Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What security training evidence should you keep?
Updated
Keep four things: the curriculum with its approval date, completion records naming every person and date, policy acknowledgements, and — where you run them — phishing-simulation results with what you did about them. Completion percentages without a named population prove little.
Security-training evidence map, last verified 10 September 2026 against ISO/IEC 27001:2022 Annex A 6.3 information security awareness, education and training, the AICPA Trust Services Criteria CC1.4 and CC2.2, PCI DSS v4.0.1 Requirement 12.6, and NIST SP 800-53 Rev. 5 AT family with NIST SP 800-50 as guidance. PCI DSS is the only source here that names a cadence, and only for entities in scope: awareness training upon hire and at least once every twelve months. Elsewhere the frequency is your own stated standard. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file with an auditor.
What this page is, and what it is not
Audience: a compliance lead, people-operations partner, or security owner who needs the people controls to be provable. Training evidence is usually easy to produce and easy to get wrong, because the artifact everyone reaches for — a completion rate — is the one an auditor can do least with.
This page is not legal advice. It does not determine YOUR obligations, does not decide which frameworks apply to your organisation, does not start a clock, and does not file anything with an auditor. Where training records identify individuals, retention and use are also employment and data-protection questions for counsel. Last verified 10 September 2026.
The core problem to solve: a completion figure is a ratio whose denominator nobody defined. An auditor's first question is who was in scope, and the second is what happened to the people who did not complete. If your artifact answers both, the control is evidenced.
- Population first. In-scope population usually means all employees and any contractors with system or data access, and the boundary needs to be written down.
- Onboarding and annual are different controls with different evidence. A joiner in November who completes the annual module in January was untrained for two months.
- Role-based training is where a maturing programme adds value: developers, administrators, and support staff face different risks, and generic awareness content evidences generic awareness.
- Phishing simulations are optional and useful. Where you run them, the evidence is the follow-up action, not the click data. Reporting raw click figures as a security outcome invites questions you do not want.
Training evidence: artifact, cadence, owner, driving requirement
This table is the checklist artifact for this page. Copy the columns, put your own names in the owner column, and record which cadence is required and which you chose. Last verified 10 September 2026. Not legal advice.
| Artifact | Cadence | Typical owner | Driving requirement |
|---|---|---|---|
| Approved awareness curriculum with content outline and version | Reviewed at least annually, and after a material change in threat or technology | Security owner, approved by the accountable executive | Certification requirement — ISO/IEC 27001:2022 Annex A 6.3 requires awareness, education and training relevant to job function. AICPA TSC CC2.2. Neither names content; the curriculum is your design. |
| In-scope population definition | Refreshed each cycle and at each cycle's start | People operations with security | Best practice, and the prerequisite for every other row. No framework names it explicitly; every auditor asks for it. |
| Completion records: person, module, version, completion date | Per person per cycle; on hire for joiners | People operations or the learning-platform owner | Legal requirement in the contractual sense where PCI DSS v4.0.1 Requirement 12.6.3 applies — upon hire and at least once every twelve months. Otherwise certification requirement under Annex A 6.3 with a cadence you set. |
| Non-completion follow-up records | Within the cycle, with escalation after a stated grace period | Line managers, tracked by people operations | Best practice, and the row auditors sample. Nothing requires a named escalation path; its absence is what turns a shortfall into a finding. |
| Policy acknowledgements | On hire, on material policy change, and at least annually | Compliance owner | Certification requirement — ISO/IEC 27001:2022 Annex A 5.1 and 6.3, and AICPA TSC CC1.1 and CC2.2. PCI DSS v4.0.1 Requirement 12.6.3 also asks for acknowledgement of understanding where in scope. |
| Role-based training for developers | At least annually, and on joining a team that writes production code | Engineering leadership with security | Certification requirement in substance — Annex A 6.3 relevance to job function and 8.28 secure coding. Legal requirement in the contractual sense under PCI DSS v4.0.1 Requirement 6.2.2 for developers of bespoke software, where in scope. |
| Role-based training for administrators and privileged users | At least annually, and on gaining privileged access | Security or IT operations | Certification requirement in substance — Annex A 6.3 and 8.2 privileged access rights. NIST SP 800-53 Rev. 5 AT-3 role-based training, as guidance. |
| Incident-response and reporting awareness | At least annually, and after a material change to the reporting path | Security owner | Certification requirement — ISO/IEC 27001:2022 Annex A 6.8 reporting information security events. AICPA TSC CC2.3. This is the training that determines whether an incident is reported in hours or days. |
| Phishing-simulation programme records and follow-up | Where run: commonly quarterly, entirely your choice | Security owner | Best practice. No source named here requires simulations. The evidence that matters is the remedial action taken, not the raw result. |
| Specialist and refresher training for the security function | Annually, or per certification maintenance requirements | Security leadership | Best practice, plus ISO/IEC 27001:2022 Clause 7.2 competence — which requires competence, not a course. |
| Programme reporting to management | At least annually, with the review itself recorded | Compliance owner | Certification requirement — ISO/IEC 27001:2022 Clause 9.3 management review. AICPA TSC CC4.2. The record of the discussion is the artifact, not the slide. |
