NIST 800-171 Controls · Awareness & Training
AT.2.001 — Security Awareness of Risks Associated with CUI
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.
What AT.2.001 means in plain English
Every person in your 8-person shop who touches a computer—the owner, the machinists logging job hours, the office manager sending purchase orders—must be told annually that they are handling government-sensitive information (CUI), what that means, and what they must never do (e.g., email drawings to personal Gmail, leave a USB drive in the parking lot). A one-hour lunch-and-learn plus a signed acknowledgment sheet satisfies this for a small shop.
The assessment question
“Has every employee who accesses systems containing CUI received documented security awareness training in the past 12 months and signed an acknowledgment?”
How to implement AT.2.001
- Create a one-page "CUI Handling Rules" document specific to your machine shop—include what CUI looks like (drawings, specs, contract line items), where it lives (shared drive, email), and what is forbidden (personal cloud, social media, unencrypted USB).
- Schedule a one-hour annual training session for all staff. Use free CISA resources at cisa.gov/cybersecurity-training-exercises or the DoD Cyber Awareness Challenge (free at https://public.cyber.mil/training/cyber-awareness-challenge/).
- Create a one-page sign-off sheet listing each employee name, training date, and a checkbox confirming they received and understood the policy. Collect signatures immediately after training.
- Store signed acknowledgments in a physical binder AND scan them into a protected folder. Label the folder "CMMC Evidence — AT — Awareness Training." Repeat annually or when someone is newly hired.
- Set a recurring calendar reminder for 11 months from now so the next training cycle is never missed.
Evidence your assessor will ask for
- Signed attendance/acknowledgment sheet with employee names, dates, and signatures
- Training material used (printout, slide deck, or DoD completion certificate)
- Written CUI handling policy that was presented during training
- Roster showing all employees who have system access were included
Does AI prompt monitoring help with this control? Honestly, no.
AT.2.001 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Awareness & Training controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.