Services · Training

CMMC Training for Teams and Professionals

CMMCMARK offers CMMC training on two tracks: courses that help your company meet and keep its CMMC requirements, and preparation for professionals pursuing official CMMC credentials such as the CCP and CCA. Courses are delivered for open groups or privately for your team.

Training for your organization

CMMC Level 2 requires security awareness training for everyone and role-based training for people with security duties. These courses cover that, and prepare the people who answer for your compliance.

CMMC Workforce Training

For all employees who handle FCI or CUI.

  • Recognizing phishing, social engineering and insider threats
  • Handling, marking and sharing CUI correctly
  • Reporting incidents and suspicious activity
  • Role-based modules for IT, administrators and managers

CMMC for Executives and Affirming Officials

For owners, executives and the official who affirms compliance.

  • What CMMC requires and what is changing
  • Choosing the level, scope and budget
  • What the yearly affirmation means for you personally
  • How to oversee compliance between assessments

CMMC Self-Assessment Training

For compliance, IT and security teams.

  • Scoping your systems and identifying FCI and CUI
  • Assessing each requirement against its objectives
  • Writing your system security plan and POA&M
  • Scoring, SPRS entry and affirmation

Training for CMMC professionals

Individuals who want to advise on or assess CMMC earn credentials issued by ISACA, the official CMMC Assessor and Instructor Certification Organization (CAICO). Candidates complete approved training and pass an exam.

CMMC Certified Professional (CCP)

The entry credential. CCPs advise organizations and can join Level 2 assessment teams under a certified assessor.

  • CMMC model, rules and ecosystem
  • Scoping and assessment methodology
  • Ethics and professional conduct
  • Preparation for the CCP exam

CMMC Certified Assessor (CCA)

For CCPs who want to conduct Level 2 certification assessments with a C3PAO. Also available as a combined CCP and CCA program.

  • Planning and conducting a Level 2 assessment
  • Evaluating evidence against assessment objectives
  • Scoring, findings and reporting
  • Preparation for the CCA exam

Requirements in brief: CCAs must hold the CCP, have at least 3 years of cybersecurity and 1 year of assessment or audit experience, and hold a qualifying certification (for example CISA or CISM). Experienced CCAs can qualify as Lead CCAs. Assessment roles also require a favorable Tier 3 background determination.

Related NIST courses

Short fundamentals courses for teams that work with other federal cybersecurity frameworks:

  • NIST Cybersecurity Framework (CSF): the core functions and how to apply them
  • NIST Risk Management Framework (RMF): the SP 800-37 process for federal systems
  • NIST SP 800-171: protecting CUI outside the CMMC context
  • Cybersecurity Supply Chain Risk Management: NIST SP 800-161
  • Secure by Design: NIST and CISA principles for secure products
  • Secure Software Development Framework (SSDF): NIST SP 800-218
  • Zero Trust Architecture: NIST SP 800-207

How does training work?

  • Formats: live online or on-site at your location
  • Private team sessions: any course can be delivered for your organization only and tailored to your environment
  • Getting started: send us a request with the course and the number of participants, and we will reply with dates and details

Questions about CMMC training

Does CMMC require employee training?

Yes, at Level 2. The Awareness and Training requirements call for security awareness training for all users, role-based training for people with security duties, and insider threat awareness.

Who issues the CCP and CCA credentials?

ISACA, which became the CMMC Assessor and Instructor Certification Organization (CAICO) in 2026. Candidates complete approved training, pass ISACA’s exam and, for assessment roles, a Tier 3 background determination.

Can training be tailored to our environment?

Yes. Private sessions can use your own systems, policies and examples, which makes the training more practical for your team.

Plan your CMMC training

Tell us who needs training and we will recommend the right courses.

Prefer the phone? Call +1 (202) 867-8444.

Sources