20 Security Frameworks Requiring Security Awareness Training (2026)

A complete overview of major standards and regulations that require awareness training. Identify the most common standards, regulations, and frameworks that require security awareness programs.

Post hero image

Table of contents

See Hoxhunt in action
Drastically improve your security awareness & phishing training metrics while automating the training lifecycle.
Get a Demo
Updated
September 15, 2026
Written by
Hoxhunt
Fact checked by
The short answer

20 major compliance frameworks and regulations touch security awareness training. 11 mandate it directly (including ISO 27001, HIPAA, PCI DSS, NIST SP 800-53, DORA, and SWIFT), 7 require it indirectly as part of a broader security-program obligation (including GDPR, GLBA, and COBIT), the EU AI Act mandates AI literacy training rather than security awareness training specifically, and only SCORM, a technical e-learning standard rather than a compliance framework, doesn’t apply at all. The full breakdown is below.

Many regulatory frameworks explicitly require organizations to implement security awareness training as part of their compliance obligations. Failure to comply with these training requirements can result in hefty financial penalties, fines, and legal repercussions.

Under GDPR, even less severe infringements could result in a fine of up to €10 million, or 2% of the firm’s worldwide annual revenue, depending on which number is larger.

Beyond those regulatory fines, the breach itself is usually the bigger cost, and it is increasingly what an insurer asks about too: see cyber insurance and security awareness training. According to IBM’s Cost of a Data Breach Report 2025, the average data breach now costs $4.88M. That is why the standards below treat security awareness training as a required control rather than an optional checkbox.

This guide identifies the most common standards, regulations, and frameworks that require security awareness training. Note that we do not consider this list fully comprehensive, as new standards are constantly being developed, many of them specific to certain countries or industries.

Why is security awareness training required by compliance frameworks?

Security awareness training sits at the center of nearly every major compliance framework. It protects sensitive data, meets regulatory requirements, and addresses the one vulnerability no framework can engineer around: the human factor.

The human factor in cybersecurity

The human factor is behind 62% of breaches, according to Verizon’s 2026 Data Breach Investigations Report.

Regardless of how advanced your technical filters are, employees can still make mistakes. No filter catches everything: employees still click phishing links, mishandle sensitive data, or skip a security protocol.

Incident response and preparedness

Security awareness training, done right, turns employees into a fast, confident first line of defense, because they learn how to quickly report suspicious activity and follow incident response protocols, which hugely limits the damage a breach can cause.

And that “quickly” is key here: Hoxhunt’s own data shows two-thirds of trained employees report a real threat within a year, and the fastest 5% do it in just 39 seconds (Hoxhunt Phishing Trends Report 2026).

The faster your employees can spot and contain cyber incidents, the less damage they’ll cause.

Protecting sensitive data

Compliance frameworks exist to protect sensitive information: personal details, financial records, and medical history.

Security awareness training goes deeper, as it teaches employees how to handle information properly, which cuts the risk of unauthorized access or a breach.

Keeping up with the latest threats

Cybersecurity threats landscape is constantly evolving, with new attack tactics emerging regularly.

Proper security awareness training must keep employees informed about the latest tactics, so their knowledge doesn’t go stale the moment a new threat appears.

That’s why compliance frameworks require continuous training: a one-time course isn’t enough, but regular, ongoing education is how you stay ahead of potential risks.

62%of breaches involve the human elementSource: Verizon 2026 Data Breach Investigations Report
2/3of trained employees report a real threat within their first year, the fastest 5% in just 39 secondsSource: Hoxhunt Phishing Trends Report 2026

Which compliance frameworks require security awareness training?