| Training-record retention decision | Set once, reviewed annually | Compliance owner with legal | Jurisdiction-dependent legal requirement — records identify employees, so employment and data-protection law reach them. See the retention checklist in this cluster. |
Framework-required, guidance, best practice, or our recommendation
Annual security awareness training is so universal that teams assume a law requires it. For most organisations the requirement comes from a certification standard, an attestation criterion, or a customer contract. Label yours. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| PCI DSS v4.0.1 Requirement 12.6.3: personnel receive security awareness training upon hire and at least once every twelve months, with acknowledgement of understanding, covering stated topics. | Legal requirement in the contractual sense, for entities in scope through card-brand and acquirer agreements. The clearest named cadence available. | Does not set a cadence for an organisation with no cardholder data in scope, and does not prescribe a vendor or platform. |
| Sector and jurisdiction-specific training duties — for example healthcare, financial services, or public-sector regimes. | Legal requirement where the regime applies. Some name topics or frequencies directly. | Does not apply because a competitor in another sector does it. Confirm applicability with counsel rather than copying a template. |
| ISO/IEC 27001:2022 Annex A 6.3, and Clause 7.2 competence and 7.3 awareness. | Certification requirement where you seek or hold certification. It requires awareness and competence appropriate to the role; it names no frequency. | Does not mandate annual. Your topic-specific policy's number becomes the auditable standard, so write one you meet. |
| AICPA Trust Services Criteria CC1.4 on attracting and retaining competent individuals, and CC2.2 on internal communication of information security objectives and responsibilities. | Attestation criteria, applying because you sought a SOC 2 report or a contract requires one. | Does not name a module, a platform, or a cadence. |
| NIST SP 800-53 Rev. 5 AT family, with NIST SP 800-50 as guidance on building an awareness programme. | Regulatory and standards guidance, binding on US federal systems through separate authority. | Does not bind a commercial company that has not contracted to it. |
| Train on hire and at least annually, add role-based content for developers and administrators, and run phishing simulations with recorded follow-up. | Industry best practice, and what enterprise customers usually expect to see. | Not required by the criteria above except where PCI DSS or a sector regime applies. |
| Define the in-scope population in writing each cycle, and record the follow-up for every non-completion rather than reporting only a completion figure. | ShipReady Metrics recommendation. | Not required by any framework named here. It exists because the population and the non-completion follow-up are the two things auditors sample and teams most often lack. |
A sample completion-record artifact
This is the shape of a training record that answers questions instead of raising them. Rows are illustrative format examples, not real data about anyone. Last verified 10 September 2026. Not legal advice.
| Field or row | Example content | Why an auditor looks for it |
|---|---|---|
| Header — population and boundary | In-scope population for the 2026 cycle: 92 employees and 7 contractors with system access, as at 1 February 2026. Excluded: 3 contractors with no system or data access — exclusion reason recorded. | Defines the denominator, which is the question every completion figure begs. |
| Header — curriculum and version | Awareness module version 2026.1, approved by the named accountable executive on 15 January 2026. Topics listed, including incident reporting and phishing recognition. | Ties the completions to specific content, so the record evidences what people were actually taught. |
| Row — standard completion | Person identifier, role, module version, assigned date, completed date, score or pass status where the platform records one. | The core row. Named person and date, not an aggregate. |
| Row — new joiner | Person identifier, hire date, assignment date within the stated onboarding window, completion date, days from hire to completion. | Answers the on-hire requirement directly, and exposes the gap between joining and training. |
| Row — role-based module | Person identifier, role: backend engineer. Secure-coding module version, completion date. Separate from the general awareness module. | Shows relevance to job function rather than one module for everyone. |
| Row — non-completion and follow-up | Person identifier, assigned date, escalation to line manager on the stated date, outcome: completed late on a recorded date; or access restricted pending completion, with the restriction recorded. | This is the sampled row. A shortfall with recorded follow-up is a working control; a shortfall with none is the finding. |
| Row — policy acknowledgement | Person identifier, policy set version, acknowledgement date, method of capture. | Links training to the policies people are being held to. |
| Footer — cycle summary | Assigned: 99. Completed within the cycle: 96. Completed late with follow-up recorded: 3. Outstanding at cycle end: 0. | A summary that reconciles to the population, which a bare percentage does not. |
| Footer — phishing programme | Simulations run in the period: 4. Remedial actions taken: targeted follow-up module assigned to identified individuals, with completion recorded. Raw result data retained per the stated retention. | Shows the simulation produced action rather than a statistic. |
| Footer — storage and retention | Stored in the evidence repository under training; retention 3 years, subject to the employment-record retention decision recorded with legal. Next cycle opens February 2027. | Shows the artifact is retained and that the personal-data question was considered. |
Checklist
A question list for the training side of your evidence set. Not a determination that any framework applies to you. Last verified 10 September 2026. Not legal advice.
- Is the in-scope population written down for the current cycle, including contractors with access, with exclusions and their reasons?
