Every major security framework requires security awareness training, but none of the ones covered here explicitly mandates phishing simulation. SOC 2 (CC1.4 and CC2.2), ISO/IEC 27001:2022 (Annex A 6.3), HIPAA (45 CFR 164.308(a)(5)), PCI DSS v4.0 (Requirement 12.6), NYDFS (23 NYCRR 500.14(a)(3)), the GLBA Safeguards Rule (16 CFR 314.4(e)), DORA (Article 13(6)) and NIS2 (Articles 20(2) and 21(2)(g)) all require a training program, and PCI DSS and NYDFS go further by requiring at least annual training that covers phishing or social engineering. Phishing simulations are a common way organizations prove that training works, and cyber insurers increasingly treat training plus phishing testing as a core underwriting control.
Most awareness programs start as a checklist: an annual course, a quiz, a completion report exported the week before fieldwork. That passes many audits until an assessor asks how you know the training worked, or an underwriter asks for simulation results.
This guide maps the exact clause in each framework, what auditors usually ask to see, and how to build one evidence pack that covers all of them. For a vendor shortlist, see our companion piece on the best security awareness training for regulated industries.
This article is general guidance and not legal advice. Confirm how each requirement applies to your organization with your auditor, QSA, or counsel.
Security Awareness Training Requirements by Framework
The table below lists the specific clause or control in each framework, whether it requires training, whether it explicitly requires phishing simulation, the frequency it states, and the evidence auditors typically request.
Framework | Clause or control | Requires training? | Explicitly requires phishing simulation? | Frequency stated | Evidence auditors typically ask for |
|---|---|---|---|---|---|
SOC 2 (AICPA Trust Services Criteria) | CC1.4 (COSO principle 4, competence) and CC2.2 (COSO principle 14, internal communication) | Yes | No | None; auditors test your own policy | Policy, completion records for the period, new-hire timing, content sample, acknowledgments |
ISO/IEC 27001:2022 | Annex A 6.3; Clauses 7.2 (competence, evaluate effectiveness) and 7.3 (awareness) | Yes | No | "Regular updates" of policies; no fixed interval | Training plan, records by role, effectiveness evidence, management review inputs |
HIPAA Security Rule | 45 CFR 164.308(a)(5), four addressable specifications | Yes, all workforce including management | No | "Periodic security updates"; no fixed interval | Program documentation, completion records, reminders, addressable-specification decisions |
PCI DSS v4.0 / v4.0.1 | Requirements 12.6.1 to 12.6.3.2, including 12.6.3.1 (phishing and social engineering) | Yes | No; training must cover phishing and related attacks | Upon hire and at least once every 12 months | Program and annual review record, phishing content, completion records, annual acknowledgments |
NYDFS Cybersecurity Regulation | 23 NYCRR 500.14(a)(3), as amended November 1, 2023 | Yes, for all personnel | No. Training must include social engineering | At minimum annually | Records for all personnel, social engineering content, link to risk assessment |
GLBA Safeguards Rule (FTC) | 16 CFR 314.4(e)(1), plus 314.4(e)(3) for security staff | Yes | No | None; "updated as necessary" per risk assessment | Training records, link to risk assessment, annual board report under 314.4(i) |
DORA (EU) 2022/2554 | Article 13(6); Article 5(2)(g) on budget | Yes, compulsory for all staff and senior management | No | None; proportional | Program records, senior management content, budget approval, third-party inclusion |
NIS2 Directive (EU) 2022/2555 | Article 20(2) (management body) and Article 21(2)(g) (cyber hygiene and training) | Yes | No | "On a regular basis" (Art. 20(2), employees) | Board and workforce training records, national law requirements |
Every framework requires training and most leave the method to you. The two that prescribe content, PCI DSS and NYDFS, prescribe phishing and social engineering, which is exactly what a simulation measures.
What Security Awareness Training Is Required for SOC 2 Compliance?
