Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Security Training Requirement Finder

Pick the frameworks you answer to. See what each one requires for staff training, how often, and what evidence to keep, then one programme that covers them all.

Frameworks you answer to

What each framework requires

Requirement, cadence and the evidence auditors ask for.

Your combined cadence
Topics your programme must cover
    Records to keep
      Awareness training, From $200/mo CAD
      Our summary of each requirement, not the text of the standards. Requirement references are to SOC 2 (2017 Trust Services Criteria), ISO/IEC 27001:2022, HIPAA, PCI DSS v4.0.1, CAN/DGSI 104 Rev 2 (2026), Quebec's private sector Act as amended by Law 25, and PIPEDA Schedule 1.

      Questions

      Can one training programme cover several frameworks?

      Yes, and it should. Build to the strictest cadence and the union of required topics, keep one set of completion records, and map it to each framework. Auditors care that the content and the records are there, not that you ran separate courses.

      Which framework is strictest on training?

      PCI DSS is the most specific: training on hire and at least every 12 months, named topics including phishing and social engineering, a yearly policy acknowledgement, and a yearly review of the programme itself. CyberSecure Canada names its Level 1 topics, including AI-enabled impersonation.

      Do we need phishing simulations?

      None of these frameworks requires simulations by name. PCI DSS requires training content on phishing and social engineering, and CyberSecure Canada Level 2 expects regular, ongoing activity, where simulations are a common way to show it.

      What do auditors check?

      They pick a sample of people, often including recent hires, and ask for proof each one completed the training on time. A missing record for a single new joiner is enough for a SOC 2 exception.

      Is this finder free?

      Yes, free and no signup. Your choices stay in your browser.

      Not ready for a call yet?

      Get your training requirements by email

      The requirements and your combined programme to keep, then a few short notes from Jacob on training that holds up in an audit. Unsubscribe in one click. Reply anytime; it reaches him directly.

      From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

      Want it done for you?

      Security awareness training

      Training mapped to your frameworks, with the completion records auditors ask for.

      Explore Security awareness training →

      Training that counts as evidence.

      Our security awareness training is mapped to the frameworks you answer to, covers the required topics, and keeps the per-person completion records your auditor will sample. From $200/mo CAD.

      See security awareness training Book a call

      Want the full picture?

      This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

      Start your free assessment See what is in the Workspace

      No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

      Track record

      Who is actually doing the work

      5
      Published CVEs, including a CVSS 9.1
      Zero
      Exceptions on a SOC 2 Type II built from nothing in-house

      Published vulnerability research

      Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

      A SOC 2 Type II built from nothing

      At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.