DoD mandatory training requirements fall into two tracks that no longer look alike. Military service members follow a shrinking list of Common Military Training set by their service, reshaped by a September 2025 order from Defense Secretary Pete Hegseth. Civilian employees and contractors continue to work through the longer, largely annual list maintained by the Defense Civilian Personnel Advisory Service and the National Industrial Security Program. What you owe depends on which track you’re on, what you have access to, and what your component adds on top.
The Civilian Mandatory List
DCPAS publishes the official DoD-wide mandatory training list for civilian employees. It has three layers: training required by statute or government-wide regulation, training required by DoD directives, and role-specific training a component may add.1DCPAS. Civilian Mandatory Training Requirement List
The core courses every DoD civilian is expected to complete:
- Antiterrorism Level 1, annually, under DoDI O-2000.16.
- Combating Trafficking in Persons, within the first year and every two years thereafter, under DoDI 2200.01.
- Constitution Day/Citizenship Day, for new employees, under Public Law 108-447.
- Counterintelligence Awareness, annually, under DoDI 3305.11 and DoDD 5240.06.
- Ethics Orientation, within 90 days of entering duty, under 5 CFR Part 2638.
- Cybersecurity Awareness, annually on a fiscal year basis, under DoDD 8140.01 and DoDI 8500.01.
- No FEAR Act, within 90 days and every two years thereafter, under Public Law 107-174.
- Operations Security, annually, under DoDD 5205.02E.
- Sexual Assault Prevention, annually, under DoDD 6495.01.
- Privacy Act and PII, annually, under DoDI 5400.11.
- Records Management, annually, under DoDI 5015.02.
- Insider Threat Awareness, annually, under DoDD 5240.06.
- Unauthorized Disclosure of Classified Information, annually, under DoDI 5200.48.
- Controlled Unclassified Information, annually, under DoDI 5200.48 and Executive Order 13556.
- Workplace Violence Prevention, annually, under DoDI 1438.06.
- Safety and Occupational Health as required by the role, under DoDI 6055.01.
Unauthorized Disclosure and CUI may be delivered as a single session. Component heads and functional leaders may add role-specific requirements.1DCPAS. Civilian Mandatory Training Requirement List
Extra Obligations for Supervisors
Anyone who supervises DoD civilians, whether civilian or military, has additional training obligations under the 2019 DoD Managerial and Supervisory Learning and Evaluation Framework. New supervisors complete initial training within one year of appointment, with refresher training at least every three years. The authority is Section 1113 of the FY2010 NDAA and 5 CFR ยง 412.202.2DCPAS. DoD Managerial and Supervisory Learning and Evaluation Framework
Supervisory content covers performance appraisals, merit system principles, mentoring, equal opportunity, handling unacceptable performance, hostile work environments, prohibited personnel practices, labor relations, hiring authorities, and workforce incentives. Managerial content addresses coaching, delegation, change management, systems thinking, and emotional intelligence. The framework also requires new supervisors to be mentored by experienced ones.2DCPAS. DoD Managerial and Supervisory Learning and Evaluation Framework
What Each Core Course Covers
Cyber Awareness Challenge
Every Defense Department employee with government computer and network access must complete the Cyber Awareness Challenge. Its scenario-based format takes about an hour and covers threats and vulnerabilities in government and defense systems, intrusion methods, countermeasures, reporting obligations, and Privacy Act protection of personally identifiable information.3Defense Counterintelligence and Security Agency. Cyber Awareness Challenge The legal basis is the Federal Information Security Modernization Act of 2014 and multiple DoD instructions. Historically annual, its frequency has become the central focus of the current reforms.4Stars and Stripes. Cyber Awareness, Privacy Training Changes in the Army
Counterintelligence Awareness and Reporting
Under DoDD 5240.06, all DoD personnel receive initial CI training within 30 days of assignment and annual refresher training after that. Content includes foreign intelligence entity threats and methods (including social media exploitation), insider threat indicators, anomalous behavior recognition, and foreign travel and contact reporting.5Department of Defense. DoDD 5240.06, Counterintelligence Awareness and Reporting The directive prefers a classroom setting led by a counterintelligence-experienced person but allows other media where that isn’t feasible. Records are kept for five years. Failure to report can lead to disciplinary action for civilians or punitive action under Article 92 of the UCMJ for service members. CDSE delivers the eLearning version, course CI116.16, as a 60-minute module requiring a 75 percent passing score.6CDSE. Counterintelligence Awareness and Reporting for DoD