SOC 2 requires security awareness training through two Trust Services Criteria: CC1.4 and CC2.2. CC1.4 maps to COSO principle 4, under which the organization demonstrates a commitment to attract, develop and retain competent individuals. CC2.2 maps to COSO principle 14, under which the organization internally communicates the information and responsibilities people need to support internal control. The revised points of focus for CC2.2 include "Communicates Information to Improve Security Knowledge and Awareness," which describes communicating security information to personnel through a security awareness training program.
SOC 2 prescribes no curriculum, frequency or test. It is an attestation against controls you define. If your control says "training within 30 days of hire and annually thereafter," the auditor samples the audit period and tests exactly that, and a missed window is an exception.
In practice, a SOC 2 Type II auditor asks for the training policy, a population list with hire dates, timestamped completion evidence for a sample, new-hire completion inside your stated window, policy acknowledgments, and course content.
Phishing simulations are optional for SOC 2. Many teams include them anyway, because a simulation program with documented report rates and follow-up training is strong support for CC2.2 (people know how to report incidents) and for the risk assessment criteria. If you add simulations to your written control, though, the auditor will test them too, so describe the cadence you can actually sustain.
Does ISO 27001 Require Employee Phishing Testing?
No. ISO/IEC 27001:2022 does not explicitly require phishing simulation. What it does require is broader, and in practice often satisfied with simulation data.
Annex A 6.3 requires appropriate awareness, education and training, plus regular updates on policies and procedures relevant to each job function. Clause 7.3 requires people to be aware of the security policy, their contribution to the ISMS, and the implications of not conforming. Clause 7.2 matters most for testing: when the organization acts to build competence, it must evaluate the effectiveness of those actions.
That "evaluate effectiveness" language is why phishing simulations show up in so many ISO 27001 certification audits. A completion record proves someone sat through a course; it says nothing about whether the course worked. ISO/IEC 27002:2022, the guidance for Annex A, describes assessing understanding and monitoring program effectiveness. Simulation results (click rate, report rate, trend, follow-up training) give the auditor an objective measure.
Practical guidance for ISO 27001:
Document a training plan scoped by role, and keep completion records as documented information.
Pick at least one effectiveness measure: simulation results, quiz scores, or incident reporting data.
Feed results into management review under Clause 9.3 and record what changed.
Match simulation channels to your risk register. If voice fraud or SMS lures are listed risks, an email-only program leaves them without control evidence. See our guides to smishing simulation tools and vishing simulation tools.
HIPAA Security Awareness Training Requirements
The HIPAA Security Rule requires covered entities and business associates to "implement a security awareness and training program for all members of its workforce (including management)" under 45 CFR 164.308(a)(5)(i). The standard has four implementation specifications, all addressable:
Security reminders: periodic security updates.
Protection from malicious software: guarding against, detecting and reporting it.
Log-in monitoring: monitoring log-in attempts and reporting discrepancies.
Password management: creating, changing and safeguarding passwords.
"Addressable" does not mean optional. It means you must assess whether each specification is reasonable and appropriate for your environment, implement it if so, and document an equivalent alternative or your rationale if not. HIPAA sets no training frequency and does not mention phishing simulation, though simulations are a practical way to show the malicious software and reporting procedures work.
Documentation matters under HIPAA. 45 CFR 164.316(b)(2) requires keeping required documentation for six years from its creation or the date it was last in effect, whichever is later. Keep training records, reminder communications and your addressable-specification decisions on that schedule.
HHS proposed Security Rule updates in January 2025; check the rule's current status with counsel before planning next year.
PCI DSS 4.0 Security Awareness Requirements
PCI DSS v4.0 (and the v4.0.1 limited revision) is the most prescriptive framework on this list. Requirement 12.6 breaks down as follows:
12.6.1: A formal security awareness program makes all personnel aware of the information security policy and procedures and their role in protecting cardholder data.
12.6.2: The program is reviewed at least once every 12 months and updated as needed to address new threats and vulnerabilities.
