ComplianceExplainer3 min readUpdated September 2026

What SOC 2 Auditors Expect From Security Awareness Training

SOC 2 doesn't prescribe a specific course, but auditors expect proof that every in-scope employee and contractor has been trained on security responsibilities when they join and on a recurring schedule you define. Keep dated completion records, and make sure the content matches your own policies.

The common failures aren't about content. They're missing records, late completion by new hires and training that doesn't mention the rules your policies actually set.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What is the auditor really checking?

The audit tests whether your company informs people of their security duties and confirms they understood them. In practice an auditor will sample employees and ask for:

  • Evidence the person completed training, with a date.
  • Evidence that new hires completed it within the timeframe your policy states.
  • The training content, to see that it covers the topics your policies require.
  • Signed policy acknowledgments.
  • Evidence for contractors who have access to in-scope systems.

The key phrase is 'your policy states'. If you write that new hires finish training within thirty days, the auditor will test thirty days. Write timeframes you can meet, then meet them.

What should the training cover?

Base the content on your risks and rules, not on a generic slide deck:

  1. Company security policies. Acceptable use, password and multi-factor rules, and where to find each policy.
  2. Phishing and social engineering. How to spot and report a suspicious message.
  3. Handling customer data. What can be copied, where it may be stored and how to share it.
  4. Device security. Encryption, screen locks, updates and lost-device reporting.
  5. Incident reporting. Who to contact and how fast, with a clear channel.
  6. Remote and travel practices. Public networks, shared spaces and personal devices.

Add role-specific modules where risk is higher. Engineers benefit from secure coding and secrets handling, support staff from verifying identity before account changes, and finance from payment fraud patterns.

How do you run it and keep the evidence?

Set up a simple cycle:

  • Onboarding. Assign training in the first days and set a due date that matches your policy.
  • Annual refresh. Everyone repeats it on a fixed schedule, with reminders sent before the due date.
  • Completion tracking. Keep a report showing person, module, completion date and pass status.
  • Exceptions. Record any late completion with a reason and follow-up date.
  • Acknowledgments. Collect signed or logged acceptance of the main policies.

A compliance platform such as Vanta or Drata can help you assign training and keep completion records for the auditor, which helps avoid missed-training exceptions. Confirm in a demo how it handles contractors. If you track manually, use one spreadsheet with hire date, completion date and due date, and review it monthly. The SOC 2 readiness checklist puts training in the context of the other controls.

Do phishing simulations and quizzes help?

They can, but they aren't a requirement. Short quizzes give you a pass record and tell you where understanding is weak. Simulated phishing shows how staff behave in practice, so use it to improve training, not to shame people. Track the report rate as much as the click rate, since staff who report suspicious mail are your early warning system.

If you use simulations, tell employees they exist, set a policy for follow-up and don't tie results to discipline for a single failure. Repeated failures call for extra coaching. Customer security reviews and cyber insurance applications also ask about training, so see the cyber insurance security requirements checklist for what those forms tend to ask.

What are the most common audit exceptions?

These come up again and again:

  • A new hire finished training late with no documented reason.
  • No record for a contractor who had system access.
  • Content out of date, mentioning tools or rules you no longer use.
  • No annual refresh for someone who joined the year before.
  • Training completion tracked in email or chat, so it's hard to prove.

Fix them by making training part of onboarding checklists and access provisioning: no completed training, no production access. Then review the report monthly. Since exceptions are visible in the final report, the small effort here is worth it. To plan the wider audit, see how long SOC 2 takes and what an audit costs.

Executive Capability Standard

What Good Looks Like

Every employee and contractor with in-scope access has dated completion evidence that meets the timeframe written in your policy.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read your policies and list the rules every employee must know, then compare that list with your current training content.
2. Do Manually:Track hire date, due date and completion date in a spreadsheet, and review it every month for anyone overdue.
3. Delegate:Assign a people-operations or IT owner to run onboarding training and chase overdue completions.
4. Automate:Tie training to access provisioning so accounts aren't granted until training is complete, and send automatic reminders.
5. Buy:Adopt a training or compliance platform that assigns courses, records completions and exports evidence for the auditor.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Vanta

Fits when you want training completion records kept alongside the rest of your SOC 2 evidence.

Visit Vanta→
Drata

Fits when you want completion reports available for the auditor; check how it handles contractors.

Visit Drata→

Frequently Asked Questions

Is security awareness training required for SOC 2?

Auditors expect evidence that staff are made aware of their security responsibilities, and training is the usual way to show it. The criteria don't name a specific course or length, so design training around your policies and keep dated completion records.

How often should employees complete security training?

At hire and at least once a year is common, but your own policy sets the standard the auditor tests. Write a schedule you can keep, and set reminders. Add extra sessions after incidents or major policy changes.

Do contractors need security awareness training?

Yes, if they have access to in-scope systems or data. Auditors sample contractors along with employees. Include them in the same assignment and tracking process, and make training a condition of getting access.

Can we build our own training instead of buying a course?

Yes, as long as it covers your policies and risks and you can prove completion. Many small teams use a short internal deck plus a quiz. Purchased courses save time and maintenance, but the content must still match your actual rules.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides