What compliance frameworks actually require of security awareness training.
Last 30 days
Requirements at a glance
The controls below are cited as published. Your auditor or assessor is the authority on how they apply to your environment — this is a reference, not legal advice.
| Framework | Controls | Minimum cadence | Who it applies to |
|---|---|---|---|
| SOC 2 | CC1.4, CC2.2 | At minimum annually for all personnel, with onboarding training for new hires. | SaaS and technology companies proving security posture to enterprise customers, usually because a prospect or existing customer demanded a report. |
| HIPAA | 164.308(a)(5)(i), 164.308(a)(5)(ii)(A-D) | Periodic and ongoing. | Covered entities and business associates — including any vendor touching electronic protected health information. |
| PCI DSS | 12.6.3, 12.6.3.1, 12.6.3.2 | On hire, then at least every 12 months. | Any organization that stores, processes or transmits cardholder data, and the service providers supporting them. |
| CMMC | AT.L2-3.2.1, AT.L2-3.2.2, AT.L2-3.2.3 | Annually at minimum, plus additional training when a user changes role or a significant new threat emerges. | Defense industrial base contractors and subcontractors handling Controlled Unclassified Information. |
Framework by framework
SaaS and technology companies proving security posture to enterprise customers, usually because a prospect or existing customer demanded a report.
The gotcha: SOC 2 Type 2 tests a period, not a moment. Auditors sample across the window, so gaps in the middle of the year surface even when the year-end numbers look complete.
Covered entities and business associates — including any vendor touching electronic protected health information. Solo practices are in scope exactly as much as health systems.
The gotcha: The six-year documentation retention requirement catches organizations that switched platforms. If a previous vendor holds the records and you no longer have access, you cannot evidence the earlier period.
Any organization that stores, processes or transmits cardholder data, and the service providers supporting them.
The gotcha: The per-employee annual clock is where most programs fail an assessment. A company-wide January training leaves anyone hired in March out of compliance by the following March, even though "everyone was trained this year" is technically true.
Defense industrial base contractors and subcontractors handling Controlled Unclassified Information.
The gotcha: AT.L2-3.2.2 is the one that fails assessments. Organizations run a single awareness course for everybody and have nothing separate to show for personnel with specific security responsibilities.
One program, several frameworks
The citations differ but the evidence converges: dated per-employee records, proof of what the content covered, and proof the program ran continuously. Most organizations should run one program and map it to every framework they are subject to, rather than running several.
The same records also answer a cyber insurance questionnaire — see what underwriters ask for.
Compliance questions
For most organizations, yes — though the obligation usually arrives indirectly. PCI DSS, HIPAA, CMMC and SOC 2 all require it, cyber insurance underwriters commonly ask for evidence of it at renewal, and enterprise customers increasingly require it of their suppliers. Very few organizations are told directly that training is mandatory; most discover it through a questionnaire, an audit or a customer security review.
Almost never. The frameworks differ in citation and cadence, but the underlying evidence is largely the same: dated per-employee completion records, proof the content covered the required topics, and evidence the program ran continuously rather than once. One well-documented program usually satisfies several frameworks at the same time.
It is the floor for PCI DSS and CMMC, and it is explicitly not enough for HIPAA, which names security reminders as an implementation specification. SOC 2 Type 2 tests a period rather than a point in time, so an annual burst leaves gaps that auditors sample into. In practice a continuous cadence is easier to evidence than an annual event.
Dated, per-employee completion records covering the full audit period; evidence of what the training content covered; acknowledgements where the framework requires them; and evidence that new hires were trained. Screenshots of a dashboard are weaker than exportable records, and records held only by a vendor you no longer use are not evidence at all.
No, and neither can any other platform. Compliance depends on your full control environment, your documentation and your auditor or assessor. What Hook Security does is produce the training evidence continuously and in exportable form, so that part of the assessment is not the thing that holds you up.
Bring your framework. We will show you the evidence it produces.
Thirty minutes, a live account, and a straight answer about what we do and do not cover.