FrameworkScopeRequires training?What it is
ISO/IEC 27001:2022GlobalYesYesInternational standard for an Information Security Management System (ISMS)
CIS Controls v8.1GlobalYesYes18 prioritized best-practice controls for cybersecurity, from the US-based Center for Internet Security
NIST Cybersecurity FrameworkGlobalYesYesCommon-language framework built around 6 core functions: Govern, Identify, Protect, Detect, Respond, Recover
NIS 2 DirectiveEUPartialEU directive strengthening cybersecurity resilience across critical sectors, transposed into national law since 17 October 2024; training is mandatory for management bodies, encouraged for staff
PCI DSS v4.0.1GlobalYesYesSecurity standard for any organization that processes, stores, or transmits credit card data. Since 31 March 2025 the training must cover phishing and social engineering
GDPREUPartialEU law governing personal data protection; training sits inside the Data Protection Officer’s compliance-monitoring task, and Article 47 requires it outright for binding corporate rules
NIST SP 800-53 Rev. 5US (federal)YesYesSecurity and privacy controls for U.S. federal information systems
Gramm-Leach-Bliley Act (GLBA)US (finance)PartialU.S. law protecting consumer financial data; training isn’t named but is required via its Safeguards Rule
FTC Safeguards RuleUS (finance)YesYesGLBA rule requiring a comprehensive information security program
NERC CIPNorth AmericaYesYesStandards securing North America’s bulk electric system
HIPAAUS (healthcare)YesYesU.S. law protecting sensitive patient health information
COBIT 2019GlobalPartialISACA’s IT governance framework; training isn’t named but sits inside APO07 Managed Human Resources
Australian Government ISMAustraliaYesYesFramework securing Australian government information and systems; annual training mandated for all personnel, with tailored training for privileged users
PAS 555 (withdrawn)UKPartialBritish specification for cybersecurity risk governance; described outcomes rather than mandating specific actions. Withdrawn by BSI on 3 June 2025 with no replacement named
DORAEU (finance)YesYesEU regulation strengthening the financial sector’s digital operational resilience, applying directly since 17 January 2025
EBA Guidelines (narrowed)EU (banking)PartialEuropean Banking Authority guidance on ICT and security risk. Narrowed on 20 May 2025 once DORA took over information and communications technology risk management, so the training obligation now sits in DORA
SWIFT CSP RequirementsGlobalYesYesMandatory controls protecting SWIFT-related infrastructure
EIOPA Guidelines (revoked)EU (insurance)PartialEU guidance on governance and risk management for insurers and pension funds. Revoked with effect from 17 January 2025 because DORA covers the same ground
EU AI Act (Article 4)EUPartialEU regulation on artificial intelligence; Article 4 requires AI literacy training for staff who operate AI systems, rather than security awareness training
SCORMGlobalNoA technical e-learning standard, not a compliance framework

Most frameworks that govern regulated industries, finance, healthcare, and critical infrastructure treat security awareness training as a baseline control rather than an optional extra. Even the frameworks marked “Partial” above build training into their broader security-program requirements. They just don’t name it as a standalone line item. Frameworks also move: three of the entries below have been withdrawn, revoked, or narrowed by later regulation since this guide was first published, and each of those entries states its current status.

1. ISO/IEC 27001:2022 

What is the ISO 27001 regulation? 

ISO 27001 is an international standard that outlines best practices for an Information Security Management System (ISMS).

Developed and published by the International Organization for Standardization (ISO), it is a controls-based framework that helps organizations manage and protect their information assets.

ISO 27001 is part of a larger series of documents known as ISO 27000. ISO 27001 certification is voluntary in most cases, but accessing the official standard document isn’t free. For what the standard expects of a training programme in particular, see ISO 27001 compliance and cybersecurity awareness training.

The current edition is ISO/IEC 27001:2022. Certificates issued against the previous 2013 edition stopped being valid after 31 October 2025, the close of the accredited transition period, so an information security management system certified today is certified against the 2022 edition and the Annex A control set quoted below.

Does the ISO 27001 regulation require security awareness training?

Yes. ISO 27001 requires that all personnel (meaning employees and third parties) take security awareness training as part of its broader focus on ensuring that all members of an organization not only understand guidelines on security policies and procedures but also adhere to them.

The standard explicitly states that employees shall receive regular training on security policies, including their roles in maintaining security, and the importance of compliance with these policies to protect the organization’s data and assets. This helps embed security standards and culture across the organization.

Where is this mentioned?

ISO 27001 Annex A 6.3:

“Personnel of the organization and relevant interested parties shall receive appropriate information security awareness, education and training and regular updates of the organization’s information security policy, topic-specific policies and procedures, as relevant for their job function.”

2. CIS Controls 

What are the CIS Controls? 

The Center for Internet Security (CIS) Controls is a set of best practices for cybersecurity. CIS is based in the United States, though organizations worldwide use the Controls.

Originally known as the SANS Critical Security Controls, these guidelines are designed to help organizations defend against common cybersecurity threats.

The CIS Controls consist of 18 top-level controls and cover areas such as asset management, access control, and incident response. The current version is v8.1. They’re ranked by priority to guide organizations in implementing the most effective security measures first, which helps them improve their cybersecurity posture systematically.

