CMMC & Security Training in Raleigh-Durham
CMMC 2.0 certification training and security awareness education for your team. Petronella Technology Group, Inc. offers self-paced online courses and instructor-led training that prepare DoD contractors and Triangle businesses for CMMC Level 2 compliance.
CMMC Level 2 courses from $49 per learner, with team packs from 10 seats for $290. Or call (919) 348-4912.
Cybersecurity Training for CMMC Readiness
Achieving and maintaining CMMC compliance requires more than technical controls -- it demands a workforce that understands cybersecurity best practices and knows how to respond when incidents occur. Petronella Technology Group provides comprehensive training programs that cover both incident response preparedness and ongoing security awareness for organizations in Raleigh, Durham, Chapel Hill, and the Research Triangle.
Our training programs are designed to be practical, engaging, and relevant to the real threats your team faces every day. Whether you are preparing for CMMC certification or simply want to reduce your organization's risk, our training delivers measurable results.
Where to get CMMC Level 2 awareness training for your employees
Petronella Technology Group, Inc., a Cyber AB Registered Provider Organization (#1449) in Raleigh, NC, sells self-paced CMMC Level 2 courses online that map to the three Awareness and Training practices (AT.L2-3.2.1, 3.2.2 and 3.2.3). You can buy a single seat, a team pack, or one organization-wide license that covers every course for every user. The training supports your AT practices; it does not by itself make an organization CMMC compliant.
- CMMC Level 2 Security Awareness: Common Core: $49 per learner, about 63 minutes, maps to AT.L2-3.2.1 and AT.L2-3.2.3 (insider threat).
- CMMC Level 2 Role-Based Training: General Users: $59, about 30 minutes, maps to AT.L2-3.2.2.
- CMMC Level 2 Role-Based Training: Executives: $149, about 30 minutes, maps to AT.L2-3.2.2 for Senior Official duties.
- CMMC Level 2 Awareness and Training License: $300 per user per year for all three courses, one enrollment code for the whole organization, 1 to 500 users, card checkout or invoice at 25+ users.
- Common Core team packs: 10 seats $290, 25 seats $625, 50 seats $999, 100 seats $1,499, redeemed within 12 months.
- Every learner earns a certificate you can check at /training/verify/, and you can download completion records for your assessor. CMMC certificates expire after 12 months, matching annual training.
Incident Response Training
When a security incident occurs, your team's response in the first minutes and hours can make the difference between a contained event and a catastrophic breach. Our incident response training covers:
- How to identify and classify security incidents
- Proper initial response procedures and escalation paths
- Evidence preservation and chain of custody requirements
- Communication protocols during active incidents
- Containment, eradication, and recovery procedures
- Post-incident analysis and lessons learned
- Tabletop exercises simulating real-world scenarios
Security Awareness Training
A single click on a phishing link, a shared password, or an unsecured Wi-Fi connection can compromise an entire organization. Our security awareness training covers:
- Identifying phishing emails and malicious website links
- Creating and managing strong passwords
- Protecting personally identifiable information (PII)
- Recognizing social engineering tactics
- Safe use of personal devices with company data (BYOD)
- Physical security for portable media and devices
- Phone scam awareness
- Wi-Fi security best practices
Our Training Approach
Cloud-Based Portal
Self-paced online training that employees can complete on their own schedule with progress tracking for administrators.
Engaging Content
Interactive videos, real-world examples, and quizzes that keep employees interested and reinforce learning.
Testing & Certification
Employee testing and training certificates that document compliance for audit purposes.
Regular Updates
Content is continuously updated to address emerging threats and evolving attack techniques.
CMMC 2.0 Training Courses
Our Petronella Technology Group, Inc. Training Academy offers self-paced CMMC courses for every role on your team, from general users to executives. Start with a single Level 2 course or the full program, then go deeper with the full implementation bootcamp. Buying for a team? Team packs start at 10 seats for $290 with one enrollment code and a roster; see the Common Core course page. Each course includes progress tracking and a completion certificate for your audit documentation.
CMMC Level 2: Security Awareness Core
$49. Core security awareness aligned to CMMC Level 2 requirements for all staff.
View courseCMMC Level 2: Role-Based Training for General Users
$59. Role-based training for general users who handle controlled unclassified information.
View courseCMMC Level 2: Role-Based Training for Executives
$149. Role-based training for leadership and executives with CMMC oversight responsibilities.
View courseCMMC 2.0 Implementation Bootcamp
The complete, step-by-step program for implementing CMMC 2.0 and NIST 800-171 controls across your organization.
