July 27, 2026

Do SOC 2, ISO 27001, and Cyber Insurance Require Security Awareness Training?

Do SOC 2, ISO 27001, or cyber insurance require security awareness training? See what each one expects and how to prove your phishing tests work.

Share

COMPLIANCE

Do SOC 2, ISO 27001, and Cyber Insurance Require Security Awareness Training?

Short answer: effectively, yes. Here is what each framework expects — and how to satisfy it without slowing your audit down.

If you are pursuing SOC 2, certifying to ISO 27001, or renewing a cyber-insurance policy, you have probably run into the same requirement worded three different ways: your people must be trained to recognize and resist attacks. That means security awareness training — and increasingly, hands-on phishing awareness training — is no longer optional. This article breaks down what each framework actually asks for and how to prove it.

Why the human element drives the requirement

Auditors and insurers focus on training because attackers focus on people. Verizon’s 2025 Data Breach Investigations Report found that roughly 60% of breaches involve a human element and that phishing is the initial access vector in 16% of breaches. IBM’s 2025 report puts the global average breach cost at $4.44 million, rising to $10.22 million in the United States. Frameworks respond to that reality by treating human risk as a control you must manage and evidence.

SOC 2

SOC 2 is built on the Trust Services Criteria. Its common criteria expect organizations to communicate security responsibilities to personnel and to maintain a security-aware workforce. In practice, auditors look for evidence that employees receive regular security awareness training and that you can show completion records. Running periodic simulated phishing campaigns is a widely accepted way to demonstrate that the training is real and measured, not a once-a-year slideshow.

ISO 27001

ISO/IEC 27001 is more explicit. Its Annex A includes a dedicated control requiring that personnel receive appropriate awareness education and training, and regular updates on organizational policies relevant to their role. Certification auditors expect a documented, recurring program — and evidence it is working. Ongoing employee phishing training with tracked results is a natural fit, because it produces exactly the records an ISO auditor wants to see.

Cyber insurance

Cyber-insurance underwriting has tightened sharply. Insurers now commonly ask, on the application itself, whether you run security awareness training and phishing tests for employees — and your answers affect both eligibility and premium. Some carriers require evidence of a program before they will bind or renew a policy. Being able to show a history of phishing test for employees campaigns and a declining click rate is one of the clearest signals to an underwriter that your human risk is under control.

PCI DSS and HIPAA, briefly

If you handle payment cards, PCI DSS requires a formal security awareness program for all staff. If you handle protected health information, HIPAA requires a security awareness and training program as an administrative safeguard. Both reinforce the same theme: training is a baseline expectation across the major regimes, not a differentiator.

How to satisfy the requirement in practice

Across every framework, auditors and insurers want the same four things. A good program produces them automatically:

  • A recurring schedule of training and anti-phishing training — not a single annual event.

  • Coverage records showing who was trained and tested, and when.

  • Measured results — click, submit, and report rates from real phishing simulation campaigns.

  • Evidence of improvement over time, plus an audit trail of authorized activity.

How Sinon helps

Sinon is a phishing simulation tool built to generate exactly this evidence. Each campaign produces an exportable, executive-ready report — risk score, gaps by department, and prioritized recommendations — while an authorization audit trail records every simulation. That turns a compliance obligation into a repeatable, defensible program you can hand straight to an auditor or attach to an insurance application.

Preparing for an audit or a renewal? Start free at sinonsecurity.com and generate your first board-ready report in minutes.


Put this into practice

Run an AI-built phishing simulation for your team in minutes and get a board-ready report.

Start free