Do the CIS Controls require security awareness training?

Yes. The CIS Controls emphasize that employees must be aware of security risks and trained to recognize, report, and respond to potential threats.

Awareness training helps employees prevent mistakes that could lead to security breaches. Human errors are hard to avoid, but organizations that successfully build a security-aware culture significantly reduce their vulnerability to cybersecurity risks by turning humans into their first line of defense.

Where is this mentioned?

CIS Controls v8.1, Safeguard 14.1:

“Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.”

Control 14 does not stop at a general awareness duty. Safeguard 14.2 names the attack class by type, and it carries no size exemption: it applies at implementation groups 1, 2 and 3, so it reaches the smallest organizations in scope as well as the largest.

CIS Controls v8.1, Safeguard 14.2:

“Train workforce members to recognize social engineering attacks, such as phishing, business email compromise (BEC), pretexting, and tailgating.”


3. NIST Cybersecurity Framework 

What is the NIST Cybersecurity Framework? 

The NIST Cybersecurity Framework is a set of guidelines developed by the National Institute of Standards and Technology (NIST), a United States federal agency, created to help organizations manage and reduce cybersecurity risks.

It provides a common language and systematic approach built around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. The framework is designed to improve cybersecurity practices across many industries and organizations, regardless of size or sector. Version 2.0, published on 26 February 2024, added Govern as the sixth function, covering how an organization establishes, communicates and monitors its cybersecurity risk management strategy, expectations and policy.

Does the NIST Cybersecurity Framework require security awareness training?

Yes. The NIST Cybersecurity Framework includes security awareness training as a key element within its “Protect” function.

This requirement essentially states that organizations should educate all personnel about their cybersecurity responsibilities.

The goal is to cultivate a culture of security awareness, so that individuals are aware of potential threats and learn how to mitigate cybersecurity incidents.

Where is this mentioned?

NIST Cybersecurity Framework 2.0, Awareness and Training (PR.AT):

“PR.AT-01: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind. PR.AT-02: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.”

4. NIS 2 

What is the NIS 2 Directive?

The NIS 2 Directive (Network and Information Systems Directive 2) is a framework established by the European Union to enhance cybersecurity across member states.

It updates the original NIS Directive, expanding its scope to cover more sectors, such as energy, transport, health, and digital infrastructure.

The directive aims to make critical entities more resilient to cyberattacks by setting stricter security requirements, enhancing incident reporting protocols, and promoting cooperation between member states.

NIS 2 also introduces tougher enforcement measures and higher penalties for non-compliance. It came into force in January 2023, and Member States had until 17 October 2024 to transpose it into national law. That deadline matters for how the obligation reaches you: a directive binds through each country’s own implementing legislation, so the text that applies to an entity is its national transposition rather than the Directive itself.

Does the NIS 2 Directive require security awareness training?

Yes, for management bodies. The NIS 2 Directive requires members of an organization’s management body to receive cybersecurity training, and encourages organizations to extend similar training to their employees.

Regular training and awareness programs help staff recognize and reduce the risk of human errors that can lead to security incidents.

Where is this mentioned?

NIS 2 Article 20, titled Governance, paragraph 2:

“Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.”

The training obligation in paragraph 2 is easier to understand next to paragraph 1 of the same article, which is where the pressure comes from. Paragraph 1 requires management bodies to approve the cybersecurity risk-management measures and to oversee their implementation, and it makes them liable for the entity’s infringements. Training the board is not a courtesy under NIS 2. It is how the people who carry the liability come to understand what they are approving.

5. PCI DSS 

What is the PCI DSS framework?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure all companies that process, store, or transmit credit card information maintain a secure environment.

The framework, developed by the PCI Security Standards Council, aims to protect cardholder data from breaches and fraud. PCI DSS applies globally, not to any single country.

It includes requirements for security management, policies, procedures, network architecture, and software design, covering areas like encryption, access control, or regular monitoring and testing of networks.

Compliance with PCI DSS is mandatory for organizations handling credit card information.

Does the PCI DSS framework require security awareness training?

Yes. The PCI DSS framework requires security awareness training to ensure that all employees understand why protecting cardholder data matters and what they personally need to do to keep it secure.

Ongoing training helps prevent human errors, like mishandling sensitive data or falling for phishing attacks, and keeps employees informed about security policies and practices, which is crucial for maintaining compliance with PCI DSS requirements.

Where is this mentioned?

