CMMC training your people actually finish.
Short, scenario-based lessons built on proven learning science, with the records your CMMC Level 2 assessment asks for.
Already a customer? Sign in to your trainingDownload the brochure (PDF)
- 3 of 3AT requirements, 9 of 9 objectives
- 110 of 110Level 2 requirements taught
- 7 · 18courses · modules
- 5graded questions per module
- 80%closed-book pass mark
- 12-monthrenewal with test-out
Most compliance training is endured, not learned.
Long reading
Pages of policy, then a click on Next. People skim, and nothing connects to the decisions they make at work.
An open-book quiz
When the answers sit on the screen, a pass shows that someone could find them, not that they know them.
Nothing remembered by Monday
A vendor email, a USB stick, a visitor at the door: the moment that matters arrives weeks later, with no practice behind it.
The Learn-by-Deciding Method.
A five-step lesson based on Decision-Based Learning and Merrill's First Principles of Instruction. Learners guess first, learn in short chunks, practice with instant feedback, prove it closed book, then apply it to their own job.
Start
A quick, ungraded guess about one or two real situations before reading anything. Guessing first, even wrongly, primes people to notice and keep the answer.
Pretesting effect (Richland et al., 2009); Merrill's activation
Learn
One short chunk of reading at a time. Each module shows its decision path: the 3 to 5 questions an expert asks, in order, and the cue that settles each one.
Mayer's segmenting principle; cognitive load theory (Sweller)
Try it
Two to six practice decisions on that chunk, each explained the moment it's answered. The feedback names the decision it exercised, and says what would change the answer.
Retrieval practice (Roediger & Karpicke, 2006); feedback (Hattie & Timperley, 2007)
Check
Five closed-book scenario questions, in situations the practice didn't use. 80% to pass, with retakes. The reading is closed, so a pass reflects what the person knows.
Mastery learning (Bloom, 1968); scenario-based learning (Clark, 2013)
Put it to work
Two or three concrete actions for their own job this week, so the lesson turns into a "when X, I'll do Y" plan.
Merrill's integration; implementation intentions (Gollwitzer, 1999)
At renewal
A returning learner can take the check first. Pass, and they're done. If not, they work the lesson and try again. It respects what adults already know and removes the biggest complaint about annual training.
Adult learning (Knowles)
Make the call.
Real practice items from the Facilities & Physical Security course. Pick an answer to see the explanation, just as learners do.
Decision path: a person, badge, or piece of CUI media is in front of me. Is this allowed, and what do I do?
- Is this person on the current authorized list for this area? Yes: they may enter (3.10.1). Not on the list: go on.
- Not authorized: are they escorted, or is CUI cleared away first? Escort and monitor visitors, crews and contractors, or clear and lock away CUI before they come in (3.10.3).
- Is every badge, key, fob and combination accounted for? Keep an inventory (3.10.5).
- Is CUI media locked away, or accountable while it travels? Lock it away; clear desks at day's end (3.8.1, 3.8.2).
- Is the media being disposed of or reused? Sanitize or destroy it first (3.8.3).
1 of 2 · OK or not OK?
The side door to the engineering area is propped open on a hot day.
Decision 1: Is this person on the current authorized list for this area?
Physical access to CUI areas is limited to authorized people (3.10.1). A propped door lets anyone in.
2 of 2 · OK or not OK?
A contractor fixing the air conditioning works alone in the CUI area for an afternoon.
Decision 2: Not authorized: are they escorted, or is CUI cleared away first?
Escort and monitor people who are not authorized (3.10.3), or clear CUI from the area first.
What would change it: If someone stayed with them the whole time, or the CUI had been cleared and locked away before they came in, it would be OK.
Built for CMMC, not adapted to it.
How it compares with the options contractors usually weigh.
| Topic | Generic security-awareness libraries | Slide deck + sign-in sheet | Long video courses | DefenseLogix CMMC Training |
|---|---|---|---|---|
| Written for CMMC and CUI | Rarely; mostly phishing and passwords | Depends on who wrote it | Sometimes | Yes. Teaches all 110 CMMC Level 2 requirements, each cited to NIST SP 800-171 |
| Role-based training (3.2.2) | Usually not | No | One size fits all | Six role courses, assigned per person |
| Assessment | Open book, or answers visible on screen | None | Quiz at the end, often open book | Closed-book scenario check, 80% to pass |
| Learner experience | Long modules, easy to click through | Passive | 30–60 minutes of watching | Short chunks, practice with instant feedback, 5 graded questions |
| Annual renewal | Retake everything | Sit through it again | Rewatch everything | Test out by passing the check |
| Assessor-ready evidence | Completion report | Paper sign-in sheet | Certificate | Attestation (time and IP), certificate, compliance panel, CSV exports, control crosswalk |
The right training for each role.
