
by Ian MacRae
President and CEO, E-N Computers
29+ years experience solving business IT problems in Virginia and Washington, D.C.
Updated August 5, 2026
CMMC certification training is still worth your time. In July 2026, the Department of Defense (DoD) suspended CMMC Phase 2 — the phase that would have required third-party Level 2 certification — while it reviews the program.
Here’s what didn’t change: Phase 1 self-assessment requirements are still in effect, and every contractor handling covered defense information is still required to protect it under NIST SP 800-171 Rev 2 and DFARS clause 252.204-7012, with annual affirmations still due in SPRS, the federal contractor scoring system. So, the training below closes the gap on 800-171 while the Department works out what CMMC becomes next. Whatever the reformed program requires, the businesses that keep learning now will be ready for it.
So, what can you do to start today?
Start by getting educated. The list below covers mostly free training resources that will help you get a grip on CMMC.
I’ve come across these over my time as president of a managed IT services provider in Virginia, a state that consistently ranks among the top in the country for federal contract dollars. I’m also registered as a CMMC Registered Practitioner with The Cyber AB, and my MSP, E-N Computers, is a Registered Practitioner Organization.
QUICK ANSWER:
Where can I find free training for CMMC certification?
The government offers several classes, guides, and bulletins that can introduce you to CMMC compliance requirements, train you on recognizing and handling Controlled Unclassified Information (CUI) and keep you up to date on cybersecurity threats — all free. Some other low-cost resources include CMMC credential training, now administered by ISACA.
Table of Contents
- The Cyber AB
- Center for Development of Security Excellence
- Project Spectrum
- DoD self-assessment guides
- Defense Industrial Base Cybersecurity Program
- The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
- DoD CIO’s Brilliant at the Basics
- The state of NIST-CMMC compliance today
- Paid training resources
- Next steps
- Learn more about CMMC
The Cyber AB
Cost: $600 for application, training, and testing ($725 if an international background check is needed) plus a $500 annual renewal fee (rates accurate as of publication based on August 3rd, 2026, listings).
Time required: 8 hours or more
Topics covered: CUI, FCI, the CMMC framework, scoping, etc.
Link: https://cyberab.org/
The Cyber AB is the official accreditation body of the Cybersecurity Maturity Model Certification (CMMC) ecosystem. As of April 1, 2026, though, individual training and credentialing moved to ISACA — the Information Systems Audit and Control Association, a global professional body for IT governance, cybersecurity, risk, and audit. ISACA now runs the exams and credentials as the CMMC Assessor and Instructor Certification Organization (CAICO).
The Cyber AB ecosystem can be a little confusing at first, particularly if you’re looking for training. The Cyber AB accredits the organizations in the ecosystem — the C3PAOs that run certification assessments, the Registered Practitioner Organizations (RPOs) that help you get ready, and the training providers. It does not certify contractors. Your Certificate of CMMC Status comes from a C3PAO. Most likely you don’t want to join an assessment team, so you can skip the assessor track. What you want is training to get your own business ready, so that when a C3PAO assessor does show up for your Level 2 assessment, you’re ready. The pricing above is for the Registered Practitioner (RP) program specifically, which The Cyber AB still runs directly and which the ISACA move didn’t affect — it’s a separate track from the CCP, CCA, and CCI credentials ISACA now administers.
One option is to take the training for becoming a Registered Practitioner — the advisory role in the CMMC ecosystem. An RP can advise but can’t sit on an assessment team; a CCP can join a C3PAO assessment team but can’t lead one. First, you join The Cyber AB. You’ll pass a background check and pay $600 for the application, training, and exam. The background check is included; an international check runs about $125 more. Topics include an introduction to the CMMC model, the CMMC accreditation body and ecosystem, Federal Contract Information (FCI), prime and subcontract information flow, CMMC tools and templates, scoping and contract agreement and fulfillment.
The RP designation renews annually for $500. The Registered Practitioner training took me about eight hours over two weekends. It wasn’t bad for someone with a background in IT, cybersecurity, and compliance.
Center for Development of Security Excellence
Cost: Free
Time required: Training must be completed in one sitting
Topics covered: Controlled Unclassified Information (CUI)
Link: https://www.cdse.edu/Training/eLearning/IF141/
The DoD Mandatory Controlled Unclassified Information (CUI) Training from the Center for Development of Security Excellence is required for all DoD personnel who handle CUI. It’s quick and basic, but useful.
Project Spectrum
Cost: Free account
Time required: Each class is about an hour
Topics covered: Access control; CUI, System Security Plans; Plans of Action & Milestones; system and communication protection, foreign ownership, control or influence
Link: https://www.projectspectrum.io/
Project Spectrum is a not-for-profit platform created to educate small businesses on CMMC and offers cybersecurity information, resources, tools, and training. Most of the training is at a high level. They also offer several self-assessment tools.
DoD self-assessment guides
Cost: Free
Time required: The audiobooks offer nine hours of content
Topics covered: Many details of CMMC Level 1 and 2
The official CMMC Assessment Guides are available directly from the DoD website. These guides, developed in collaboration with organizations like Carnegie Mellon University, detail the practices and assessment objectives for each CMMC level, helping organizations prepare for their official CMMC assessment.
As a service to the IT community, E-N Computers created audiobooks for the guides. As I was preparing for CMMC, I found myself wishing for an audio version so I could review on the go. So, we put together a professionally recorded series of audiobooks for our clients and others.
The official CMMC Assessment Guides are available directly from the DoW website. These guides, developed in collaboration with organizations like Carnegie Mellon University, detail the practices and assessment objectives for each CMMC Level, helping organizations prepare for their official CMMC assessment.