PCI DSS v4.0.1 (June 2024), requirement 12.6.3:

“Personnel receive security awareness training as follows: Upon hire and at least once every 12 months. Multiple methods of communication are used. Personnel acknowledge at least once every 12 months that they have read and understood the information security policy and procedures.”

And the requirement that names our attack class, which was a best practice in version 4.0 and became mandatory on 31 March 2025:

PCI DSS v4.0.1, requirement 12.6.3.1:

“Security awareness training includes awareness of threats and vulnerabilities that could impact the security of cardholder data and/or sensitive authentication data, including but not limited to: Phishing and related attacks. Social engineering.”

The standard then says something most compliance summaries skip, in the applicability notes to this requirement: the anti-phishing technical controls in requirement 5.4.1 and the training in 12.6.3.1 are “two separate and distinct requirements, and one is not met by implementing controls required by the other one”. In plain terms, a filter that blocks phishing emails does not discharge the obligation to train people to recognise them. An assessor will look for both.

6. GDPR

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that governs how personal data of individuals within the EU is collected, processed, and stored.

Implemented in May 2018, GDPR aims to give individuals greater control over their personal data, by ensuring transparency, security, and accountability in data handling.

The regulation imposes strict requirements on organizations, such as obtaining explicit consent for data processing, allowing data access and deletion requests, and reporting data breaches within 72 hours.

Does GDPR require security awareness training?

Indirectly. GDPR doesn’t mandate training for all employees directly, but Article 39 places awareness-raising and training of staff inside the Data Protection Officer’s task of monitoring compliance. And there is one place where the Regulation does mandate training outright: Article 47, on binding corporate rules, the mechanism multinationals use to legitimise transfers of personal data inside their own group.

Where is this mentioned?

GDPR Article 39(1)(b), among the tasks of a Data Protection Officer (DPO), inside the duty to monitor compliance:

“awareness-raising and training of staff involved in processing operations”

And the outright requirement, which applies to binding corporate rules:

GDPR Article 47(2)(n):

“the appropriate data protection training to personnel having permanent or regular access to personal data.”

7. NIST SP 800-53 

What is NIST SP 800-53?

NIST Special Publication 800-53 (NIST SP 800-53) is a comprehensive set of guidelines developed by the National Institute of Standards and Technology (NIST) for U.S. federal information systems and organizations.

It provides a catalog of security and privacy controls designed to protect the confidentiality, integrity, and availability of information systems against various threats.

These controls help organizations comply with federal laws and regulations, including the Federal Information Security Management Act (FISMA), the U.S. law that governs cybersecurity for federal agencies.

Does NIST SP 800-53 require security awareness training?

Yes. NIST SP 800-53 requires security awareness training as part of its “Awareness and Training” (AT) control family. Revision 5 renamed the relevant control: AT-2 is now “Literacy Training and Awareness”, and it is written as outcomes to achieve rather than steps to perform. The control catalog is maintained in releases, and the current one is Release 5.2.0 of 27 August 2025, which changed software update and patch controls and left the AT family untouched.

This control family states the need to ensure that all personnel are aware of the security risks associated with their activities, and that they are equipped with the knowledge and skills to mitigate those risks.

Where is this mentioned?

NIST SP 800-53 Rev. 5, AT-2 Literacy Training and Awareness, paragraphs (a) and (d):

“a. Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): 1. As part of initial training for new users and [Assignment: organization-defined frequency] thereafter; and 2. When required by system changes or following [Assignment: organization-defined events];”
“d. Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.”

The bracketed “Assignment” notes are part of the control text. They mark the decisions NIST leaves to the adopting organization, so each agency sets its own training frequency and its own list of triggering events rather than inheriting a fixed number.

Paragraph (d) is the one worth reading twice. It obliges an organization to feed what it learns from real incidents back into the training itself, which makes a static annual course insufficient on its own. The control’s discussion section goes the same way on measurement: “Organizations provide basic and advanced levels of literacy training to system users, including measures to test the knowledge level of users.”

8. Gramm-Leach-Bliley Act 

What is the Gramm-Leach-Bliley Act?

The Gramm-Leach-Bliley Act (GLBA, also known as the Financial Services Modernization Act of 1999), is a U.S. federal law that requires financial institutions to protect the privacy of consumer financial information.

The act mandates that these institutions explain how they share information with customers. It also requires them to implement safeguards that protect sensitive data.

