Skip to main content
Trusted by Hundreds of MSPs

SOC 2 security awareness training requirements

SOC 2 (AICPA Trust Services Criteria). What the controls say, how often you have to train, what an assessor will ask to see, and the detail that fails most assessments.

app.hooksecurity.co/dashboard
Security Overview

Last 30 days

↓ 73% risk reduction
1,247
Phishing Tests
+12%
94.2%
Pass Rate
+8%
3,892
Trained Users
+156
Recent Activity
Phishing simulation completed
Marketing Team
2m ago
Training module finished
john.doe@company.com
15m ago
Suspicious click detected
sarah.smith@company.com
1h ago

Who this applies to

SaaS and technology companies proving security posture to enterprise customers, usually because a prospect or existing customer demanded a report.

The controls

CC1.4Commitment to competence

The entity provides training so personnel can develop and maintain the competencies needed to support its objectives. Maps to COSO Principle 4.

CC2.2Internal communication

The entity internally communicates the information, objectives and responsibilities needed to support internal control — including communicating information to improve security knowledge and awareness, and modelling appropriate security behaviors through an awareness program.

How often you have to train

At minimum annually for all personnel, with onboarding training for new hires. Type 2 reports test operating effectiveness across the whole audit window, so a single burst of training before fieldwork will not hold up.

What an assessor will ask to see

  • Per-employee completion records with dates, covering the entire audit period
  • Policy distribution and acknowledgement records
  • Evidence of ongoing awareness communication, not just an annual course
  • Onboarding training records for anyone hired during the window

The detail that fails most assessments

SOC 2 Type 2 tests a period, not a moment. Auditors sample across the window, so gaps in the middle of the year surface even when the year-end numbers look complete.

How Hook Security fits

Hook Security runs training and simulations continuously rather than in an annual burst, which is what a Type 2 window actually tests. Records export to Vanta automatically, or via REST API and CSV for any other platform.

Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.

The same records answer a cyber insurance questionnaire — see what underwriters ask for.

Show us your SOC 2 scope. We will tell you what we cover.

Thirty minutes, a live account, and an honest answer about the gaps.