View courseWhat the CMMC Awareness and Training requirement actually says
CMMC Level 2 is built on NIST SP 800-171 Rev 2. Section 3.2 of that standard, Awareness and Training, defines three practices, and a CMMC Level 2 assessment checks all of them. The practices sound similar but they are not interchangeable, so it helps to read what each one actually requires:
- AT.L2-3.2.1, Role-Based Risk Awareness. Managers, system administrators, and users of organizational systems must be made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures. This is awareness for everyone who touches your systems, from the front desk to the server room.
- AT.L2-3.2.2, Role-Based Training. Personnel must be trained to carry out their assigned information security-related duties and responsibilities. Awareness alone does not cover people whose jobs carry specific security duties, such as system administrators, IT staff, or the executive who owns the compliance program.
- AT.L2-3.2.3, Insider Threat Awareness. Organizations must provide security awareness training on recognizing and reporting potential indicators of insider threat. The practice is about two skills: spotting warning signs and knowing how to report them.
Our awareness and training compliance guide shows how each Petronella course maps to each practice, so you can match assignments to the requirement instead of guessing.
Who has to take CMMC security awareness training
The short answer is everyone who uses your systems, plus role-specific training for the people who carry security duties. Reading the practice text, that breaks down into five groups:
- All employees and contractors who use organizational systems. AT.L2-3.2.1 names managers, system administrators, and users alike. Part-time staff and contractors who use your systems are not exempt from awareness.
- General users who handle controlled unclassified information (CUI). They need training tied to their duties with that data, which is what AT.L2-3.2.2 addresses.
- IT staff and system administrators. Their assigned security duties are broader than a general user's, so their role-based training goes deeper.
- Executives and the Affirming Official. Leadership carries oversight duties for the program, and under 32 CFR Part 170 an Affirming Official affirms the organization's compliance. Role-based training for executives covers those duties.
- New hires and people who change roles. Awareness at onboarding, then refreshed on your annual cycle, with re-training when someone's duties change.
A common pattern for DoD contractors: Common Core for everyone, the General Users role-based course for staff who handle CUI, the Executives course for leadership, and a documented roster that shows who was assigned what.
What CMMC Level 2 assessors typically ask to see
For the Awareness and Training domain, assessors look for evidence that training was assigned to the right people, actually completed, and refreshed on a stated cycle. Have these artifacts ready before an assessment:
- A written awareness and training policy or procedure, referenced in your System Security Plan.
- A training roster that maps each person to the course or courses they were assigned, organized by role.
- Completion records with dates, so training can be shown as current against your stated review cycle.
- Certificates of completion for individual learners.
- Evidence that content covers all three AT practices: general awareness, role-specific duties, and insider threat indicators.
- Your onboarding process for new hires and your process for re-training people whose roles change.
Completion dates matter because assessors compare them to your policy. If your policy says training is annual, a certificate dated more than 12 months back does not support that statement. Petronella buyers can download a roster CSV with learner names and completion dates and verify any certificate at /training/verify/, and CMMC course certificates expire after 12 months to match an annual cadence.
How to build an annual security awareness training plan
A plan you can hand to an assessor does not need to be complicated, but it needs to be written down and repeatable. A workable annual cycle looks like this:
- Map roles to practices. List every role in the company, then map each role to AT.L2-3.2.1 (all users), AT.L2-3.2.2 (anyone with security duties), and AT.L2-3.2.3 (all users). That map becomes both your assignment sheet and assessor evidence.
- Assign courses by role. Common Core for everyone, General Users for staff who handle CUI, Executives for leadership. Our AT.L2-3.2.1 guide and AT.L2-3.2.2 guide walk through the mapping in detail.
- Set completion windows. Give each course a due date, chase the stragglers, and record who completed what and when.
- Refresh every year. CMMC course certificates from Petronella expire after 12 months, so an annual re-enrollment keeps completion dates current without extra bookkeeping.
- Reinforce between courses. Short security reminders, phishing simulations, and periodic tabletop exercises keep awareness alive between formal courses.
- File the evidence. Export the roster CSV after each cycle and store it with the certificates. That folder is your assessor package for the AT practices.
How to choose a CMMC training provider
Not every security awareness course maps to CMMC Level 2 practices, and a course that never names the practices can leave you debating coverage mid-assessment. When you compare providers, check for:
- Explicit practice mapping. Course pages should state which practices the content supports, such as AT.L2-3.2.1, AT.L2-3.2.2, and AT.L2-3.2.3.
- Role-based options. Separate courses for general users and executives, because AT.L2-3.2.2 is about assigned duties, not one-size-fits-all content.
- Verifiable completion records. Certificates, a public verification page, and a roster export with completion dates.