It includes three primary components:

  • The Financial Privacy Rule, which regulates the collection and disclosure of private financial information.
  • The Safeguards Rule, which requires institutions to implement security measures.
  • The Pretexting provisions, which protect against fraudulent access to private information.

Does the Gramm-Leach-Bliley Act require security awareness training?

No, not in the Act itself. GLBA sets the policy and then delegates: it directs each supervising agency to establish safeguards standards for the institutions under its jurisdiction. The standard the Federal Trade Commission wrote is the Safeguards Rule, and that rule does name security awareness training outright, as a required element rather than a common practice. So the obligation is real for a covered institution. It simply lives one level down, in the rule rather than in the statute, and the FTC Safeguards Rule entry below quotes the exact wording.

Its goal is for employees to understand the risks and their responsibilities in safeguarding sensitive financial information. The financial services industry already outperforms every other sector: it has the highest employee reporting rate (66.4%) and the lowest fail rate (2.04%), according to the Hoxhunt Phishing Trends Report 2026.

Where is this mentioned?

The Act itself delegates the detail. It tells each supervising agency to:

Gramm-Leach-Bliley Act, 15 U.S.C. 6801(b):

“establish appropriate standards for the financial institutions subject to their jurisdiction relating to administrative, technical, and physical safeguards”

The three objectives listed under that instruction cover the security and confidentiality of customer records, anticipated threats to those records, and unauthorized access to them. Training is not among them. It appears in the standard written under this authority, the FTC Safeguards Rule, which is the next entry.

9. FTC Safeguards 

What is the FTC Safeguards Rule?

The FTC Safeguards Rule (issued by the Federal Trade Commission) is part of the Gramm-Leach-Bliley Act (GLBA) and requires U.S. financial institutions to develop, implement, and maintain a comprehensive information security program to protect consumer information.

This program must include administrative, technical, and physical safeguards to ensure the security, confidentiality, and integrity of customer data. The rule also mandates regular risk assessments, employee training, and oversight of third-party service providers, all aimed at maintaining appropriate security measures.

Does the FTC Safeguards Rule require security awareness training?

Yes. Section 314.4 of the Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program. It must include administrative, technical, and physical safeguards that help protect customer information.

The rule sets out nine elements, lettered (a) to (i), and personnel training is element (e). What makes it demanding is not that training must happen but what it must be built on: the rule ties the content to the institution’s own risk assessment, and requires it to be updated as those risks change. A generic annual course that never moves does not satisfy that.

Where is this mentioned?

FTC Safeguards Rule, 16 CFR 314.4(e), with its first numbered item:

“Implement policies and procedures to ensure that personnel are able to enact your information security program by: (1) Providing your personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment;”


10. NERC CIP

What is NERC CIP?

North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) is a set of standards designed to secure the assets critical to operating North America’s bulk electric system.

These standards address various aspects such as safeguarding physical and cyber assets, ensuring personnel are trained, and preparing for incident response and recovery. The overarching goals are to secure the electric grid from potential cyber threats and to ensure its reliability.

Does NERC CIP require security awareness training?

Yes. NERC CIP requires security awareness training to ensure that all personnel involved in the protection and operation of critical electric infrastructure are well-informed about security risks and protocols.

Security awareness training ensures employees can safeguard physical and cyber assets, prevent unauthorized access, and respond effectively to security threats.

Where is this mentioned?

NERC CIP-004-7, Table R1, Part 1.1, which applies to high and medium impact BES Cyber Systems:

“Security awareness that, at least once each calendar quarter, reinforces cyber security practices (which may include associated physical security practices) for the Responsible Entity’s personnel who have authorized electronic or authorized unescorted physical access to BES Cyber Systems.”

Two details are worth pulling out. The cadence is quarterly, which is the most frequent requirement of any framework in this guide, where annual is the norm. And the word the standard uses is “reinforces”, not “delivers”: the obligation is continuing reinforcement of practice rather than a course that is completed once and filed. BES Cyber Systems are the bulk electric system assets whose loss would affect the reliable operation of the grid.


11. HIPAA

What is HIPAA?

Health Insurance Portability and Accountability Act (HIPAA) is a U.S. law enacted in 1996 to protect sensitive health information.

It establishes national standards for the security and privacy of health data, requiring healthcare providers, insurance companies and their business associates to safeguard medical information. HIPAA also grants patients the right to access their records and request corrections to them.

Non-compliance with HIPAA can result in significant fines and penalties.