- Is the curriculum approved, versioned, and dated, so completions tie to specific content?
- Do completion records name the person, the module version, and the date, rather than only an aggregate?
- Are joiners trained within a stated window of hire, and can we show the gap for each?
- Is there role-based content for developers, administrators, and privileged users, or one module for everyone?
- Does every non-completion have a recorded follow-up and outcome?
- Are policy acknowledgements captured on hire, on material change, and on the stated cadence?
- Does training cover how to report an incident, and does the reporting path in the material match the current one?
- If we run phishing simulations, is the recorded artifact the remedial action rather than the raw result?
- Has the retention of training records — which identify individuals — been agreed with legal?
- Was the programme reported to management in the period, with the review recorded?
What to do now
Ordered so the sampled rows become producible first. None of these steps is a legal determination, and none files anything with an auditor.
- Write the in-scope population down for this cycle, with exclusions and reasons. Everything else on this page depends on it.
- Version and date the curriculum, and get it approved by the accountable executive. Undated content makes every completion record ambiguous.
- Add a recorded follow-up step for non-completion, with an escalation after a stated grace period. This closes the most commonly sampled gap.
- Separate onboarding training from the annual cycle, and measure days from hire to completion.
- Add one role-based module for developers and one for administrators before adding more general content.
- If you run phishing simulations, record the remedial action per identified individual and stop reporting raw results as an outcome.
- Agree training-record retention with legal, since the records identify people and sit under employment and data-protection rules.
- Report the programme to management once in the period and record the discussion, which satisfies the oversight row cheaply.
- Re-verify the cited requirements annually against the primary sources below, and record the date. Ours says 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. This product does not deliver training, does not run phishing simulations, does not track completions from a learning platform, and does not file anything with an auditor.
If you already have a session: signed-in app → Compliance holds evidence collection, which records control-mapped artifacts for starter control subsets, and evidence review, where a named human accepting a manual row renders it met and rejecting it renders it a gap, with a timestamp. Training completions and acknowledgements are manual rows reviewed that way. That overlay is a timestamped compliance artifact — not a forensic chain of custody, not a downloadable evidence binder, and not an auditor's opinion.
A policies library lives under Compliance → Policies in the signed-in app, which is where policy documents and their versions sit. Acknowledgement capture and enforcement remain in your own people systems.
The obligation map lists frameworks your organisation marked in-scope. That mark is a scoping input you control, not a legal opinion that a framework applies. Readiness is an internal indicator, not certification.
Primary sources (last verified 10 September 2026)
Each source is labelled by the kind of authority it carries.
ISO/IEC 27001:2022 Annex A 5.1, 6.3, 6.8 and 8.2, and Clauses 7.2, 7.3 and 9.3, are certification requirements. AICPA Trust Services Criteria CC1.1, CC1.4, CC2.2, CC2.3 and CC4.2 are professional attestation criteria. PCI DSS v4.0.1 Requirements 6.2.2 and 12.6 bind entities in scope through card-brand and acquirer contracts, and Requirement 12.6.3 is the source of the on-hire and twelve-month cadence quoted above. NIST SP 800-53 Rev. 5 AT family and NIST SP 800-50 are guidance. Employment and data-protection law reaches records that identify individuals and varies by jurisdiction. Not a complete list, and not legal advice.
The retention checklist in this cluster covers how long to keep these records, and the audit evidence repository page covers where they should live.
Frequently asked questions
Is this legal advice?
No. It is an operational guide to training evidence, with each source labelled by the kind of authority it carries. Whether a sector regime, PCI DSS, or a customer contract imposes training duties on you is a legal and commercial question for counsel and your contracts — as is how long you may keep records that identify individuals. This page does not determine YOUR obligations.
Is annual security awareness training legally required?
For most organisations, no statute requires it. PCI DSS v4.0.1 Requirement 12.6.3 requires it on hire and at least every twelve months for entities in scope, and some sector regimes impose their own duties. ISO/IEC 27001 Annex A 6.3 and the AICPA criteria require awareness appropriate to the role without naming a frequency, which means your own stated cadence becomes the auditable standard.
Is a completion percentage enough evidence?
No, because a percentage is a ratio whose denominator nobody has seen. An auditor wants the in-scope population definition, named completions with dates and module versions, and the follow-up for everyone who did not complete. Give those three and the percentage becomes a summary of evidence rather than a substitute for it.
Do we need phishing simulations?
No source named on this page requires them. They are industry best practice and often genuinely useful. If you run them, make the evidence the remedial action taken — targeted follow-up training with recorded completion — rather than the raw result. Reporting click figures as a security outcome invites questions about population, difficulty, and what changed as a result.
Does ShipReady Metrics track training completion?
No. It does not deliver training, connect to learning platforms, or run simulations. Training completions and policy acknowledgements are handled as manual evidence rows, where a named human accepting a row renders it met and rejecting it renders it a gap, with a timestamp. A policies library exists under Compliance → Policies for policy documents and versions; acknowledgement capture stays in your people systems.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.