- An expiry model that matches your cadence. Certificates that expire after 12 months line up with annual training instead of fighting it.
- Licensing that fits your size. Single seats, team packs, and an organization-wide license with one enrollment code, so you are not paying per-course for 300 people.
- Provider standing. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization (#1449) in Raleigh, NC, and the courses are taught by instructor Craig Petronella, a CMMC-RP.
You can start with a single seat of the Common Core course or compare the team and license options before committing to an organization-wide rollout.
Common CMMC training mistakes to avoid
- Treating training as a one-time event. Awareness fades and assessors look for a current cycle, not a certificate from a kickoff three years ago.
- Buying one generic course for everyone. It covers awareness but leaves AT.L2-3.2.2 unanswered, because role-specific duties never got trained.
- Skipping insider threat content. AT.L2-3.2.3 is its own practice. If your awareness course does not cover recognizing and reporting insider threat indicators, that is a gap.
- No role mapping. Without a document that assigns training by role, assessors cannot connect your roster to the practice.
- Stale records. Completion dates older than your policy's stated cycle work against you.
- Unassigned licenses. Seats purchased but never redeemed, or enrollment codes that never reached the employees, leave trained staff on paper only.
- Assuming training alone is compliance. Training supports the AT practices. It does not by itself make an organization CMMC compliant, so pair it with the rest of the controls, and start with a readiness assessment if you are unsure where you stand.
Training for HIPAA and FTC Safeguards obligations
The same discipline shows up outside CMMC. The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires a security awareness and training program for all members of the workforce, including management, with topics that include security reminders, protection from malicious software, log-in monitoring, and password management. The FTC Safeguards Rule, at 16 CFR 314.4(e), requires financial institutions to provide personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment. If those rules apply to your business, these courses cover them:
2026 Security Awareness Training
$49, 90 minutes. General awareness for any team that needs an annual refresh.
View courseFTC Compliance Mastery
$149. Supports staff training under the FTC Safeguards Rule, 16 CFR 314.4(e).
View courseHIPAA Rescue Manual for Healthcare Practices
$999. Built for practices working through HIPAA Security Rule obligations.
View courseHIPAA Compliance & Cybersecurity Mastery
$2,997. A deeper program for teams building out HIPAA compliance.
View courseSee all training courses, or the dedicated HIPAA training and security awareness training pages.
Frequently Asked Questions
Is security awareness training required for CMMC?
How often should training be conducted?
Can training be customized for our organization?
Do employees receive certificates upon completion?
Can training be delivered on-site?
CMMC training questions, answered
What does AT.L2-3.2.1 require for CMMC security awareness training?
AT.L2-3.2.1 requires organizations to make sure managers, system administrators, and users of organizational systems are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures. In practice, every person who uses your systems needs awareness training, including leadership, and you need records that show who completed it. The CMMC Level 2 Security Awareness: Common Core course, $49 per learner and about 63 minutes, maps to this practice and to AT.L2-3.2.3.
Which employees need role-based training under AT.L2-3.2.2?
AT.L2-3.2.2 requires personnel to be trained to carry out their assigned information security-related duties and responsibilities. That means anyone whose job includes security duties: general users who handle controlled unclassified information, IT staff and system administrators, and executives who oversee the program. Petronella offers CMMC Level 2 Role-Based Training: General Users for $59 and Role-Based Training: Executives for $149, each about 30 minutes, both mapped to AT.L2-3.2.2.
What does insider threat awareness training under AT.L2-3.2.3 cover?
AT.L2-3.2.3 requires security awareness training on recognizing and reporting potential indicators of insider threat. The training focuses on two skills: spotting warning signs, such as unusual data handling or policy circumvention, and knowing how to report a concern through your incident reporting process. The Common Core course includes insider threat awareness, and our insider threat program page explains how to build the surrounding program.
What training records do CMMC Level 2 assessors ask to see?
Assessors typically ask to see a written training policy, a roster that maps each person to the training they were assigned, completion records with dates, and certificates of completion for individual learners. They also check that content covers general awareness, role-specific duties, and insider threat indicators, and that completion dates fall within your stated training cycle. Petronella buyers can export a roster CSV with completion dates and verify certificates at /training/verify/.
How long are Petronella CMMC training certificates valid?
Petronella CMMC course certificates expire after 12 months, which matches an annual training cycle. When a certificate expires, re-enroll the learner so completion dates stay current for assessors. Anyone can confirm a certificate at /training/verify/.
Does HIPAA require security awareness training?
Yes. The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires a security awareness and training program for all members of the workforce, including management. Topics the rule calls out include security reminders, protection from malicious software, log-in monitoring, and password management. Our HIPAA training courses support this requirement for practices and covered entities.