12.6.3: Personnel receive security awareness training upon hire and at least once every 12 months, multiple methods of communication are used, and personnel acknowledge at least once every 12 months that they have read and understood the security policy and procedures.
12.6.3.1: Training includes awareness of threats and vulnerabilities that could impact the security of the cardholder data environment, including phishing and related attacks and social engineering.
12.6.3.2: Training includes awareness of acceptable use of end-user technologies, in line with Requirement 12.2.1.
Requirements 12.6.2, 12.6.3.1 and 12.6.3.2 were future-dated in v4.0 and became mandatory on March 31, 2025.
Read 12.6.3.1 carefully. It requires that training cover phishing and social engineering; it does not require a simulated campaign. Simulations are still useful evidence for 12.6.3.1 and the "multiple methods of communication" in 12.6.3, and they feed the annual review in 12.6.2. Keep that review record: date, reviewer, and what changed.
Financial Services: NYDFS Part 500, GLBA Safeguards Rule, and DORA
NYDFS 23 NYCRR 500.14(a)(3)
The November 2023 amendment to the NYDFS Cybersecurity Regulation requires covered entities to "provide periodic, but at a minimum annual, cybersecurity awareness training that includes social engineering for all personnel that is updated to reflect risks identified by the covered entity in its risk assessment." The requirement phased in during 2024 under the amendment's transitional dates.
Three details matter for examiners: training is at least annual, it covers social engineering, and its topics visibly track the risk assessment. NYDFS's October 16, 2024 industry letter on AI-related cybersecurity risks describes AI-enabled social engineering, including deepfake audio, video and text, and lists training among the mitigations. It adds no new rule, but it signals what examiners expect content to cover. Have evidence ready before your annual compliance certification.
GLBA Safeguards Rule, 16 CFR 314.4(e)
The FTC's Safeguards Rule applies to non-bank financial institutions such as mortgage brokers, auto dealers that finance, tax preparers and fintech lenders. Section 314.4(e)(1) requires "security awareness training that is updated as necessary to reflect risks identified by the risk assessment." Section 314.4(e)(3) adds security updates and training for information security personnel. There is no stated frequency and no simulation requirement. The testable element is the link to the written risk assessment, and the Qualified Individual's annual board report under 314.4(i) is a natural place to report results.
DORA Article 13(6)
The EU Digital Operational Resilience Act has applied since January 17, 2025. Article 13(6) states that financial entities "shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes." They apply to all employees and senior management, scaled to role, and to ICT third-party providers where appropriate. Article 5(2)(g) makes the management body responsible for the budget. DORA states no frequency and does not name phishing simulation.
FFIEC and SEC, briefly
US banks and credit unions should also expect examiners to use the FFIEC IT Examination Handbook, whose Information Security booklet covers training under section II.C.7(e). For public companies, the SEC's cybersecurity disclosure rules (Regulation S-K Item 106) require describing cybersecurity risk management processes. They do not mandate training; keep any description of your awareness program consistent with your evidence.
For a deeper look at running social engineering tests in regulated environments, see our multi-channel phishing simulation platform guide.
NIS2 Training Requirements
NIS2 creates two separate training duties. Article 20(2) requires members of management bodies of essential and important entities to follow training, and encourages entities to offer similar training to employees on a regular basis, so they can identify risks and assess cybersecurity risk-management practices. Article 21(2)(g) lists "basic cyber hygiene practices and cybersecurity training" among the minimum risk-management measures for the whole organization.
NIS2 is a directive, so the binding obligation is your member state's transposing law. For certain digital providers (DNS, cloud, data centers, managed services and others), Implementing Regulation (EU) 2024/2690 Annex section 8 adds awareness and role-specific training requirements. Neither text mandates phishing simulation. Keep board and workforce training records separately.
How to Satisfy Cyber Insurance Requirements for Security Training
Cyber insurance is often stricter in practice than regulators, because underwriters price coverage from your application answers.
