ClickCerts
Back to all posts

CMMC Assessors: Here’s a Security Awareness Training Tool You Can Actually Recommend.

What to recommend when CMMC clients ask about security awareness training. Auditor-ready certificates, quarterly cadence, and a reseller program that pays.

June 25, 2026ClickCerts Team
CMMC Assessors: Here’s a Security Awareness Training Tool You Can Actually Recommend.

A note for C3PAO assessors, independent CCAs, and MSP-affiliated reviewers. Every contractor you assess needs ongoing security awareness training. Here’s what auditor-ready actually looks like — and how you can earn referral revenue when you point clients somewhere good.

Every CMMC assessor has the same conversation a dozen times a year.

You sit down with a contractor. You walk through their environment. You get to AT.L2-3.2.1 — the security awareness training control — and they show you a 45-minute video their HR person assigned to everyone in 2023. Nobody’s done it since. There’s no record of who completed it. There’s no evidence of ongoing training. There’s no role-based content for privileged users. There’s certainly no insider-threat awareness piece to satisfy 3.2.3.

You write it up. You note the gap. You move on.

And then they ask the question every assessor hears: “What should we use?”

And you can’t really answer. Not formally. Not as part of the assessment. But you also don’t want to leave them stuck — because if they don’t fix it, they’ll fail the next gap-closure review, and that’s bad for them and bad for your scheduling. So you mumble something about one of the major platforms, and you both move on.

This post is for those moments.

What the controls actually require (the version assessors live with)

The relevant NIST 800-171 controls — pulled forward into CMMC Level 2 — are short and unambiguous:

  • AT.L2-3.2.1 — Ensure managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures.

  • AT.L2-3.2.2 — Ensure personnel are trained to carry out their assigned information security-related duties and responsibilities.

  • AT.L2-3.2.3 — Provide security awareness training on recognizing and reporting potential indicators of insider threat.

What every assessor knows that isn’t on the page: “made aware” and “trained” and “provide” are ongoing verbs. Not done once. Not done at hire. Ongoing. That word matters because it’s what most contractors miss — and what the DoD has consistently flagged as a common deficiency.

If the contractor can’t show you ongoing training within a defined cadence, with documented per-user completion records, with content that includes an insider-threat component, they don’t have AT.L2 satisfied. They have a checkbox.

What auditor-ready evidence looks like

You’ve seen the bad versions. Spreadsheet of attendees from a lunch-and-learn. Self-attestation form. “Our employees took it during onboarding.” A YouTube link from as SharePoint site or a shared drive.

You want three things:

  1. Per-user completion records, dated, with the course content identified.

  2. Ongoing cadence — evidence that training is a recurring program with a defined interval, not a one-time event.

  3. Insider-threat content — explicit coverage of indicators, reporting paths, and the contractor’s own internal escalation process.

If the contractor can produce those three things on demand, AT.L2 is in good shape. If they can’t, no amount of policy documents or screenshot evidence is going to close the gap.

The platforms that work for this are the ones that produce a documented certificate of completion per user, per course, on a defined cadence — and store that record where the contractor can pull it for you on demand. The platforms that fight you on this are the ones built around phishing simulations and dashboards full of “campaigns” but no actual proof that any individual employee completed any specific training.

What we built ClickCerts to do

We built ClickCerts specifically for the contractor who needs auditor-ready evidence and doesn’t want to buy a platform designed for a Fortune 500 SOC team.

Three things matter, and they’re the three things assessors keep asking for:

  • A certificate of completion is generated for every user, for every module, with the course content, completion date, and a verifiable serial number. The certificate is the artifact you can point to in the evidence pack. Not “the dashboard says they did it” — an actual PDF.

  • A quarterly cadence is enforced by the platform. Every customer gets one new training module every 90 days, anchored to when they joined. The contractor cannot crowd everything into Q1 and forget about training the rest of the year. The cadence itself is the evidence of “ongoing.”

  • Insider-threat content is built in. The Q1 modules addresses it and the Q3 module every year focuses on data handling, privacy, and insider threat with a deeper look — directly mapped to AT.L2-3.2.3.

That’s the product. We’re not pretending it’s the only thing a contractor needs to pass CMMC Level 2. But for the SAT controls specifically, it’s purpose-built for auditor evidence, and it’s priced for small contractors who don’t have a security budget that supports a $35+-per-user platform.

Why this matters for your practice

A few things assessors tell us:

  • Every assessment you do with a contractor whose SAT program is unmanaged is an assessment that’s going to come back to you for gap remediation. That’s billable, but it’s also a scheduling drag and a relationship tax.

  • You can’t formally endorse a vendor as part of an assessment. Everyone knows this. But contractors ask for recommendations constantly, and “I can’t tell you” is the worst answer you can give them.

  • Having a known-good recommendation in your back pocket — one that's priced for the contractor in front of you, that produces the evidence you actually need to see, and that you've personally validated — is genuinely useful.

The partnership ask

ClickCerts has a reseller program. It’s straightforward.

  • A generous discount off retail. You set your own end-customer pricing. The margin is yours, and we never see what you charge them.

  • No onboarding fee. No annual commitment for you as the reseller. You sign up when you have a client to bring on, not on spec.

  • Independent assessors and MSP-affiliated assessors both fit. Solo CCA — refer clients, earn margin. MSP-employed reviewer — your MSP carries the wholesale and runs it as a service line.

  • 50 free seats for your own team. Use ClickCerts internally first, validate the product, then resell with confidence.

  • You’re the prime contractor. The customer has a relationship with you. ClickCerts bills you on a single invoice; you bill your customer however you want.

The model is built for low-friction recurring referrals. You assess a contractor. They need SAT. You point them at a tool you actually use, that you actually trust, and that pays you a meaningful margin for the relationship.

What to do next

If you want to evaluate the product as an assessor first, that’s the right move. Set up a free internal account for your own team (up to 50 employees), see what the certificates look like, walk through the cadence yourself, and decide whether it’s something you’d be comfortable recommending.

Contact us through the form on this site, or email sales@clickcerts.com. Mention you’re a CMMC assessor and we’ll get you set up. We built this product for the contractor who needs evidence and the assessor who needs to recommend something. If you’re either one, let’s talk.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.