4.92 (212)

CMMC Training for Defense Contractors (DIB)

Categories: CMMC, NIST

Play Video

Course Information

Are you overwhelmed by CMMC? This course will save you WEEKS of research and set you up for success as you prepare for CMMC!

This course provides you with the essential knowledge you need to confidently make those critical (and costly) decisions, such as understanding which CMMC level you should pursue, selecting a compliant MSP, or choosing compliant cloud solutions, all of which are crucial for achieving CMMC certification.

Jacob Hill is leading the CMMC charge at a defense contractor and created this course specifically for other contractors so they can quickly get up to speed on CMMC!

Interested in more than 25 licenses? Contact us for bulk discounts.

Who Should Take This Course?

This overview course is for defense contractor personnel who need an in-depth understanding of CMMC.

Do you need to educate the rest of your organization? Check out our CMMC Awareness Training.

This course is also available for sale to government on GSA Advantage.

Why Should You Take This Course?

CMMC certification (or compliance) will be required to win DoD contracts.

Jacob Hill has been leading the CMMC charge at a small business for several years, and he also previously served in the government as a DoD Contracting Officer Representative (COR). His unique background allows him to simplify complicated topics.

The course is taught in a series of online micro-lectures that are delivered in a focused bottom-line-up-front format and provides a comprehensive overview of your FAR and DFARS cyber contractual requirements.

What is CMMC?

Cybersecurity Maturity Model Certification (CMMC) is a cybersecurity compliance and certification program which the United States Department of Defense (DoD) created that is focused on gaining assurance that its supporting contractors are implementing the 110 requirements to protect its controlled unclassified information (CUI). Nearly all DoD contractors will need to be CMMC compliant or certified to be able to do business with the DoD.

CMMC requirements will begin to appear in contracts by the 4th quarter of 2025.

What is NIST 800-171?

The majority of CMMC’s requirements are based on NIST 800-171, “Protecting CUI in Nonfederal Systems and Organizations.” Most contractors are ALREADY required to comply with NIST 800-171 per DFARS 252.204-7012, and have been required to comply since December of 2017.

Are you compliant? If not, do you know what steps you need to take?

What Companies need to be CMMC Certified?

Nearly all DoD contractors will be required to comply with CMMC in some manner. CMMC consists of 3 levels, and the requirements vary per level:

  • CMMC Level 1
    • Implement 15 CMMC controls
    • Required for contracts with federal contract information (FCI)
    • Contractor is required to perform a self-assessment – no 3rd-party assessment is required
  • CMMC Level 2
    • Implement 110 CMMC controls
    • Required for contracts with CUI
    • Nearly all contracts will require a 3rd-party assessment by a C3PAO resulting in CMMC certification
  • CMMC Level 3
    • Implement 24 additional CMMC controls
    • Required for DoD’s most critical CUI programs
    • All contracts will require a 3rd-party assessment by DIBCAC resulting in CMMC certification

CMMC is an evolving field, and this course will be updated as changes occur. This course is being completely updated and rerecorded and the new version should be available in August 2025!

Enroll Now

Arm yourself with the knowledge you need to successfully navigate the processes of NIST 800-171 and CMMC. Don’t let your business fail because you didn’t achieve compliance or certification.

*This has been created for the DIB by a member of the DIB, and is not affiliated with the DoD, the CyberAB (also known as the CMMC Accreditation Body) or the Cybersecurity Assessor and Instructor Certification Organization (CAICO).

Peer Reviewers

Thank you to the following subject matter experts who peer reviewed this course:

Featured Reviews

Jordan Watson

- 01/09/2025
(5)

This was an excellent course that thoroughly describes and easily breaks down the CMMC requirements and references. I would highly recommend this course to anyone looking to further develop and prepare themselves for CMMC roles.

View Credly Badge
Show More

Shauna Weatherly

- 01/09/2025
(5)

Helpful explanation of the information

View Credly Badge
Show More

Tiffany Laitola

- 02/07/2023
(5)

This course was outstanding! The bite-sized pieces of instruction were delicately balanced between the necessary information to cover and the right amount of it to cover. It was not overwhelming and it was easy to follow. The quizzes added value and reinforced each topic in a no nonsense-type of way. What was even better was that I actually enjoyed the course, it somehow was a bit fun to me!

If you have never heard of CMMC or are considering the certification, this is a great foundational course to familiarize yourself with it. Look no further!

Thank you GRC Academy and Jacob Hill. I look forward to exploring future courses.

Update: I just achieved the CMMC Certified Professional (CCP) certification! This course was such a huge help! It gave me a good foundation for starting my actual CCP course. It should be a pre-requisite for all RP and CCP courses, in my opinion.

View Credly Badge
Show More

Kelsey Morris

- 02/01/2023
(5)

The training is nothing short of excellent. As if learning and understanding the requirements of CMMC is not confusing enough, this course will help you cut through the confusion (and varied opinions out there) and get you headed on the right path. It will provide you with the knowledge and resources, as well as a plan, to confidently move your company forward with CMMC.