Marsh lists "cybersecurity awareness training and phishing testing" as one of 12 key controls that insurers focus on, and states that adoption of certain controls has become a minimum requirement for insurability. Marsh McLennan's Cyber Risk Intelligence Center found in its August 2025 report that cybersecurity awareness training and phishing testing ranked fourth among the controls it studied for reducing the probability of a breach-based claim, behind network hardening, EDR, and logging and monitoring.
Carriers reinforce this by offering training and simulation to policyholders. At-Bay includes security awareness training and phishing testing with its policies for up to 1,000 employees. Coalition sells a security awareness training add-on with phishing simulations inside its Coalition Control platform. Chubb has offered policyholders a discounted Cofense phishing assessment that runs two simulated phishing scenarios over four months.
Application wording varies by carrier and changes at renewal. Have a documented answer for each of these:
Do you train all employees? Show full workforce coverage, including contractors with system access.
How often? State the cadence your policy actually sets.
Do you run phishing simulations, and how often? Have campaign dates for the policy period ready.
What are the results? Share click rate, report rate and trend.
What happens when someone fails? Describe follow-up training and how repeat failures are handled.
Do you test beyond email? Vishing and smishing results strengthen the answer for help desk and finance teams.
Answer only what you can evidence, since misstatements can surface at claim time, and pull your evidence pack well before renewal so your broker has numbers to work with.
The Evidence Pack: What to Keep for Auditors
Build one evidence pack and map it to every framework. Most artifacts serve several audits.
Artifact | Why it matters | Frameworks it supports |
|---|---|---|
Written training policy and program plan (scope, roles, cadence, owners) | Defines the control auditors test against | SOC 2, ISO 27001, HIPAA, PCI DSS 12.6.1, NYDFS, GLBA, DORA, NIS2 |
Personnel population list with hire dates and roles | Lets auditors sample and confirm full coverage | SOC 2, ISO 27001, PCI DSS 12.6.3, NYDFS |
Timestamped completion records per person | Core proof that training happened in the period | All frameworks, cyber insurance |
New-hire completion within the stated window | Commonly sampled; frequent source of SOC 2 exceptions | SOC 2, PCI DSS 12.6.3 |
Signed annual policy acknowledgments | Explicitly required by PCI DSS; supports awareness clauses | PCI DSS 12.6.3, ISO 27001 Clause 7.3, SOC 2 CC2.2 |
Course content or syllabus showing phishing and social engineering topics | Proves required topics were covered | PCI DSS 12.6.3.1, NYDFS 500.14(a)(3), HIPAA |
Annual program review record mapped to the risk assessment | Shows the program changes with the threat | PCI DSS 12.6.2, NYDFS, GLBA 314.4(e)(1), ISO 27001 |
Phishing simulation results by campaign (date, channel, click, report, time to report) | Measures effectiveness and supports insurer questions | ISO 27001 Clause 7.2, SOC 2 CC2.2, cyber insurance |
Remediation records for people who failed simulations | Shows the program acts on results | ISO 27001, SOC 2, NYDFS, cyber insurance |
Role-based training records for high-risk roles and executives | Required or expected for management and privileged roles | DORA Art. 13(6), NIS2 Art. 20(2), ISO 27001 A.6.3 |
Board or management reporting on program results | Shows governance oversight | GLBA 314.4(i), DORA Art. 5(2)(g), NIS2 Art. 20, ISO 27001 Clause 9.3 |
Retention schedule for all of the above | HIPAA requires six years for required documentation | HIPAA 164.316(b)(2), all others by policy |
Store evidence so it exports per audit period without manual stitching of HR and training data.
How to Move From Compliance-Based Training to Behavior Change
Compliance-based training asks whether everyone completed the course. Behavior change asks whether people spot, resist and report attacks, and whether the highest-access people improve fastest. The frameworks already lean this way: ISO 27001 asks for effectiveness, PCI DSS and NYDFS tie training to current threats, and insurers ask for simulation results.
