
by Ian MacRae
President and CEO, E-N Computers
25+ years experience solving business IT problems in Virginia and Washington, D.C.
Updated August 2, 2026
CMMC certification training is still worth your time — even though the requirement it was intended to support has been suspended. On July 13, 2026, the Department of War – DoW paused CMMC Phase 2, the phase that would have required third-party Level 2 certification starting Nov 10, 2026, and opened a 60-day review of the whole program. The businesses that keep learning now will be ready for whatever the reformed program requires.
Here’s what didn’t change: Phase 1 self-assessment requirements are still in effect, and every contractor handling covered defense information is still required to protect it under NIST SP 800-171 Rev 2 and DFARS clause 252.204-7012. So, the trainings below close the gap on 800-171 while the DoW figures out what CMMC becomes next.
So, what can you do to start today?
The first step is to get educated. Here is a small but powerful list of mostly free training resources that can help you get a grip on CMMC.
I’ve come across these over my time as president of a managed IT services provider in Virginia, a state consistently among the top states in the country for federal contract dollars. I’ve also been certified as a CMMC Registered Practitioner by The Cyber AB, and my MSP, E-N Computers, is a Registered Practitioner Organization.
QUICK ANSWER:
Where can I find free training for CMMC certification?
The government offers several classes, guides, and bulletins that can introduce you to CMMC compliance requirements, train you on recognizing and handling Controlled Unclassified Information (CUI), and keep you up to date on cybersecurity threats – all are free. Some other low-cost resources include CMMC credential training, now administered by ISACA.
Table of Contents
The Cyber AB
Cost: $600 (Application, Training & Testing) plus a $500 annual renewal fee
Time required: 8 hours or more
Topics covered: CUI, FCI, the CMMC framework, scoping, etc.
The Cyber AB is the official accreditation body of the Cybersecurity Maturity Model Certification (CMMC) ecosystem. As of April 1, 2026, though, the training and certification side moved to ISACA—Information Systems Audit and Control Association (a global professional association that focuses on IT governance, cybersecurity, risk management, and information systems auditing), which now runs the exams and credentials as the CMMC Assessor and Instructor Certification Organization (CAICO).
The Cyber AB ecosystem can be a little confusing at first, particularly if you’re looking for training. The Cyber AB accredits consultants and auditors to work with businesses and also accredits businesses as CMMC compliant. Most likely you don’t want to become a CMMC auditor, so you don’t need that training. You are looking for training to become CMMC compliant as a business so that when the auditor comes (to assess you for CMMC Level 2), you are ready. The pricing below is for the Registered Practitioner (RP) program specifically, which is still run directly by the Cyber AB and unaffected by the ISACA move — it’s a separate track from the CCP, CCA, and CCI credentials ISACA now administers.
One option is to take the training for becoming a Registered Practitioner – the consultant role in the CMMC ecosystem. First, you must join the Cyber AB. You’ll have to pass a background check and pay $600 for the training and assessment. Topics include an introduction to the CMMC model, the CMMC accreditation body and ecosystem, Federal Contract Information (FCI), prime and subcontract information flow, CMMC tools and templates, scoping and contract agreement and fulfillment.
There is an annual renewal fee of $500 for the RP designation. The Registered Practitioner training took me about eight hours over two weekends. It wasn’t bad for someone with a background in IT, cybersecurity, and compliance.
Center for Development of Security Excellence
Cost: Free
Time required: Training must be completed in one sitting
Topics covered: Controlled Unclassified Information (CUI)
This DoW Mandatory CUI training provided by the Center for Development of Security Excellence is mandatory for all DoW personnel with access to CUI. This is relatively a quick and basic training but useful.
Project Spectrum
Cost: Free account
Time required: Each class is about an hour
Topics covered: Access control; CUI, System Security Plans; Plans of Action & Milestones; system and communication protection, foreign ownership, control or influence
Project Spectrum is a not-for-profit platform created to educate small businesses on CMMC and offers cybersecurity information, resources, tools, and training. Most of the training is at a high level. They also offer a number of self-assessment tools.
DoW self-assessment guides
Cost: Free
Time required: The audiobooks offer nine hours of content
Topics covered: Many details of CMMC Level 1 and 2
The official CMMC Assessment Guides are available directly from the DoW website. These guides, developed in collaboration with organizations like Carnegie Mellon University, detail the practices and assessment objectives for each CMMC Level, helping organizations prepare for their official CMMC assessment.
As a service to the IT community, E-N Computers created audiobooks for the guides. As I was preparing for CMMC, I found myself wishing for an audio version so I could review on the go. So, we put together a professionally recorded series of audiobooks for our clients and others.
CMMC Level 1 (FCI)
CMMC Self-Assessment Guide Level 1 (PDF)
CMMC Self-Assessment Guide Level 1 (Audiobook)
CMMC Level 2 (CUI)
CMMC Self-Assessment Guide Level 2 (PDF)
CMMC Self-Assessment Guide Level 2 (Audiobook)
Defense Industrial Base Cybersecurity Program
Cost: Free
Topics covered: Current cybersecurity threats
The DIB Cybersecurity Program is a voluntary program to help businesses keep DoW information safe. Cybersecurity threats and remediation are shared between the DoW and cleared defense contractors. This program can help you keep up with security threats and get some coaching around security.
