat
  6. Incidents, Reporting & Consequences
IT and system admins · 4 modulesCMMC for System Administrators
  1. Privileged Access & Accounts
  2. Configuration, Patching & the Boundary
  3. Secure Design, Maintenance & Media
  4. Logging, Monitoring & Incident Handling
Supervisors who approve access · 3 modulesCMMC for Managers & Access Approvers
  1. Approving Access to CUI
  2. Onboarding, Role Changes & Departures
  3. Leading on Security
Security lead, incident response · 2 modulesCMMC for Security Leads & Incident Responders
  1. Running the Program (SSP, assessments, plans of action)
  2. Handling a Cyber Incident and Reporting to DoD
HR, recruiting, people ops · 1 moduleCMMC for HR & People Operations
  1. Screening, Personnel Actions & Training Records
Facilities, reception, physical security · 1 moduleCMMC for Facilities & Physical Security
  1. Physical Access, Visitors & Media
The affirming official and senior leaders · 1 moduleCMMC for Affirming Officials & Executives
  1. The Affirmation: What You Sign and What Backs It

Topics other training skips Using AI tools with CUI, the 72-hour DoD incident report, and what the affirming official is actually signing.

Assessor-ready evidence

Ready when the assessor asks.

Attestations, certificates, a live compliance panel and one-click exports, mapped to the Awareness and Training requirements.

  • AT.L2-3.2.1Make everyone aware of security risks and the policies that applyEssentials required for all users; completion dates, scores and attestations recorded
  • AT.L2-3.2.2Train people with security duties to carry them outSix role-based courses assigned per person; assignment and completion history recorded
  • AT.L2-3.2.3Insider threat awarenessA dedicated Essentials module, plus insider-threat content in the Managers, HR and Security Lead courses

Full Awareness and Training coverage: 3 of 3 requirements and 9 of 9 assessment objectives (NIST SP 800-171A). Your company still supplies its own policy list and the security roles in its SSP; the platform trains on the common requirements and records the evidence.

The evidence package

  • Who completed which course, when, and with what score
  • A signed attestation per person, with timestamp and IP
  • A completion certificate
  • Current, due or overdue status for every person
  • Renewal history across training years
The compliance panel for a demo company: 3 of 7 people trained and current, 4 still to finish, 3 attestations signed, with a per-learner table of modules, scores and last activity.
The compliance panel an organization admin sees. Demo company and people.
For admins and IT

Easy to run. Secure by design.

Nobody gets in uninvited

Invite-only accounts, with Google Workspace single sign-on.

No CUI ever touches it

The platform holds training records only. Staff never upload CUI, and records are hosted in the US.

Delegate the admin

An organization admin role, so your own staff manage your people and pull your reports.

Stays current without chasing

Annual renewal by default, per course. Retrain a course in one click when a policy or system changes.

Hand over the records in seconds

CSV exports that open cleanly in Excel: learners, compliance status, module results and training history.

Records outlast staff changes

Training history is kept when a person leaves or a course is taken off them.

Content that keeps up with DoD

Course updates track program changes, such as the July 2026 Phase 2 suspension and incident reporting through DC3's portal.

Works for everyone

Keyboard and screen-reader friendly, and it works on a phone.

Grounded in learning science

  • Decision-Based Learning (Plummer & Swan, Brigham Young University): teach the expert's decisions, with the "when and why" made explicit.
  • Merrill's First Principles of Instruction: activate, demonstrate, apply, integrate.
  • Mayer: short segments keep working memory free for understanding.
  • Roediger & Karpicke: retrieving knowledge, not rereading it, is what makes it stick.
  • Bloom: mastery learning. The standard is fixed; the time it takes can vary.

The research describes the techniques the design uses; it did not study this product. The method draws on Decision-Based Learning and is not an official DBL implementation.

FAQ

Questions buyers ask.

Each module is short and broken into chunks, with five graded questions at the end. Most people can finish a module in one sitting, and at renewal they can test out.
No. The reading is closed while you take the check, so the pass reflects what you know.
They review the lesson and retake the check. Retakes are unlimited by default, with a short break after repeated misses; an admin can set a limit. The record shows the passing attempt.
No. At renewal they can test out by passing the check first. If they don't pass, they work the lesson and try again.
It covers the awareness and training requirements (AT 3.2.1–3.2.3) and produces the evidence. Overall compliance depends on all of your controls and is determined by assessment.
Never. The platform holds only training records.
Module 1 teaches the policies every contractor must have and tells staff to get your current versions from your security contact. Showing your own policy list and contacts inside the course is on the roadmap.
Contact us for pricing. Tell us roughly how many people need training and we'll suggest a pilot.
Request a demo

See a lesson in five minutes.

Request a demo, or start a pilot with your team. We'll walk you through a lesson, the compliance panel and the evidence exports.

Sharing this with your team? Download the two-page brochure (PDF)

We use this information to respond to your request, as described in our Privacy Policy. Please do not include CUI or details of an active incident.

DefenseLogix CMMC Training supports the awareness and training requirements of CMMC Level 2 (NIST SP 800-171 3.2.1–3.2.3). Overall CMMC compliance depends on all of an organization's security requirements and is determined by assessment.