SOC2Prep

Security awareness training records for SOC 2

Training is a small control with an unforgiving population: it applies to every single person, so one missing record is a visible hole rather than a rounding error.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Security awareness training evidence is a per-person completion record with a name, a completion date, and an identifiable course, tested against a population of everyone who was employed or engaged during the observation window. Auditors sample individuals and check two dates: completion against hire date for new joiners, and completion against your stated annual cycle for everyone else.

100 percent The only completion rate that produces no exception

What does the auditor actually sample?

They ask for the completion report covering the whole window, then reconcile it against your employee and contractor roster. Anyone on the roster and not on the report is a question. From the reconciled list they select individuals and ask for the underlying record for each. An aggregate percentage from a dashboard is never enough on its own.

Training obligations by audience and what evidences each
AudienceWhat your policy usually requiresEvidenceTiming tested
New employeeSecurity awareness during onboardingCompletion record with dateWithin your stated days of start date
All staff, annuallyRefresh on the anniversary or a fixed cycleCompletion report for the cycleInside the observation window
EngineersSecure development training, if your policy names itCourse record or attendance listAt the cadence your policy states
Contractors with accessThe same awareness training as staffCompletion record, or a signed attestationBefore access is granted
Privileged administratorsAdditional role-based content, where committedCourse record naming the personAnnually
Everyone, on policyAcknowledgement of the security policy setTimestamped acknowledgement per personAt hire and annually

Only put rows in your policy that you will run. A downloaded policy that promises quarterly phishing simulations and role-based training for four separate job families has committed you to four controls you did not know you had, and the auditor will test every one of them.

What do you do about contractors?

Contractors with access to systems in scope are in the population. This is the single most common gap in training evidence and it has the same root cause as the gap in access reviews: contractors are not in the HR system, so they are absent from the list that generated the training report.

  1. Build the training population from your identity provider, not from payroll. If someone has an account, they need training.
  2. Decide per contractor type whether they take your course or attest to their employer's equivalent. Both are defensible. Silence is not.
  3. Where you accept an employer's training, get something in writing naming the person and the date, and file it in the same place as everything else.
  4. Make training a gate in the access request rather than a task afterwards, so the record exists before the account does.
  5. Include contractors in the annual cycle, not only at engagement, if the engagement runs longer than a year.

An agency developer with production access and no training record is the finding that makes an auditor widen the sample. The joiner and leaver evidence page covers building that one roster properly.

The person who never completed it

Every company has one. A founder, a sales lead who was travelling, an engineer who ignored eleven reminders. You have three honest options and one dishonest one.

  1. Get it done now and record the real completion date, even though it is late. A late record inside the window is an exception on timing. A missing record is an exception on existence, and timing is the smaller of the two.
  2. If the person has left, record that they left and when, and show they had training in a prior cycle if they did.
  3. If the person has no access to anything in scope, document the scoping decision in writing before fieldwork rather than as an answer to the auditor's question. Retroactive scope arguments do not travel well.
  4. Do not create a completion record with a date the person did not complete anything on. The learning platform stamps its own timestamps and the mismatch is visible.

Completion rate is a control metric, not a report card

Track completion monthly and put the number in front of whoever runs the company. Auditors respond well to a company that knew it was at 92 percent in August, chased it, and reached full completion in September, because that is a monitoring control operating. They respond badly to a company that discovered the gap when the request list arrived.

Why does training evidence get bounced?

  • An aggregate percentage with no names. A dashboard saying 96 percent complete cannot be sampled, and the missing 4 percent is what the auditor wants to see.
  • A completion export with no course identified. A list of names and ticks does not show what anyone was trained on.
  • Completion dates outside the window. Training from fourteen months ago does not evidence an annual control operating during a twelve month window that started later.
  • The roster excludes contractors. Same failure as access reviews, same consequence for how much the auditor trusts your other populations.
  • A calendar invite as evidence of a session. An invitation shows a meeting was scheduled. For live training, evidence is an attendance list with the date and the material presented.
  • Policy acknowledgement conflated with training. These are usually two separate controls in the request list, and one record cannot answer both unless your policy explicitly defines them as one thing.

Getting the training file audit-ready

0 of 7 done ·

The rules on exports beating screenshots are on the evidence collection page. The evidence tracker gives training its own row with a cadence and an owner, which is usually the difference between a control that runs and one that is remembered in month ten.

Get training records that cover everyone, all period

Training evidence fails on the person who joined in month four. Tell us your scope and compare firms that set the cadence up properly.

Get matched

Common questions

Do we need to buy a training platform for SOC 2?

No. A recorded session with a slide deck, an attendance list and a short quiz is acceptable evidence for a company under about thirty people. A platform buys you automatic reminders and a clean export, which is worth money once chasing people becomes somebody's monthly job.

Does the founder have to do the training too?

Yes, and auditors check specifically. Executives are in the population like everyone else, and an incomplete record at the top of the company reads badly in a report about a control environment.

Are phishing simulations required?

Not by SOC 2. They are required by your policy if your policy says so, which is why a template promising quarterly simulations is worth editing before you adopt it. If you do run them, evidence is the campaign report with dates, and the follow-up for people who clicked.

Someone joined two weeks before the window closed. Do they need training?

They need it inside whatever deadline your policy gives new joiners. If your policy allows thirty days and they joined two weeks before the window ended, completion after the window can still be fine, because the obligation had not yet come due. Show the auditor the joiner date and the policy deadline together.

Can training and policy acknowledgement be one record?

Only if your policy defines them as one activity, and it is usually cleaner to keep them apart. Auditors often test policy acknowledgement under a different criterion than awareness training, and a single combined record forces you to explain the same document twice.