As a service to the IT community, E-N Computers created audiobooks for the guides. As I was preparing for CMMC, I found myself wishing for an audio version so I could review on the go. So, we put together a professionally recorded series of audiobooks for our clients and others.
CMMC Level 1 (FCI)
CMMC Self-Assessment Guide Level 1 (PDF)
CMMC Self-Assessment Guide Level 1 (Audiobook)
CMMC Level 2 (CUI)
CMMC Self-Assessment Guide Level 2 (PDF)
CMMC Self-Assessment Guide Level 2 (Audiobook)
Defense Industrial Base Cybersecurity Program
Cost: Free
Time required: Ongoing participation — no set completion time
Topics covered: Current cybersecurity threats
Link: https://dibnet.dod.mil/
The DIB Cybersecurity Program is a voluntary program to help businesses keep DoD information safe. The Department and cleared defense contractors share threat information and remediation guidance through it. It’s a way to keep up with active threats and get some coaching along the way.
The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
Cost: Free
Time required: 1 hour
Topics covered: A requirement-by-requirement review of NIST 800-171, with examples
Link: https://www.encomputers.com/2025/12/dfars-and-nist-800-171-ultimate-guide/
Our plain English walkthrough of all 110 NIST SP 800-171 requirements, with the steps to meet each one.
DoD CIO’s Brilliant at the Basics
Cost: Free
Time required: About 10 minutes per list, self-paced
Topics covered: Top 10 IT practices and top 10 OT practices for DIB partners
Link: https://dodcio.defense.gov/BrilliantBasics/
The DoD CIO office released two short, plain-English top 10 lists — one for IT, one for operational technology — built specifically for small and mid-sized defense contractors. It’s a quicker read than the Cyber AB material and a solid gut check before you commit to formal training.
The state of NIST-CMMC compliance today
Many of these training options also show up in my 2023 talk at RVAsec, the Richmond, Virginia cybersecurity conference: The state of NIST-CMMC compliance today. It’s a thorough introduction to government compliance, and I hope, in plain English. A few specifics have changed since then, but the core ideas still hold.
Paid training resources
The official CMMC Assessment Guides are the authoritative source, but plenty of small and mid-sized businesses get further faster with structured training and outside help. Here’s what that costs.
1. Official CMMC ecosystem training (certification path)
If you have in-house IT, security, or compliance staff who’ll be deeply involved in implementation and assessment prep, the official CMMC certification training is the most reliable foundation. Approved Training Providers (ATPs) — formerly called Licensed Training Providers — deliver these courses, and you can find them on The Cyber AB Marketplace. ISACA now administers the exams and credentials as the CAICO.
| Course name | Purpose | Estimated cost (course only) | Course Duration |
|---|---|---|---|
| CMMC Certified Professional (CCP) | Covers the CMMC model, the assessment process, and the NIST SP 800-171 requirements. | $1,495 – $3,499 | typically, 4–5 days |
| CMMC Certified Assessor (CCA) | Trains professionals to run CMMC Level 2 assessments. Highly valuable for internal staff who will conduct pre-assessments. | $2,495 – $3,499 | TBD |
| Lead CMMC Certified Assessor (LCCA) | Senior assessor role — plans, directs, and holds final determination authority for a full CMMC assessment. Relevant mainly for C3PAO staff, not most in-house teams. | TBD | Not yet available |
| CMMC Credentialed Instructor (CCI) | Authorizes delivery of official CMMC training. Not yet available — ISACA lists it as “Coming Soon” (early 2026 per ISACA’s FAQ). | Not yet available | Not yet available |
Note: These costs cover the ATP training course only. You’ll also pay a separate, smaller fee directly to ISACA for the CMMC Professional Number (CPN) — the ID that tracks your credential — and for the exam itself.
2. Specialized compliance workshops and courses
Many training providers and consulting firms offer targeted courses designed specifically for contractors, not for professional certification. Here are the general categories:
- CMMC readiness/compliance workshops: Offered by CMMC consultants and training providers, these focus on applying CMMC Level 2 requirements in practice — gap analysis against NIST SP 800-171, System Security Plan (SSP) guidance, and building a Plan of Action and Milestones (POA&M), the document that lists the gaps you haven’t closed yet and when you’ll close them.
- CMMC for business professionals/executives: Shorter courses (often 1-day or half-day) designed for senior leaders to understand the contractual, financial, and strategic implications of CMMC, so they can budget and staff for it.
- End-user security awareness training: Everyone on staff needs this. Many providers offer CMMC-aligned awareness training that meets the Awareness and Training (AT) domain requirements.
3. Professional implementation services (consulting)
n RPO does more than supply credentialed people. A gap assessment compares your systems to the CMMC practices and hands you a prioritized list of what’s missing. Implementation support is hands-on help closing those gaps, so you get compliant faster and you’re less likely to fail the official assessment.
Next steps
If you’re trying to work out which of these to start with — or whether anyone on your team needs a formal credential at all — the answer depends on your contracts, where your CUI lives, and who’s doing the work. E-N Computers is a Registered Practitioner Organization in Virginia, and we have that conversation with defense contractors most weeks. We’re happy to have it with you. If you’d rather start on your own, our free IT Maturity Self-Assessment will show you where your systems and processes stand.
Complimentary review with an experienced engineer
Are you ready for CMMC?

Get a free strategic consultation to start or streamline your journey toward CMMC compliance.
Learn more about CMMC
Guides, case studies, and tools for defense contractors navigating compliance

Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082