What training does the FTC Safeguards Rule require?
The FTC Safeguards Rule, at 16 CFR 314.4(e), requires financial institutions to provide personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment. Because the training has to reflect current risks, it needs to be refreshed as your risk assessment changes. The FTC Compliance Mastery course, $149, supports this requirement.
How much does CMMC Level 2 security awareness training cost?
CMMC Level 2 Security Awareness: Common Core is $49 per learner for about 63 minutes of training. Role-Based Training: General Users is $59 and Role-Based Training: Executives is $149, each about 30 minutes. Common Core team packs are 10 seats for $290, 25 seats for $625, 50 seats for $999, and 100 seats for $1,499, with seats redeemable for 12 months. The organization-wide Awareness and Training License is $300 per user per year and includes all three CMMC courses.
How does the single enrollment code work for a whole organization?
The CMMC Level 2 Awareness and Training License covers 1 to 500 users at $300 per user per year and includes all three CMMC courses with one enrollment code. Orders of 25 or more users can be invoiced. If you only need the awareness course, Common Core team packs cover 10 to 100 seats.
How do we verify employee training certificates?
Every course ends with a certificate of completion, and anyone can confirm a certificate at /training/verify/. Administrators can also export a roster CSV with learner names and completion dates, which is the artifact assessors usually want alongside the certificates.
What is the difference between awareness training and role-based training?
Awareness training teaches everyone the security risks tied to everyday system use and how to recognize and report insider threat indicators, which maps to AT.L2-3.2.1 and AT.L2-3.2.3. Role-based training teaches people the specific duties their job carries, which maps to AT.L2-3.2.2. CMMC Level 2 assessors expect both, and our awareness and training compliance guide shows how the courses map to each practice.
Train Your Team to Be Your First Line of Defense
Contact Petronella Technology Group to implement cybersecurity training that reduces risk and supports CMMC compliance.
(919) 348-4912 Schedule Training5540 Centerview Dr., Suite 200, Raleigh, NC 27606
Why Choose Petronella Technology Group
Petronella Technology Group has been a trusted IT and cybersecurity partner for businesses across Raleigh, Durham, Chapel Hill, Cary, Apex, and the Research Triangle since 2002. Led by CEO Craig Petronella, an NC Licensed Digital Forensics Examiner (License# 604180-DFE), CMMC Certified Registered Practitioner, Cybersecurity Expert Witness, Hyperledger Certified, and MIT-certified professional in cybersecurity, AI, blockchain, and compliance, Petronella Technology Group brings deep expertise to every engagement.
BBB A+ Accredited since 2003 and founded in 2002, Petronella has the experience and track record to deliver results. Craig Petronella is an Amazon number-one best-selling author of books including "How HIPAA Can Crush Your Medical Practice," "How Hackers Can Crush Your Law Firm," and "The Ultimate Guide To CMMC." He has been featured on ABC, CBS, NBC, FOX, and WRAL, and serves as an expert witness for law firms in cybercrime and compliance cases.
Petronella holds certifications including CCNA, MCNS, Microsoft Cloud Essentials, and specializes in CMMC 2.0, NIST 800-171/172/173, HIPAA, FTC Safeguards, SOC 2 Type II, PCI DSS, GDPR, CCPA, and ISO 27001 compliance. Our forensic specialties include endpoint and networking cybercrime investigation, data breach forensics, ransomware analysis, data exfiltration investigation, cryptocurrency and blockchain analysis, and SIM swap fraud investigation.
The Petronella Compliance Process
Achieving and maintaining regulatory compliance requires a structured, repeatable process. Petronella has refined its compliance methodology since 2002, helping businesses navigate complex regulatory requirements. Our process begins with a comprehensive gap assessment that evaluates your current policies, procedures, and technical controls against the specific requirements of your target framework. This assessment identifies exactly where your organization stands and what needs to be done to achieve compliance.
Following the gap assessment, Petronella develops a prioritized remediation roadmap that outlines every action item needed to close identified gaps. We categorize items by risk level and effort required, allowing organizations to address the most critical deficiencies first while planning for longer-term improvements. Our consultants work alongside your team to implement technical controls, develop required policies and procedures, create employee training programs, and establish the documentation and evidence collection processes needed to demonstrate compliance during audits and assessments.
Compliance is not a one-time project but an ongoing commitment. Regulations evolve, threats change, and business environments shift. Petronella provides continuous compliance monitoring services that track your compliance status in real time, alert you to emerging gaps, and ensure that your security controls remain effective. We conduct regular internal audits, update policies as regulations change, and prepare your organization for external audits or assessments. Our goal is to make compliance a natural part of your business operations rather than a periodic scramble to meet audit deadlines.
