Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Security awareness
training that passes.

Almost every framework we work in names security awareness training directly, and PCI DSS goes as far as naming the topics it has to cover. The control is rarely failed because people were not trained. It is failed because nobody can produce dated, per-person records showing that they were.

Scope a programme

Which frameworks require security awareness training

The obligations differ in wording and in how prescriptive they are. What they share is that the evidence, not the training, is what gets sampled.

FrameworkStatusWhat it requiresEvidence expected
PCI DSS v4.012.6.1, 12.6.2, 12.6.3 Required A formal security awareness programme must exist. It must be reviewed at least once every twelve months and updated as needed to address new threats. Personnel must be trained on hire and at least once every twelve months. Programme documentation, the annual review record, and per-person completion records with dates.
PCI DSS v4.012.6.3.1 and 12.6.3.2 Required Training must specifically cover phishing and related social engineering attacks, and the acceptable use of end-user technologies. These are named as separate sub-requirements, which is why generic packages often fail to satisfy them. Content demonstrably covering both topics, not a general module that mentions them in passing.
ISO/IEC 27001:2022A.6.3 Required Personnel and relevant interested parties must receive appropriate information security awareness, education and training, plus regular updates of policies and procedures relevant to their job function. Role-relevant content, delivery records, and evidence the material tracks your actual policies.
HIPAA Security Rule45 CFR 164.308(a)(5) Required A security awareness and training programme is required for all workforce members, including management. The implementation specifications cover security reminders, protection from malicious software, log-in monitoring and password management. Training records for the whole workforce, plus evidence of ongoing reminders rather than a single annual event.
SOC 2CC1.4 and CC2.2 Expected The entity must demonstrate a commitment to attract, develop and retain competent individuals, and must internally communicate information, including objectives and responsibilities for internal control. Training records and evidence that security responsibilities were communicated to the people who hold them.
CMMC and CPCSC Level 2NIST SP 800-171 3.2.1 to 3.2.3 Required Managers, system administrators and users must be made aware of the security risks of their activities, personnel must be trained to carry out their assigned security duties, and insider threat awareness training is required specifically. Role-based records, and a distinct insider threat module rather than a line inside a general course.
GDPRArticle 39(1)(b) Conditional Where a data protection officer is appointed, awareness raising and staff training form part of the monitoring duties assigned to that role. Evidence that privacy training reaches the staff carrying out processing.

The sub-requirements are where this gets failed. PCI DSS 12.6.3.1 names phishing and social engineering, and 12.6.3.2 names acceptable use of end-user technologies, as separate obligations. A general security course that mentions phishing in one slide has not clearly satisfied either. The same applies to insider threat training under 800-171 3.2.3 for CMMC and CPCSC Level 2, which is a named requirement rather than a topic inside a broader module.

What the programme includes

Built so the evidence falls out of running it, rather than being assembled the week before an audit.

Role-based curriculum

Different content for engineers, for people handling customer data, and for everyone else. Frameworks ask for training relevant to the job function, and a single all-staff course is the most common reason this control gets a finding.

Onboarding and annual cadence

Training on hire and at least once every twelve months, tracked so the twelve months is measured per person rather than per calendar year. The per-person clock is what PCI and most auditors actually sample against.

Phishing and social engineering

Covered as its own module because PCI DSS 12.6.3.1 names it separately, with simulation where you want a measurable baseline rather than an attendance record.

Acceptable use of end-user technologies

The other named sub-requirement, tied to your actual acceptable use policy rather than a generic one, so the training and the policy do not contradict each other.

Insider threat module

Required outright for CMMC and CPCSC Level 2 under 800-171 3.2.3, and worth having regardless. Delivered as a distinct module so the evidence is unambiguous.

Secure coding for developers

Where you are heading for PCI DSS or ISO 27001, engineering needs content its own auditors will recognise. This pairs with the independent code review requirement in PCI DSS 6.2.3.

Completion records and evidence export

Per-person, dated, exportable. This is the deliverable auditors actually sample, and it is the part companies running informal training cannot produce.

Annual programme review

The documented review PCI DSS 12.6.2 requires, updating content against new threats so the programme does not quietly go stale between audits.

Where this sits in a wider programme

Training is one control in a set, and it is cheap relative to the rest. Where we are already running your SOC 2, ISO 27001 or CPCSC work, the curriculum is built against the policies we wrote, so the training and the policy set do not drift apart. That drift is the second most common finding after missing records.

Where somebody else is running your programme, this stands alone perfectly well. The same is true of our internal audit work, which we take on a ring-fenced basis for companies whose readiness was done elsewhere.

Awareness training questions, answered

Does SOC 2 require security awareness training?

SOC 2 does not name it as a standalone control the way PCI DSS does, but CC1.4 and CC2.2 require the entity to develop competent people and to communicate internal control responsibilities to them. In practice every SOC 2 auditor asks for training records, and being unable to produce them is a straightforward way to pick up an exception.

How often does security awareness training have to happen?

PCI DSS requires it on hire and at least once every twelve months, with the programme itself reviewed annually. HIPAA requires it for all workforce members with ongoing security reminders rather than a single annual event. ISO 27001 says regular updates relevant to the job function without naming an interval, so you set the interval and then have to meet the one you set. Annual plus onboarding satisfies all of them.

What does PCI DSS 12.6 actually require?

Three things. A formal awareness programme must exist and be documented (12.6.1). It must be reviewed at least every twelve months and updated for new threats (12.6.2). Personnel must be trained on hire and at least annually (12.6.3), and the content must specifically address phishing and social engineering (12.6.3.1) and acceptable use of end-user technologies (12.6.3.2). Those last two are separate named sub-requirements and generic training often does not clearly satisfy them.

Can we just buy an off-the-shelf training platform?

You can, and for some companies that is the right answer. What a platform gives you is content and completion tracking. What it does not give you is the mapping between its modules and the specific sub-requirements you are being audited against, a curriculum matched to your actual policies, or an answer when an auditor asks why your acceptable use training describes a policy you do not have. We work either way: we will build the programme on a platform you already own, or run it without one.

What evidence will an auditor ask for?

Per-person completion records with dates, the content itself, the annual programme review, and evidence that new starters were trained on hire. For CMMC and CPCSC they will look for the insider threat module specifically. For PCI they will look for phishing and acceptable use content specifically. Most findings here are evidence problems rather than training problems.

Do contractors and part-time staff need training?

Generally yes. HIPAA applies to the workforce, which includes people whose conduct you control regardless of whether you pay them as employees. PCI DSS applies to personnel with access to the cardholder data environment. ISO 27001 A.6.3 extends to relevant interested parties. Scoping training to full-time employees only is a common and easily-found gap.

Does phishing simulation count as training?

It complements training rather than replacing it. Simulation gives you a measurable click rate and identifies who needs more support, which is genuinely useful. It does not by itself evidence that people were taught the material, so auditors will still ask for the training records behind it.

We are a ten-person company. Is this overkill?

The requirement does not scale down, but the programme does. A ten-person company still needs training on hire and annually, still needs the phishing and acceptable use content if PCI applies, and still needs records. What it does not need is an enterprise learning platform. We scope it to the size of the company and the frameworks actually in play.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

What auditors actually sample

Short notes on the evidence behind common controls, including which records get requested first. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.