SOC 2 Control Implementation Guide

Workforce Security

Security and Privacy Awareness Training for SOC 2

Personnel and contractors complete security and privacy awareness training during onboarding and at least annually thereafter.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Employees and covered contractors learn the security and privacy behaviors expected of them during onboarding and at least annually, with overdue training actively followed through to completion.

First SOC 2 program

A credible starting point

Use a short, credible course that covers phishing and credential safety, incident reporting, acceptable use, customer-data handling, and privacy responsibilities. Enroll each new starter promptly, repeat the course annually, and track completion in one place.

As the company scales

Make it repeatable

Integrate the learning platform with the HR population, assign role-specific modules for privileged, engineering, support, and privacy roles, and use escalation rules and reconciliations to prevent people from falling between systems.

How to implement Security and Privacy Awareness Training

  1. 1

    Define the learner population

    Identify employees and contractors who need training, including people without a standard corporate email account, and define onboarding and annual due dates.

    You should end up with: A scoped learner list with assignment rules and due dates.

  2. 2

    Approve relevant course content

    Review the course against the company’s real reporting channels, data-handling practices, major threats, and privacy commitments.

    You should end up with: A dated course version and content approval record.

  3. 3

    Assign onboarding training

    Enroll each new employee or covered contractor and communicate the deadline and consequences for non-completion.

    You should end up with: Assignment records tied to each new starter and course version.

  4. 4

    Run the annual campaign

    Reassign the current course to the full in-scope population and send escalating reminders to learners and managers.

    You should end up with: Annual campaign records, reminder history, and completion report.

  5. 5

    Resolve overdue assignments

    Investigate overdue learners, correct population or leave-status errors, and document manager escalation until each assignment is completed or formally exempted.

    You should end up with: An overdue tracker with resolution notes and approvals.

  6. 6

    Reconcile learners to HR

    Compare active personnel and in-scope contractors with training assignments and completions, then resolve missing or duplicate records.

    You should end up with: A dated population reconciliation and final completion summary.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

Training completion reports

  • Confirm what the record proves

    Shows which in-scope people completed the assigned onboarding or annual course, which version they took, and whether they met the applicable due date.

  • Include this context

    learner identifier

  • Include this context

    employment or contractor status

  • Include this context

    course and version

  • Include this context

    assignment date and due date

  • Include this context

    completion date and result

Weak evidence to avoid

A dashboard showing 100% complete without learner names, course version, due dates, exclusions, or export date.

onboarding checklist

  • Confirm what the record proves

    Shows that awareness training was assigned and tracked as part of a named starter’s onboarding rather than waiting for the next annual campaign.

  • Include this context

    starter identifier

  • Include this context

    start date

  • Include this context

    training assignment

  • Include this context

    due date

  • Include this context

    completion status

  • Include this context

    checklist owner

Weak evidence to avoid

A blank onboarding checklist or a checked training box with no learner, assignment, or completion record.

overdue training follow-up records

  • Confirm what the record proves

    Shows that late assignments were identified, escalated to accountable managers, and resolved or formally exempted rather than removed from the report.

  • Include this context

    learner and assignment

  • Include this context

    original due date

  • Include this context

    reminder or escalation dates

  • Include this context

    manager or owner

  • Include this context

    resolution and date

Weak evidence to avoid

An automated reminder email with no recipient-level follow-up, manager escalation, or final outcome.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

The active learner population, current onboarding and annual course assignments, latest course version, and all overdue or exempted assignments outstanding on the examination date.

Type 2

Evidence across the review period

Every employee and covered-contractor start during the review period, every annual awareness assignment issued to the active in-scope population, and every overdue escalation or exemption resolved during the period.

Completeness check

Reconcile active personnel and all period starts from HR and contractor rosters to learning assignments, then match completions and overdue cases back to the same stable learner identifiers; explain leave, termination, duplicates, and every unassigned or unresolved person.

Build the record set from

  • HR information system
  • contractor roster
  • learning management system
  • onboarding ticket queue
  • manager escalation records

Keep these fields for each record

  • learner identifier
  • worker type and status
  • start date
  • course and version
  • assignment and due dates
  • completion date and result
  • escalation or exemption status

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Employees and covered contractors learn the security and privacy behaviors expected of them during onboarding and at least annually, with overdue training actively followed through to completion.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (HR Owner / IT / CISO), then compare dated records with the stated cadence: Upon hire/change/termination; annual as applicable.

  • Establish the complete audit record set

    Reconcile active personnel and all period starts from HR and contractor rosters to learning assignments, then match completions and overdue cases back to the same stable learner identifiers; explain leave, termination, duplicates, and every unassigned or unresolved person.

  • Prepare the as-of-date evidence for a Type 1 engagement

    The active learner population, current onboarding and annual course assignments, latest course version, and all overdue or exempted assignments outstanding on the examination date.

  • Prepare period evidence for a Type 2 engagement

    Every employee and covered-contractor start during the review period, every annual awareness assignment issued to the active in-scope population, and every overdue escalation or exemption resolved during the period.

  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect Training completion reports

      For each selected record, confirm it demonstrates Shows which in-scope people completed the assigned onboarding or annual course, which version they took, and whether they met the applicable due date.

      • learner identifier
      • employment or contractor status
      • course and version
      • assignment date and due date
      • completion date and result
    • Inspect onboarding checklist

      For each selected record, confirm it demonstrates Shows that awareness training was assigned and tracked as part of a named starter’s onboarding rather than waiting for the next annual campaign.

      • starter identifier
      • start date
      • training assignment
      • due date
      • completion status
      • checklist owner
    • Inspect overdue training follow-up records

      For each selected record, confirm it demonstrates Shows that late assignments were identified, escalated to accountable managers, and resolved or formally exempted rather than removed from the report.

      • learner and assignment
      • original due date
      • reminder or escalation dates
      • manager or owner
      • resolution and date
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • Training is assigned annually but not during onboarding.
  • Contractors and recently acquired teams are absent from the learner population.
  • Completion percentages exclude overdue users or terminated accounts without explanation.
  • Course content names reporting channels or practices the company no longer uses.
  • Overdue reminders are sent, but nobody owns escalation and resolution.

Before you call this control ready

  • Do sampled new starters have assignments and completion dates consistent with the onboarding rule?
  • Does the annual report reconcile to the active employee and covered-contractor population?
  • Can the company show which course version each person completed?
  • Are overdue assignments supported by follow-up, resolution, or a documented exemption?
  • Does current training tell people exactly how to report a suspected security or privacy event?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC1.4
  • CC1.5
  • CC2.2
  • P8.1

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.