Security Awareness Training Requirements

How often to train, how often to phish, and what the frameworks actually demand, without the compliance fog.

How often should security awareness training be conducted?

At least annually for compliance, quarterly for genuine behaviour change, plus a baseline module for every new starter within their first two weeks. The strongest programmes run short modules continuously rather than one long annual session.

The gap between those cadences is the gap between passing audits and changing outcomes. Annual training exists because frameworks wrote it down decades ago; memory research and phishing results both show the effect decaying within weeks. Quarterly micro-modules (ten minutes, one topic) hold attention without burning goodwill, and they map cleanly onto the rotating topic lists in our topics and templates pack. The full programme logic lives in the complete guide.

How often should you run phishing tests?

Quarterly as the baseline, monthly for high-risk teams such as finance and executives, and always unannounced. Less than quarterly and staff never build the reflex; more than monthly and simulations become background noise people resent.

Cadence matters less than consistency and follow-through: a simulation without instant coaching for clickers is a statistic, not training. Rotate template styles so the lesson is scrutiny rather than pattern-matching, and read the trend across campaigns rather than any single result. The mechanics, template choices and metrics are covered step by step in the phishing simulation guide, and a first unannounced campaign via the free phishing test gives you the honest baseline to measure everything else against.

Is security awareness training mandatory?

For many organisations, effectively yes: payment card handling, health data, government supply chains and a growing share of cyber insurance policies all carry training expectations. Even where no law names it, contracts and insurers increasingly do.

FrameworkWhat it expectsCadence signal
PCI DSSFormal awareness programme for anyone handling card dataOn hire + at least annually
ISO 27001Personnel aware of the policy and their security responsibilitiesOngoing, evidence required
SOC 2Training as a control supporting the trust criteriaTypically annual + onboarding
HIPAASecurity awareness programme for all workforce membersPeriodic, plus reminders
ACSC guidance (AU)Ongoing awareness alongside the Essential Eight controlsOngoing, tailored to role
Cyber insuranceProposal forms increasingly ask for training and phishing testingEvidence at renewal

Primary sources if you need chapter and verse: the PCI Security Standards Council and the ACSC publish theirs openly; ISO sells its text but the awareness clause summary above is faithful. Our standards page maps how train2secure covers each, and insurance-grade evidence handles the renewal-form conversation.

What must training include to satisfy auditors?

Three things: relevant content (phishing, data handling, reporting at minimum), records proving who completed what and when, and a written policy showing the cadence is deliberate rather than accidental. Content without records fails audits; records without a policy fails diligence.

The policy is the piece most small companies are missing, and it takes ten minutes with a decent starting point: our free policy template covers purpose, scope, cadence, phishing simulation rules and evidence retention in two pages of plain English. Pair it with platform-generated completion exports and the audit conversation becomes a five-minute email.

Common questions

Is annual security awareness training enough?

It satisfies the letter of most frameworks and the behaviour of almost nobody. Annual training fades within weeks; short quarterly modules with phishing simulations between them keep the reflex alive. Treat annual as the compliance floor, not the target.

Do new employees need training immediately?

Within the first couple of weeks, yes. New starters are prime phishing targets because they do not yet know what normal internal email looks like, and most frameworks expect security training during onboarding. Auto-assigning a baseline module at account creation solves it permanently.

Who has to take security awareness training?

Everyone with access to systems or data: employees, contractors, part-timers and executives. Leadership exemptions are the classic mistake, since executives are the most impersonated and most targeted people in the building.

What evidence do auditors and insurers actually want?

Completion records with dates and names, certificates, phishing simulation results over time, and a policy showing the cadence is deliberate. Screenshots assembled the week before an audit convince nobody; platform-generated exports do.

Can the cadence be automated?

Fully. A platform should auto-assign onboarding training, schedule refreshers, chase stragglers with reminders, run phishing campaigns on a calendar and export the evidence. train2secure does all five, which turns this whole page into configuration rather than a project.

Set the cadence once and let it run: see plans or grab the free policy template.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress