Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

DoD Mandatory CUI Training: What It Is, Who Needs It, and How to Take It

  • cui
  • DoD Mandatory CUI Training: What It Is, Who Needs It, and How to Take It

The DoD's mandatory CUI training is a free, self-paced online course from the Center for Development of Security Excellence (CDSE), course number IF141.16. You can launch it directly at securityawareness.dcsa.mil/cui with no account or CAC required, and it takes roughly an hour to complete. It's required for all DoD personnel with access to CUI, and for defense contractors it fulfills the training requirement when your contract requires CUI training.

Below, we’ll dive deeper into who's required to take mandatory CUI training and how often, what your options are as a contractor, and how this course differs from the Cyber Awareness Challenge, which is a separate training that’s easy to mistake with CUI training.

What the DoD CUI training covers

The course provides a baseline introduction to the CUI Program: what CUI is and where it comes from, how to identify it using the DoD and ISOO CUI registries, how to apply CUI markings, safeguarding and dissemination requirements, decontrolling, destruction, and how to identify and report security incidents involving CUI. 

Successful completion produces a certificate, which you should save directly yourself. CDSE does not maintain a record of your completion, so the certificate you print or download is your only evidence.

Who is required to take CUI training, and how often?

Per DoDI 5200.48, all DoD personnel with access to CUI must complete CUI training. For defense contractors, the requirement flows through your contract: per the DCSA's CUI guidance for industry, DoD contractors require initial CUI training and annual refresher training, pursuant to DoDI 5200.48 and contractual requirements.

Tthe annual refresher cadence is a DoD requirement. Federal agencies governed only by the government-wide rule in 32 CFR 2002 require refresher training every two years. If you work across defense and civilian contracts, the DoD's annual cycle is the stricter standard, and following it satisfies both.

Contractor training requirements also connect to your compliance program. NIST SP 800-171 requirements 3.2.1 and 3.2.2 (the Awareness and Training family) require security awareness training and role-based training for personnel handling CUI, and a C3PAO assessing CMMC compliance will look for evidence that training happened. Completion certificates from IF141.16, tracked in a simple log with dates and names, are inexpensive, credible evidence.

Do contractors have to use the CDSE course?

Per the DCSA's training reference guide for industry, organizations may use the CDSE-developed training or create their own CUI training program based on the governing guidelines and regulations. Questions about what your specific contract requires should go to your Government Contracting Activity (GCA).

That said, most small and mid-sized contractors default to using the CDSE course. It's free, it's authoritative, it produces a certificate, and building an equivalent internal program costs more than it saves. 

The main reasons to build your own are if you want training tailored to your specific environment and workflows, or you want to fold CUI content into a broader security awareness program you already run. If you do build your own, it needs to cover the same ground the mandatory course covers, and your GCA is the authority on whether it satisfies your contract requirements. 

DCSA also encourages industry to supplement CUI training with the Unauthorized Disclosure course (IF130.16), which covers what happens when protected information gets out and how to respond. It’s optional, but a smart addition for anyone whose role involves sharing CUI externally.

CUI training vs. the DoD Cyber Awareness Challenge

These programs are easily confused, partly because both are mandatory DoD trainings that discuss CUI. But they are different courses with different purposes.

The Cyber Awareness Challenge is the DoD's broad annual cybersecurity training, produced by DISA. It covers phishing, identity protection, classified and unclassified information handling, insider threats, and more. It runs about 60 minutes, and the current version is the 2026 Challenge. 

The DoD Mandatory CUI Training (IF141.16) is dedicated entirely to the CUI Program and goes deeper on designation, marking, safeguarding, and decontrol.

The Cyber Awareness Challenge course teaches that Controlled Unclassified Information is government information that must be handled using safeguarding or dissemination controls, including categories like controlled technical information (CTI), personally identifiable information (PII), protected health information (PHI), and financial, payroll, and operational information. It is unclassified information, but it is not cleared for public release, and mishandling it carries real consequences. 

Recommended reading

What is Controlled Unclassified Information (CUI)?

Read More

The DoD recently announced that military personnel now complete the Cyber Awareness Challenge upon initial access and once every three years thereafter, per a memorandum reducing annual training requirements for service members. Civilian personnel and contractors still complete it annually. Note that this change applies only to the Cyber Awareness Challenge, not to CUI training, where the annual refresher requirement for contractors stands.

How to take the DoD Mandatory CUI Training

Go to securityawareness.dcsa.mil/cui and launch the course directly, no login required, or take it through CDSE's site if your organization tracks training through STEPP. Enable pop-ups, use a current browser, and save your completion certificate when you finish.

If you're responsible for training at your organization, collect certificates centrally and log completion dates so your annual refresher cycle and your assessment evidence are ready for your Affirming Official or contracting officer review.

Loading...