Metrics beyond completion
Metric | What it tells you | Why it beats completion rate |
|---|---|---|
Report rate | Share of employees who report a simulated attack | Measures the behavior that helps the SOC during a real campaign |
Time to report | Minutes from delivery to first report | Fast early reports shrink the window an attacker has to work in |
Click or interaction rate | Share who clicked, replied, scanned or followed instructions | Direct measure of susceptibility, tracked over time |
Repeat clickers | People who fail multiple simulations | Identifies a small group that carries outsized risk |
Role-based risk | Risk weighted by access and attacker interest | A finance approver failing a wire-fraud lure matters more than an average click |
Channel coverage | Results across email, SMS, voice, chat and QR | Attackers move off email when email defenses improve |
How to make the shift
Baseline first. Measure across email, SMS and voice before changing anything. A human risk baseline runs alongside your current program.
Make report rate the headline metric. Click rate alone rewards people who ignore everything.
Score risk by role. Weight results for payments, help desk, IT admins and executives.
Train in the moment. Keep the annual course for compliance and add short modules right after a failed simulation.
Act on persistent risk. For repeat clickers in sensitive roles, add step-up authentication or temporary access restrictions.
Report outcomes to the board. Trend lines for report rate and high-risk roles double as governance evidence for GLBA, DORA and NIS2.
Why simulation data is stronger evidence
Completion records prove attendance. Simulation records show behavior under realistic conditions, with timestamps, and they show what the organization did with the result. One dataset maps to ISO 27001's effectiveness requirement, supports SOC 2's communication criteria, shows PCI DSS and NYDFS reviewers that phishing and social engineering were addressed, and answers the insurer's results question.
Platforms That Help Produce Compliance Evidence
Most platforms export completion data. The differences are in effectiveness evidence: channel coverage, report-rate tracking, role-based risk and audit-ready exports. Vendors are described from public pages as of October 2026.
Cimento
Cimento is an AI-native human risk management platform. It runs adaptive phishing simulations across email, SMS, voice, AI voice and deepfake video, QR phishing, callback phishing, and in-chat Microsoft Teams and Slack simulations, then scores each employee and role with living risk scores. It triages reported emails with SOAR integration, delivers 60 to 90 second modules in Slack or Teams, and can auto-restrict access for high-risk users through Okta, Azure AD or Google Workspace. Cimento's product page lists audit-ready exports supporting SOC 2, ISO 27001 and HIPAA, and Cimento is itself SOC 2 and ISO 27001 certified. AI agent security testing is generally available. Publicly named customers include Together AI and Exa.
KnowBe4
KnowBe4 offers Compliance Plus, a compliance training library with content for requirements such as HIPAA, PCI and GDPR, plus tracking and reporting for automated compliance campaigns. Compliance automation platforms such as Drata document integrations that pull KnowBe4 training completion data in as audit evidence. Per-employee risk scoring across non-email channels: Not confirmed.
Proofpoint ZenGuide
Proofpoint ZenGuide combines awareness training, simulations and a Report Suspicious button across email and mobile. Its public page describes threat-informed risk scoring that combines threat exposure, vulnerabilities and phishing performance, and dashboards that track behavior change over time and benchmark against industry peers. Framework-mapped audit exports: Not confirmed.
Hoxhunt
Hoxhunt runs adaptive, gamified simulations and training, and its public material emphasizes report and detection rates as core metrics, with an administrator dashboard for reporting. Hoxhunt states it is SOC 2 Type II, GDPR and CCPA compliant. Framework-mapped audit exports: Not confirmed.
SoSafe
SoSafe positions its platform around NIS2, DORA and ISO 27001, with board-ready risk data, a Human Security Index for benchmarking, and one-click exports mapped to compliance requirements. It is EU hosted, lists ISO 27001 and TISAX certifications, and offers anonymized reporting controls for privacy.
