Clause references for security awareness training across SOC 2, ISO 27001, PCI DSS, HIPAA, CCPA, CMMC, NIST CSF, PIPEDA, Quebec Law 25 and GDPR
Most IT Directors know security awareness training is expected. Fewer can point to the clause when a board member asks why it is in the budget. Here it is, framework by framework.
| Framework | Control | What it requires |
|---|---|---|
| SOC 2 | CC2.2 | Common criteria require the organization to internally communicate information, including security responsibilities, so personnel can carry out their duties. |
| ISO/IEC 27001:2022 | Annex A 6.3 | Personnel receive appropriate information security awareness, education and training, and regular updates to organizational policy, relevant to their role. |
| PCI DSS v4.0.1 | 12.6.3 and 12.6.3.1 | A formal security awareness program delivered on hire and at least once every twelve months, reviewed annually and updated as threats change, covering phishing and related social engineering and acceptable use of end user technologies. |
| HIPAA | Sec. 164.308(a)(5) and Sec. 164.530(b)(1) | The Security Rule requires a security awareness and training program for all workforce members, including periodic security reminders and malicious software protection. The Privacy Rule requires workforce training on the policies governing protected health information. |
| CCPA and CPRA | 11 CCR 7100 | Training for all individuals responsible for handling consumer privacy inquiries and rights requests, covering the requirements of the Act and how to direct consumers to exercise their rights. Narrower in scope than the security frameworks above. |
| CMMC | AT domain | Inherits the NIST SP 800-171 Awareness and Training family, which requires role based training and insider threat awareness for personnel handling controlled unclassified information. |
| NIST CSF 2.0 | PR.AT | Personnel are provided with awareness and training so they possess the knowledge to perform their security relevant duties. |
| PIPEDA | Principle 4.1.4 | Organizations must train staff on the policies and practices protecting personal information, as part of the accountability principle. |
| Quebec Law 25 | Governance | Documented governance policies and practices for the protection of personal information, with staff made aware of them. |
| GDPR | Art. 39(1)(b) | Awareness raising and training of staff involved in processing operations, monitored by the data protection officer. |
Every one of these asks for the same two things: that training happened, and that you can prove who did it. The second is where most organizations fail the audit.
See how we run security awareness training and phishing simulation for you, with completion records mapped to these frameworks.
If this guide doesn't cover your situation, our team can walk you through it directly.