View Credly Badge
Show More

What Will You Learn

  • What is Federal Contract Information (FCI)
  • What is Controlled Unclassified Information (CUI)
  • The history of NIST 800-171 & CMMC and what it means to you
  • What DFARS 252.204-7012, 7019, 7020, and 7021 mean to you
  • How to comply with NIST 800-171
  • The 110 NIST 800-171 security requirements
  • How to calculate a NIST 800-171 score per the DoD assessment methodology
  • How NIST 800-171 relates to CMMC
  • The 3 levels of CMMC
  • When CMMC will be required
  • What is a Joint Surveillance Voluntary Assessment (JSVA)
  • Which CMMC levels require self-assessment & 3rd-party assessment
  • Roles in the CMMC assessment ecosystem
  • How to scope for CMMC
  • How to prepare for a CMMC assessment
  • How to get CMMC certified
  • CMMC and Managed Service Providers (MSPs)
  • Action plan

Course Content

Introduction00:03:45
  • All Levels
  • 369 Total Enrolled

  • 3 Hours 32 Minutes Duration

  • 49 Lectures

  • 12-Month Access
  • September 4, 2025 Last Updated

A course by

GRC Academy

Taught by

Founder of GRC Academy | CISSP-ISSEP, CCP

Peer Reviewed by

CCP, CMMC PI/PA Candidate, CMMC LTP, CISSP, PMP
CMMC RP, CISSP, CISM, CRISC

Material Includes

  • Spreadsheet with NIST 800-171, NIST 800-171A, and CMMC controls

Audience

  • DoD contractors
  • Defense Industrial Base (DIB)
  • Federal contractors
  • Small Businesses
  • Medium Businesses
  • Large Businesses
  • Government Entities
  • Anyone who wants an in-depth understanding NIST 800-171 and CMMC

4.92-Star Rating | 212 Course Reviews

Course Reviews

Gino Gerard

- 08/27/2025
(4)

This course was very informative and provided a great foundation for understanding the basics of CMMC. As someone who recently started a career in cybersecurity after graduating from college, I found it extremely helpful.

Show More

Ramjee Adhikary

- 08/24/2025
(5)

Excellent course materials; highly recommended.

Show More

Thomas Carrier

- 08/22/2025
(5)

Great course!

Show More

Kevin Offutt

- 08/15/2025
(5)

Great course

Show More

Anthony Vecchione

- 08/14/2025
(5)

The course was well done and very helpful.

Show More

Donald Fountain

- 08/10/2025
(5)

Really well-structured course. As a systems engineer learning CMMC Level 2, I found it easy to follow and engaging.

Show More

Yung Leung

- 08/09/2025
(4)

If cybersecurity frameworks were a genre, CMMC would be the slow-burn political thriller—heavy on policy, light on popcorn. While the subject matter leans heavily toward rules, controls, and compliance jargon, the instructor does a commendable job keeping it structured and digestible. Reference materials are also provided for those who would like to dive a little deeper.

Each chapter ends with a quiz to reinforce key concepts, which helps break up the monotony and ensures you’re not just zoning out while staring at acronyms like a deer in headlights. The presentation is clear, methodical, and professional—no flashy animations or dramatic plot twists, but that’s probably for the best when discussing such a vast subject.

Was it boring? A little. But that’s the nature of the content, not the fault of the instructor. You don’t take a CMMC course for entertainment—you take it because you want to stay compliant and avoid awkward conversations with auditors. And in that regard, this course delivers exactly what it promises.

Show More

Kaitlyn Bussey

- 08/03/2025
(5)

It was very informative and went over critical information multiple times. Helps to provide a better understanding of CMMC.

Show More

Abdullateef Obomeghie

- 07/19/2025
(5)

Great course and very good resources. Lots of information but easy to understand. I definitely would recommend this course for everyone seeking to get good knowledge of CMMC ????

Show More

Anurag Baral

- 07/07/2025
(5)

Very thorough, and entertaining lectures. For a topic that can seem boring (compliance can be boring after all, let’s be honest), the instructor does a great job keeping us engaged. Also clear explanations with examples, and as the course went on my understanding grew

Show More

Colin Wunch

- 06/11/2025
(5)

Very in depth, and entertaining as well!

Show More

Earl Deas

- 06/09/2025
(5)

Just completed the CMMC overview training and now I am closer to my goal of changing to a new career direction. This course provided the information I needed in a “user friendly” manner with bite – sized , expertly explained sections, in addition to the reference materials and additional sources of information made available to me that I was able to down load. As courses go, I really appreciate the presentation and level of expertise throughout the course. 5 stars all day long!

Show More

Josh Eby

- 05/13/2025
(5)

It was very helpful for getting ramped up on CMMC.

Show More

Victor Franco

- 05/07/2025
(5)

Amazing. I’ve taken both the CCP and CCA courses, including study material from those courses. This GRC Academy was head and shoulders better. It’s far more clear and succinct. 10/10 recommend! This is the best overall course I’m aware of.

Show More

Hannah Koontz

- 04/08/2025
(5)

AMAZING — I’ve gained so much knowledge throughout this course & so happy that I will now be able to apply it. The information is perfectly organized to mirror the best way to learn any and everything CMMC. The information is also highly digestible with several real-life examples provided.

Show More