The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
Cost: Free
Time required: 1 hour
Topics covered: A control-by-control review of NIST 800-171 with examples of application
Our plain English explanation of the 110 NIST controls and actionable steps.
DoW CIO’s Brilliant at the Basics
Cost: Free
Time required: About 10 minutes per list, self-paced
Topics covered: Top 10 IT practices and top 10 OT practices for DIB partners
The DoW CIO office released two short, plain-English top 10 lists — one for IT, one for operational technology — built specifically for small and mid-sized defense contractors. It’s a quicker read than the Cyber AB material and a solid gut check before you commit to formal training.
The state of NIST-CMMC compliance today
Last but not least, a lot of these training options are included in my presentation to the Richmond, Virginia-based cybersecurity conference RVAsec. This is a thorough introduction to the complexities of government compliance, but also (I hope) in plain English.
Next steps
When you have the right people working together, you can implement systems and processes that actively help you reach your business goals. We sometimes call this IT maturity. But for many organizations, something is off when it comes to their partnerships, strategy, systems, and settings. How can you know what’s working well and where you have room for improvement? Start by taking our free IT Maturity Self-Assessment. You’ll walk away with some pointers and, if you want, a free appointment to discuss your results.
Paid training resources
While the official CMMC Assessment Guides are the authoritative source, many organizations, particularly small and medium-sized businesses, are helped by structured training and expert consulting services. These paid resources offer accelerated learning and professional guidance.
1- Official CMMC ecosystem training (certification path)
For organizations that plan to have in-house IT, security, or compliance staff deeply involved in implementation and assessment preparation, investing in official CMMC certification training provides the most accurate and reliable foundation. These courses are delivered by Approved Training Providers (ATPs) listed on the CyberAB Marketplace. ISACA now administers the exams and credentials as the CAICO.
| Course name | Purpose | Estimated cost (course only) |
|---|---|---|
| Certified CMMC Professional (CCP) | Provides a foundational and comprehensive understanding of the CMMC 2.0 model, assessment process, and NIST SP 800-171 requirements. | $1,995 – $3,000 (typically 4-5 days) |
| Certified CMMC Assessor (CCA) | Trains professionals to execute CMMC Level 2 assessments. Highly valuable for internal staff who will conduct pre-assessments. | $2,995 – $3,300 (typically 5 days) |
Note: These costs cover the ATP training course only. The organization must also pay a separate, smaller fee directly to ISACA (the CAICO) for the CMMC Professional Number (CPN) and the certification exam itself.
2- Specialized compliance workshops and courses
Many training providers and consulting firms offer targeted courses designed specifically for contractors, not for professional certification. Here are some general categories
- CMMC readiness/compliance workshops: These workshops, offered by various CMMC consultants and training providers, focus on the practical application of CMMC Level 2 requirements, often including gap analysis against NIST SP 800-171, System Security Plan (SSP) guidance, and developing a Plan of Action & Milestones (POA&M).
- CMMC for business professionals/executives: Shorter courses (often 1-day or half-day) designed for senior leaders to understand the contractual, financial, and strategic implications of CMMC, to better allocate budget and resources.
- End-user security awareness training: Necessary for all personnel; many providers offer CMMC-aligned security awareness training to meet the Awareness and Training (AT) practice domain requirements.
3- Professional implementation services (consulting)
An RPO does more than supplying certified people. A gap assessment compares your systems to the CMMC practices and hands you on a prioritized list of what’s missing. Implementation support is hands-on help closing those gaps, so you get compliant faster and you’re less likely to fail the official assessment.
Complimentary review with an experienced engineer
Are you ready for CMMC?

Get a free strategic consultation to start or streamline your journey toward CMMC compliance.
Related articles
Learn more about CMMC
Guides, case studies, and tools for defense contractors navigating compliance
CMMC Managed IT
Virginia CMMC Managed IT Services
Best CMMC managed IT services providers in the DMV
Best Virginia CMMC managed IT services providers
Finding help
Best CMMC RPOs near Washington, DC
Best Virginia Registered Practitioner Organizations
Case Study: Virginia Government Contractor Nears CMMC Compliance
Best CMMC assessors near Washington, DC
CMMC consulting services for small and medium-sized businesses
Virginia CMMC consulting services
Washington, DC CMMC consulting services
Understanding CMMC
The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
What is FCI and should I worry about it?
What is CUI and should I worry about it?
CMMC compliance deadlines: Key dates and what they mean
Tools & training
How to buy GCC High and what’s involved
We found the best GRC tool for CMMC
What is Microsoft GCC High and do I need it?
CMMC Level 1 guide as audio book
CMMC Level 2 guide as audio book
CUI enclaves in CMMC compliance: Are they right for your business?

Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082