Antiterrorism Level 1
JS-US007 Level I Antiterrorism Awareness Training is hosted on Joint Knowledge Online and required annually by DoDI 2000.16. It is used across all services and combatant commands for annual compliance, pre-deployment preparation, and family member training.7Joint Chiefs of Staff. Antiterrorism Training on JKO Offers Broad Reach
Information Security
DoD Manual 5200.01, Volume 3, sets a two-part structure. All personnel receive an initial orientation covering classified and controlled unclassified information definitions, security policies, personal responsibilities, and sanctions. Those with access to classified information systems receive further training on electronic marking, media handling, and data spill reporting.8CDSE. DoDM 5200.01-V3, Enclosure 5
The initial CDSE course, IF140.16, is a 60-minute module requiring 80 percent to pass. The annual refresher, IF142.06, runs about 25 minutes, requires 75 percent on a pre- or post-test, and must be completed in a single session.9CDSE. DoD Initial Orientation and Awareness Training10CDSE. DoD Annual Security Awareness Refresher Original classification authorities must train before exercising that authority and annually thereafter, with written certification. Derivative classifiers and declassification authorities train at least every two years; missing the deadline suspends the authority to classify until training is completed.8CDSE. DoDM 5200.01-V3, Enclosure 5
Controlled Unclassified Information
Course IF141.16 is a 45-minute module required for any DoD military, civilian, or contractor personnel who handle CUI. It covers eleven topics from DoDI 5200.48 and 32 CFR Part 2002: marking, physical safeguards, destruction methods (cross-cut shredding to specified dimensions or pulverizing), incident reporting, and sharing and decontrolling CUI. Passing score is 70 percent.11CDSE. DoD Mandatory Controlled Unclassified Information Training Contractors may use the CDSE course or develop their own, provided it covers all eleven required topics and is built on the governing laws and regulations.12Defense Counterintelligence and Security Agency. CUI Training Reference Guide
Ethics
The Joint Ethics Regulation requires initial ethics training within 90 days of entering duty and annual training after that. The annual requirement matters especially for those who file SF-278 or SF-450 financial disclosure forms. Administrative officers keep completion records for three years. Content follows Executive Order 12674 and 5 CFR Parts 2635 and 2638.13Department of Defense. Joint Ethics Regulation14Naval Support Activity Monterey. Ethics Training
Insider Threat Awareness
Course INT101.16 is required annually and teaches recognition of insider risk indicators through case studies, plus reporting procedures. It is available on the CDSE Security Awareness Hub without registration or on STEPP for formal transcript records. If you complete it on the Hub, print or save the certificate yourself. CDSE does not retain records for Hub completions.15CDSE. Insider Threat Awareness16Defense Counterintelligence and Security Agency. Insider Threat Awareness Course
Operations Security
DoDD 5205.02E requires OPSEC awareness training at initial entry and annually. OPSEC program managers, information operations professionals, public affairs officers, and contracting specialists receive additional specialized training. Personnel deploying overseas must complete area-specific OPSEC training before arrival, with the geographic combatant commands responsible for that content.17Department of Defense. DoDD 5205.02E, DoD Operations Security Program
Contractor Requirements Under NISPOM
Cleared contractors under the National Industrial Security Program follow 32 CFR Part 117, the NISPOM Rule. Every cleared employee receives an initial security briefing before accessing classified information, covering threat awareness, counterintelligence, the classification system, reporting obligations, cybersecurity, and the legal consequences of unauthorized disclosure. Annual refresher training is required for all cleared employees.18eCFR. 32 CFR 117.12, Security Education and Training
Facility Security Officers must complete FSO orientation and program management courses within six months of appointment. Derivative classification training is required before an employee may make any classification decision, with refresher training every two years. Insider threat awareness training is annual for all cleared employees, and cleared authorized users of information systems receive training keyed to the specific risks of their role.18eCFR. 32 CFR 117.12, Security Education and Training
Where the Courses Live