Adaptive Security
Adaptive Security offers simulations across email, voice, SMS, deepfake and chat, plus compliance and policy training. Its public page describes per-employee and per-department risk scores that update from simulation outcomes, training completion and reported phish, and displays SOC 2, HIPAA, GDPR and AI Act badges. Framework-mapped audit exports: Not confirmed.
Living Security
Living Security focuses on human risk quantification through its Human Risk Index and Unify platform, which correlates behavior, identity and threat signals. Its public material emphasizes business-aligned metrics for leadership and risk-based training. Framework-mapped audit exports: Not confirmed.
"Not confirmed" means we could not verify the capability in the vendor's public documentation as of October 2026. It may exist; confirm with the vendor.
The Bottom Line
Every framework here requires security awareness training, PCI DSS and NYDFS require it at least annually with phishing or social engineering content, and none explicitly mandates phishing simulation. Simulations remain a practical way to meet ISO 27001's effectiveness requirement, answer insurance applications, and show that training changed behavior. Build one evidence pack, map it to every framework you answer to, and make report rate and role-based risk the numbers you bring to the board. To see where your program stands across email, SMS, voice and AI impersonation, with a compliance readiness view for SOC 2, ISO 27001, HIPAA, PCI and insurance, run a Human Risk Baseline.
FAQs: Security Awareness Training Compliance Requirements
Does ISO 27001 require employee phishing testing?
No. ISO/IEC 27001:2022 does not explicitly require phishing simulation. Annex A 6.3 requires awareness, education and training, and Clause 7.2 requires evaluating the effectiveness of competence actions. Phishing simulation results are a common way organizations show that effectiveness to certification auditors.
What security awareness training is required for SOC 2 compliance?
SOC 2 requires security awareness training through Trust Services Criteria CC1.4 (commitment to competence) and CC2.2 (internal communication), including a CC2.2 point of focus on communicating security awareness through a training program. SOC 2 sets no frequency or curriculum, so auditors test against your written policy. A common approach is training at hire and annually, with timestamped completion records and policy acknowledgments.
How do you satisfy cyber insurance requirements for security training?
Run documented training for all employees, run phishing simulations on a regular cadence, and keep results such as click rate, report rate and remediation records. Marsh lists awareness training and phishing testing among the 12 key controls insurers focus on. Answer application questions only with what you can evidence, and pull your numbers before renewal.
Does PCI DSS 4.0 require phishing simulations?
No. PCI DSS v4.0 Requirement 12.6.3.1 requires that security awareness training cover phishing and related attacks and social engineering, and Requirement 12.6.3 requires training upon hire and at least every 12 months. Simulations are useful supporting evidence, but training content that covers phishing satisfies the requirement's wording.
What does HIPAA require for security awareness training?
HIPAA requires a security awareness and training program for all workforce members, including management, under 45 CFR 164.308(a)(5). Its four implementation specifications, covering security reminders, malicious software, log-in monitoring and password management, are addressable. HIPAA sets no frequency, and required documentation must be kept for six years.
What does NYDFS Part 500 require for security awareness training?
23 NYCRR 500.14(a)(3) requires periodic, at minimum annual, cybersecurity awareness training that includes social engineering for all personnel. The training must be updated to reflect risks identified in the covered entity's risk assessment. NYDFS has also issued guidance describing AI-enabled social engineering such as deepfakes.
Do DORA and NIS2 require security awareness training?
Yes. DORA Article 13(6) requires financial entities to include ICT security awareness programs and digital operational resilience training as compulsory modules for all employees and senior management. NIS2 Article 20(2) requires management body training, and Article 21(2)(g) requires basic cyber hygiene practices and cybersecurity training. Neither names phishing simulation as mandatory.
How do you move from compliance-based training to behavior change?
Start with a multi-channel baseline, then make report rate, time to report, repeat clickers and role-based risk your headline metrics. Deliver short training right after a failed simulation and add controls for persistent high-risk users. Report trends to the board, which also serves as governance evidence for several frameworks.




