CUI Guardian: CMMC Awareness and Training

A free, self-paced 12 module training curriculum for CUI Guardian: CMMC Awareness and Training, built for defense contractors, government suppliers, federal healthcare providers, and universities handling Controlled Unclassified Information. Completing every module issues a printable 12.0 contact hour certificate from TECHLEAD 187 LLC.

Domains covered

Module syllabus

  1. 1.1 Foundations of Security Awareness
    Individual security responsibilities, applicable policies and reporting channels, the threat landscape for organizations handling government data, and why awareness is a CMMC AT.L2-3.2.1 obligation.
  2. 1.2 CUI: Identify & Mark
    What qualifies as CUI, Basic vs Specified, the NARA and DoD CUI Registries as category authority, banner line construction, portion marking, designation indicators, and limited dissemination controls.
  3. 1.3 CUI: Protect, Share & Destroy
    Safeguarding CUI in controlled environments, protection at rest and in transit, sharing on a lawful government purpose basis, subcontractor flow-down, decontrol, and destruction per NIST SP 800-88.
  4. 1.4 Insider Threat Recognition & Reporting
    Malicious, negligent, and compromised insider vectors, behavioral and technical indicators, case-pattern awareness, reporting channels, and the AT.L2-3.2.3 training requirement.
  5. 1.5 OPSEC for Sensitive Programs
    The five-step OPSEC process, building an organization-specific critical information list, adversary collection methods including social media, and countermeasures in daily work.
  6. 1.6 Safeguarding PII & PHI
    PII definitions and sensitivity, PHI as a PII subset, Privacy Act and DoD 5400.11 duties, authorized vs unauthorized disclosure, breach response, penalties, and the HIPAA touchpoint.
  7. 2.1 Overlay: Defense Contractors
    DFARS 252.204-7012 covered defense information and 72-hour DIBNet incident reporting, -7019/-7020 self-assessments and SPRS scores, -7021 CMMC as a condition of award, FCI vs CUI, and subcontractor flow-downs.
  8. 2.2 Overlay: Civilian-Agency Suppliers
    FAR 52.204-21 basic safeguarding of Federal Contract Information, agency CUI marking practice, the government-wide FAR CUI rulemaking, and incident notification outside DoD channels.
  9. 2.3 Overlay: Government Healthcare Providers
    Health information as CUI (SP-HLTH) beside HIPAA PHI duties, the dual-regime reality for VA, TRICARE, and HHS contractors, breach clocks compared, and minimum necessary vs lawful government purpose.
  10. 2.4 Overlay: Universities & Research
    CUI in sponsored research, fundamental research exclusion limits, export control intersection (ITAR/EAR and deemed exports), NSPM-33 research security programs, the 800-171 enclave pattern, and FERPA vs CUI.
  11. 3.1 Role: Managers & Program Leads
    Role-based duties under AT.L2-3.2.2: assigning and verifying security responsibilities, sanctions processes, incident escalation ownership, assessment evidence duties, and a non-retaliatory reporting culture.
  12. 3.2 Role: System Administrators & ISSOs
    Technical duties behind awareness claims: least-privilege account hygiene, audit log review discipline, media sanitization per NIST SP 800-88 Rev 2, FIPS-validated cryptography, baselines, and CUI enclave administration.

What each module includes

An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.

Start this curriculum

Other curricula

Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.