For organizations subject to multiple compliance frameworks, Petronella takes a unified approach that maps overlapping requirements across frameworks. Rather than implementing separate programs for each regulation, we build a comprehensive security and compliance program that satisfies multiple requirements simultaneously. This integrated approach reduces costs, eliminates redundant processes, and provides a clearer picture of your overall security and compliance posture, making it easier to manage ongoing obligations and demonstrate compliance to auditors, clients, and business partners.
Our Approach to Cybersecurity
At Petronella Technology Group, cybersecurity is not just about installing antivirus software or setting up a firewall. We take a comprehensive, layered approach to security that addresses people, processes, and technology. Our methodology is built on industry-standard frameworks including NIST Cybersecurity Framework, CIS Controls, and MITRE ATT&CK, ensuring that your security program is aligned with the same standards used by Fortune 500 companies and government agencies. Every engagement begins with a thorough assessment of your current security posture, followed by a prioritized remediation roadmap that addresses your most critical risks first.
Our security operations team provides continuous monitoring through our Security Information and Event Management platform, which correlates events across your entire environment to detect threats in real time. When a potential threat is identified, our analysts investigate and respond immediately, often containing threats before they can cause damage. This proactive approach dramatically reduces the risk of successful cyberattacks and provides the rapid response capability that is essential in today's threat landscape.
We believe that employee awareness is one of the most important layers of defense. Technology cannot compensate for untrained employees, and informed employees are the layer of defense that catches what tools miss. Petronella provides comprehensive security awareness training programs that educate your team about phishing, social engineering, password security, data handling, and incident reporting. Our training programs include simulated phishing campaigns that test employee readiness and identify areas where additional education is needed, helping organizations build a strong security culture from the ground up.
Beyond prevention, Petronella prepares organizations for the reality that breaches can occur despite the best defenses. Our incident response planning services help businesses develop, document, and test response procedures so that when an incident does occur, your team knows exactly what to do. From tabletop exercises to full incident simulations, we ensure that your organization is prepared to respond quickly and effectively, minimizing damage, preserving evidence, and meeting all regulatory notification requirements within required timeframes.
Additional Questions and Answers
What compliance frameworks does Petronella help businesses implement?
How long does it take to achieve compliance certification?
What happens if a business fails a compliance audit?
What is the difference between SOC 2 Type I and Type II?
Can one compliance framework satisfy multiple regulatory requirements?
Petronella Service Areas
Petronella Technology Group delivers a comprehensive suite of technology and cybersecurity services to businesses throughout the Research Triangle. Our managed IT services provide proactive monitoring, maintenance, and help desk support that keeps your technology running smoothly and your team productive. We handle everything from server management and workstation support to cloud migrations and network infrastructure, giving you a complete IT department without the overhead of hiring in-house staff.
Our cybersecurity services protect your business from the constantly evolving threat landscape. We offer security risk assessments, vulnerability scanning, penetration testing, security awareness training, endpoint detection and response, email security, and managed SIEM monitoring. For businesses that need to meet regulatory requirements, our compliance consulting services cover CMMC, NIST, HIPAA, SOC 2, PCI DSS, GDPR, CCPA, ISO 27001, and FTC Safeguards Rule compliance with gap assessments, remediation planning, policy development, and audit preparation.
Petronella also provides digital forensics and incident response services for businesses and law firms dealing with data breaches, cybercrimes, and litigation support. Our forensic lab handles computer and mobile device forensics, network forensics, cryptocurrency investigation, and electronic discovery. Craig Petronella provides expert witness testimony and forensic consulting for attorneys across North Carolina. Additionally, our cloud services team manages migrations to and ongoing operations in Microsoft Azure, AWS, Google Cloud, and private cloud environments.
Our emerging technology practice helps businesses leverage artificial intelligence, blockchain, and automation securely and compliantly. From custom AI development and secure inference hosting to AI compliance consulting and blockchain security, Petronella ensures that organizations can adopt new technologies without compromising security or regulatory standing. We combine deep technical expertise with practical business insight to deliver technology solutions that drive real results for businesses of all sizes in the Raleigh-Durham-Chapel Hill area.
Ready to Get Started?
Contact Petronella Technology Group today for a free consultation. Serving Raleigh, Durham, Chapel Hill, and the Research Triangle since 2002.
(919) 348-4912 Schedule a Free Consultation5540 Centerview Dr., Suite 200, Raleigh, NC 27606
Ready to Get Started?
Schedule a free consultation with our team or call us directly. No pressure, no obligation.