How the program works
Training is completed online, individually, and at each employee's own pace. Courses are divided into short modules that combine on screen content, audio narration, and knowledge checks. An employee must answer each knowledge check correctly before advancing, and each course ends with a scored final test. A certificate of completion is issued when the final test is passed. Courses are versioned, and each completion record shows the version the employee took, so the content of any past training cycle can be demonstrated later.
- HR assigns the course. The employee receives login credentials and the course appears on their training home page.
- The employee completes the modules. Short screens with narration and knowledge checks, typically finished in one or two sittings. Progress is saved between sessions.
- The employee passes the final test. The score is recorded and the certificate is issued automatically.
- The record is retained. Assignment, completion timestamps, scores, course version, and certificate are stored for reporting and assessment evidence.
Course outlines
Three courses make up the core program. Course examples are drawn from defense manufacturing: engineering drawings, CAD files, shop floor travelers, inspection records, and correspondence with prime contractors.
Course 1: CMMC Security Awareness
The foundation course for every employee. It explains why the company's defense contracts carry cybersecurity obligations and what each person's role is in meeting them.
- The Contract Behind the Work. What CMMC is, why it exists, and how the obligation reaches every employee who touches defense related work.
- Recognizing Controlled Information. Federal Contract Information and Controlled Unclassified Information as they appear in daily work.
- Handling and Transmitting. Approved systems for storing, sending, printing, and disposing of controlled information.
- Access and Accountability. Passwords, multifactor authentication, workstation habits, physical security, and visitors.
- Phishing and Social Engineering. Recognizing deceptive email, calls, and requests, with examples aimed at manufacturers.
- Reporting. What to report, how to report it, and why fast reporting protects the employee and the company.
Supports AT.L2-3.2.1 (security awareness) and AT.L2-3.2.2 (training for assigned security duties).
Course 2: Recognizing and Handling CUI
A deeper course for employees who work directly with technical data: engineering, quality, production, purchasing, and shipping personnel.
- What Makes Information CUI. Categories, markings, and the difference between marked and unmarked controlled information.
- CUI in the Shop and Office. Drawings, CAD files, travelers, inspection results, test data, and customer correspondence.
- Approved Handling. Storage, transmission, marking, reproduction, and disposal using the company's approved methods.
- When It Is Not Obvious. Gray areas, unmarked information, and when to stop and ask before storing, sending, or sharing.
Supports AT.L2-3.2.1 and AT.L2-3.2.2 for personnel handling CUI.
Course 3: Incident Recognition and Reporting
What a security incident looks like from an employee's chair, and the exact steps for reporting through the company's procedures.
- What Counts as an Incident. Mishandled information, lost devices, suspicious system behavior, and unauthorized access.
- Phishing and Suspicious Contact. Recognizing and reporting deceptive messages and unusual outside inquiries.
- Insider Threat Indicators. Recognizing and reporting potential indicators of insider threat.
- The Reporting Path. Who to tell, how quickly, and what happens after a report is made.
Supports AT.L2-3.2.3 (insider threat awareness) and incident reporting expectations.
Administering the training
Each client company has its own administration area. A designated HR or training administrator manages the company's employees and training from one place; no software is installed and nothing is maintained on your systems.
Employee and assignment management
- Add employees individually or from a list, and edit their details at any time
- Assign courses per employee or by group, with due dates for each assignment
- Deactivate departed employees while their historical training records are retained
- Reset a login or reissue credentials when an employee needs access restored
- See every employee's current status at a glance: not started, in progress, complete, or overdue
Tracking, reminders, and reporting
- Scores and completion timestamps are recorded automatically for every module, knowledge check, and final test
- Email reminders are sent to the HR administrator when employees are coming due for annual training, and again if an assignment becomes overdue
- Annual cycles are tracked per employee, so recurring training does not have to be rescheduled by hand
- A defensible assessment report can be produced on demand: who was assigned, who completed, when, with what score, and on which course version
- Certificates for every completion are stored and available for download
The assessment report
When your company faces a CMMC assessment, the Awareness and Training requirements are demonstrated with records, not recollection. The platform's assessment report is built for that moment. It presents the employee roster with assignments, completion dates and timestamps, final test scores, course versions, and issued certificates, organized so an assessor can trace any employee's training history across annual cycles. Records are retained year over year, so evidence from prior cycles remains available for as long as your company uses the platform.