Essentials for everyone with CUI access, plus six role courses from system administrator to affirming official. 7 courses, 18 modules, 90 graded scenario questions.
Required for everyone with CUI access · 6 modulesCMMC Workforce Training (Essentials)
- CMMC, FCI & CUI: Why This Applies to You
- Recognizing & Handling CUI
- Daily Safeguards
- AI, Cloud Tools & CUI
- Social Engineering & Insider Threat
- Incidents, Reporting & Consequences
IT and system admins · 4 modulesCMMC for System Administrators
- Privileged Access & Accounts
- Configuration, Patching & the Boundary
- Secure Design, Maintenance & Media
- Logging, Monitoring & Incident Handling
Supervisors who approve access · 3 modulesCMMC for Managers & Access Approvers
- Approving Access to CUI
- Onboarding, Role Changes & Departures
- Leading on Security
Security lead, incident response · 2 modulesCMMC for Security Leads & Incident Responders
- Running the Program (SSP, assessments, plans of action)
- Handling a Cyber Incident and Reporting to DoD
HR, recruiting, people ops · 1 moduleCMMC for HR & People Operations
- Screening, Personnel Actions & Training Records
Facilities, reception, physical security · 1 moduleCMMC for Facilities & Physical Security
- Physical Access, Visitors & Media
The affirming official and senior leaders · 1 moduleCMMC for Affirming Officials & Executives
- The Affirmation: What You Sign and What Backs It
Topics other training skips Using AI tools with CUI, the 72-hour DoD incident report, and what the affirming official is actually signing.
Ready when the assessor asks.
Attestations, certificates, a live compliance panel and one-click exports, mapped to the Awareness and Training requirements.
- AT.L2-3.2.1Make everyone aware of security risks and the policies that applyEssentials required for all users; completion dates, scores and attestations recorded
- AT.L2-3.2.2Train people with security duties to carry them outSix role-based courses assigned per person; assignment and completion history recorded
- AT.L2-3.2.3Insider threat awarenessA dedicated Essentials module, plus insider-threat content in the Managers, HR and Security Lead courses
Full Awareness and Training coverage: 3 of 3 requirements and 9 of 9 assessment objectives (NIST SP 800-171A). Your company still supplies its own policy list and the security roles in its SSP; the platform trains on the common requirements and records the evidence.
The evidence package
- Who completed which course, when, and with what score
- A signed attestation per person, with timestamp and IP
- A completion certificate
- Current, due or overdue status for every person
- Renewal history across training years
Easy to run. Secure by design.
Nobody gets in uninvited
Invite-only accounts, with Google Workspace single sign-on.
No CUI ever touches it
The platform holds training records only. Staff never upload CUI, and records are hosted in the US.
Delegate the admin
An organization admin role, so your own staff manage your people and pull your reports.
Stays current without chasing
Annual renewal by default, per course. Retrain a course in one click when a policy or system changes.
Hand over the records in seconds
CSV exports that open cleanly in Excel: learners, compliance status, module results and training history.
Records outlast staff changes
Training history is kept when a person leaves or a course is taken off them.
Content that keeps up with DoD
Course updates track program changes, such as the July 2026 Phase 2 suspension and incident reporting through DC3's portal.
Works for everyone
Keyboard and screen-reader friendly, and it works on a phone.
Grounded in learning science
- Decision-Based Learning (Plummer & Swan, Brigham Young University): teach the expert's decisions, with the "when and why" made explicit.
- Merrill's First Principles of Instruction: activate, demonstrate, apply, integrate.
- Mayer: short segments keep working memory free for understanding.
- Roediger & Karpicke: retrieving knowledge, not rereading it, is what makes it stick.
- Bloom: mastery learning. The standard is fixed; the time it takes can vary.
The research describes the techniques the design uses; it did not study this product. The method draws on Decision-Based Learning and is not an official DBL implementation.
Questions buyers ask.
See a lesson in five minutes.
Request a demo, or start a pilot with your team. We'll walk you through a lesson, the compliance panel and the evidence exports.
Sharing this with your team? Download the two-page brochure (PDF)
DefenseLogix CMMC Training supports the awareness and training requirements of CMMC Level 2 (NIST SP 800-171 3.2.1–3.2.3). Overall CMMC compliance depends on all of an organization's security requirements and is determined by assessment.
