When companies prepare for CMMC, the early focus tends to land on technology: encryption, multifactor authentication, logging. But controls only work when people understand their part. An estimator who forwards a drawing set to a personal email account, or a foreman who photographs a controlled document on a personal phone, can undo a lot of technical work.
Preparing employees is a core part of readiness for contractors who handle controlled unclassified information. This guide explains how to think about roles, training, and everyday habits.
Start with who touches what
Not every employee interacts with controlled information. Map it.
- Who receives, stores, edits, or sends information that your contracts mark as controlled?
- Which systems and locations hold it?
- Which roles, such as project managers, estimators, engineers, document controllers, and executives, handle it regularly?
- Which employees, such as general laborers, have no need to see it?
This mapping supports a principle that helps both security and training: limit the people and systems in scope, and train most intensively where the information actually flows.
Training layers
Awareness for everyone
All employees, in scope or not, benefit from foundational training that covers recognizing phishing, using strong passwords and multifactor authentication, reporting incidents, handling devices, and basic data handling. NIST SP 800-171, the basis for CMMC Level 2 requirements, includes awareness and training expectations, and assessors will look for evidence that training happened and was relevant.
Role-based training
People with specific responsibilities need deeper instruction.
- Employees who handle controlled information should learn what it is, how to recognize markings, where it may and may not be stored, how to share it, and who to ask when unsure.
- IT and administrators need training on secure configuration, logging, access management, and incident response.
- Managers should understand their duties in approving access and enforcing procedures.
- Executives should understand the company's obligations, risk, and reporting duties.
New hire and change-of-role training
Do not wait for the annual session. Train new employees before they receive access, and retrain people who move into roles that involve controlled information.
Assign clear responsibilities
Documented ownership prevents gaps.
- Program owner: typically a senior leader accountable for the compliance effort.
- Control owners: named people responsible for specific areas such as access control, training, or incident response.
- Information handlers: employees who follow handling rules in daily work.
- Reporters: everyone, who must report suspected incidents quickly.
Write these roles into your procedures and job descriptions where appropriate.
Make it practical and short
Employees tune out long, generic training. Make it count.
- Use examples from construction and energy, such as bid packages, drawings, and subcontractor email.
- Keep sessions short and frequent, with refreshers throughout the year.
- Include a simple quiz or acknowledgment, and keep the records.
- Provide quick reference cards that explain how to mark, store, and share controlled information.
- Make reporting easy with a single email address or phone number.
Reinforce through everyday habits
- Use approved systems for controlled files, and discourage personal email, messaging apps, and unapproved cloud storage.
- Lock screens and protect devices in vehicles and trailers.
- Verify recipients before sending files.
- Avoid discussing controlled information in public places.
- Report lost devices and suspicious messages immediately.
Test and measure
Phishing simulations, spot checks, and short follow-up questions can show whether training sticks. Treat results as a learning tool rather than a punishment. Track completion and improvement over time.
Keep records
Maintain training materials, attendance, dates, and acknowledgments in an organized evidence folder. Assessors generally want proof of what was taught and to whom, so records matter as much as the sessions themselves.
Plan for turnover and seasonality
Construction workforces change often. Build training into onboarding and offboarding checklists, and make sure seasonal and temporary workers receive appropriate instruction before they receive access.
Where Ironfield Cyber fits
Ironfield Cyber helps defense subcontractors design role-based training, identify who is in scope, and gather training evidence for readiness. We work alongside your assessor and counsel, and are happy to review your current program.