The Center for Development of Security Excellence, part of DCSA, is the primary hub for security-related training across the department. CDSE offers eLearning, instructor-led classes at its facility in Linthicum, Maryland, virtual sessions, case studies, job aids, and webinars. Its Security Awareness Hub hosts the most commonly assigned mandatory courses without registration, which is the fastest path to completing annual requirements. For formal transcripts and continuing education credit, STEPP is the tracked learning management system.19CDSE. CDSE Training20CDSE. Center for Development of Security Excellence
Joint Knowledge Online hosts the Antiterrorism Level 1 course and other joint training.7Joint Chiefs of Staff. Antiterrorism Training on JKO Offers Broad Reach The Air Force uses myLearning; the Marine Corps uses MarineNet and the Total Workforce Management Service.21United States Marine Corps. Annual Cyber Awareness Training and Cyber Awareness Challenge Training Compliance Travel-related training runs through the Defense Travel Management Office’s TraX platform, reached via the Passport single sign-on portal.22Defense Travel Management Office. DTMO eLearning
What Changed in 2025 and 2026
On September 30, 2025, Secretary Hegseth issued a memorandum titled “Reduction of Mandatory Training Requirements to Restore Mission Focus.” The memo said too much mandatory training was pulling service members away from warfighting preparation and that online courses had become an administrative burden.23Department of Defense. Reduction of Mandatory Training Requirements to Restore Mission Focus
The memo targeted specific courses. Cybersecurity training and CUI training were to have their annual frequency relaxed. Records Management was to be narrowly tailored to specific roles with greater delivery flexibility. Privacy Act training was to come off the Common Military Training list entirely. Combating Trafficking in Persons refresher frequency was to be eliminated pending legislative action. Remaining topics were to be consolidated, and “test-out” options for refreshers expanded. Training on harmful behaviors was to clearly separate prevention content from response procedures. A 60-day review of military education and training standards ran alongside the memo.23Department of Defense. Reduction of Mandatory Training Requirements to Restore Mission Focus24U.S. Army. Hegseth Announces Series of War Department Reforms
Army
The Army updated Army Regulation 350-1 and cut mandatory items from 27 to 16. Resiliency training was eliminated. Several topics moved to commander discretion, including CBRN training, combat lifesaver, safety and occupational health, law of war, code of conduct, and online SERE and personnel recovery courses.25Army Times. Army Slashes Mandatory Training Requirements With Regulation Update
In February 2026 the Army went further on cyber. It reduced the Cyber Awareness Challenge from annual to once every five years for soldiers, and its Chief Information Officer shifted primary responsibility for cybersecurity awareness to individual commanders, who tailor training to their unit’s mission risks.4Stars and Stripes. Cyber Awareness, Privacy Training Changes in the Army
Navy
NAVADMIN 066/26, issued March 23, 2026, set the FY26 Common Military Training list at six topics: counterintelligence and insider threat awareness and reporting; Cyber Awareness Challenge; operations security; sexual assault prevention and response awareness; suicide prevention; and records management. CUI training became biennial, redundant topics were eliminated, and command-delivered, in-person training was preferred where possible. These changes are in effect through September 30, 2026.26U.S. Navy. NAVADMIN 066/26, FY26 Common Military Training Requirements The underlying instruction, OPNAVINST 1500.22J, was issued September 11, 2025.27Department of the Navy. OPNAVINST 1500.22J, Common Military Training
Pentagon-Wide Cyber
By mid-2026 the Pentagon was moving toward a department-wide policy requiring service members to complete cybersecurity training once every three years, a compromise between the traditional annual requirement and the Army’s five-year interval. The Army indicated it would align with the Office of the Secretary of Defense’s guidance once finalized.28DefenseScoop. Pentagon Changing Cybersecurity Training Requirement
Civilians and Contractors Are Not Included
The Hegseth memo and the service-level reforms target military Common Military Training. Civilian employees and contractors continue on the existing DoD-wide mandatory list under DCPAS, which the reforms have not modified. Cybersecurity training for civilians and contractors remains annual even as the military branches move to multi-year cycles.28DefenseScoop. Pentagon Changing Cybersecurity Training Requirement An integrated review across topics is ongoing, and further changes to both military and civilian requirements could follow.26U.S. Navy. NAVADMIN 066/26, FY26 Common Military Training Requirements