Does HIPAA require security awareness training?

Yes. Under the HIPAA Security Rule, covered entities and their business associates must implement a security awareness and training program for all members of their workforce.

Security awareness training ensures employees understand how to safeguard electronic protected health information (ePHI) from unauthorized access, breaches, and other security threats.

Where is this mentioned?

HIPAA § 164.308 (5) (i): Under the Act, an organization must:

“Implement a security awareness and training program for all members of its workforce (including management).”

12. COBIT

What is COBIT?

Control Objectives for Information and Related Technologies (COBIT) is a framework for IT management and governance, developed by ISACA (Information Systems Audit and Control Association). 

It provides organizations with a set of best practices, tools, and guidance to help them align IT with business goals, manage risk effectively, and meet regulatory compliance requirements.

COBIT focuses on managing and optimizing IT processes, improving information security, and ensuring that IT investments deliver value to the organization.

Does COBIT require security awareness training?

Not directly. COBIT does not name security awareness training as an objective of its own. The closest fit is the objective covering people and their competencies, which in the current version, COBIT 2019, is APO07 Managed Human Resources. Security awareness sits inside it as part of keeping staff competent for their roles, alongside understanding and following information security policies.

Well-informed employees are less likely to make costly security mistakes, which reduces risks associated with human error.

Where is this mentioned?

COBIT 2019, objective APO07 Managed Human Resources. This guide names the objective rather than quoting it, because the exact wording could not be verified against ISACA’s own published text.

One correction worth stating plainly, since other compliance guides repeat it: the identifier “PO7” belongs to COBIT 4.1. The “PO” domain, Plan and Organise, was retired when COBIT 5 arrived in 2012. COBIT 2019 organises its objectives under five domains instead, abbreviated EDM, APO, BAI, DSS and MEA.

13. Australian Government InfoSec Manual 

What is ISM?

Australian Government InfoSec Manual (ISM) is a framework designed to assist government agencies in protecting their information and systems from cyber threats. It provides guidelines and controls for securing data, ensuring system integrity, and maintaining confidentiality.

The ISM covers a wide range of topics, including access control, risk management, and incident response, and is regularly updated to address emerging threats and technologies.

Does the ISM require security awareness training?

Yes. The ISM mandates security awareness training to ensure that all employees are knowledgeable about their responsibilities in protecting sensitive information and systems.

Training is essential for reducing human error and for ensuring that staff are aligned with the ISM’s security requirements.

Where is this mentioned?

Information security manual, control ISM-0252 (revision 8, updated March 2025):

“Cybersecurity awareness training is undertaken annually by all personnel and covers: the purpose of the cybersecurity awareness training; security appointments and contacts; authorised use of systems and their resources; protection of systems and their resources; reporting of cybersecurity incidents and suspected compromises of systems and their resources.”

Two neighbouring controls matter as much as that one, and neither is widely quoted. ISM-1565 requires tailored privileged user training annually for every privileged user, so a single all-staff course does not discharge the obligation for administrators and developers. And ISM-2022, added in June 2025, requires that “a cybersecurity awareness training register is developed, implemented and maintained”, which turns the training from something you do into something you have to be able to evidence on request.

14. PAS 555 Cyber Security Risk: Governance and Management (withdrawn 2025) 

What is PAS 555?

PAS 555, short for Publicly Available Specification, was a British specification that provided a framework for managing and governing cybersecurity risks within an organization. BSI itself notes that a Publicly Available Specification is not to be regarded as a British Standard. It emphasized a comprehensive, outcomes-focused approach that integrated risk management with business processes.

Status update. BSI withdrew PAS 555:2013 on 3 June 2025 and named no replacement, so it is no longer a specification an organization can work to. It stays in this guide because compliance documentation and vendor questionnaires still reference it.

PAS 555 was designed to help organizations understand their cyber risk exposure, establish effective governance, and implement strong security controls. It covers areas such as leadership responsibilities, risk assessment, incident management, and continuous improvement.

Does PAS 555 require security awareness training?

Not exactly. PAS 555 didn’t specify exact actions. It described what effective cybersecurity looks like, including a workforce that is aware of cyber risks and understands its role in managing them.

Organizations that integrate security awareness into daily operations strengthen their overall cybersecurity posture.

Where is this mentioned?

PAS 555 didn’t specify actions. It defined what effective cyber security looks like.

It advocated for organizations to ensure that all personnel are informed about cybersecurity risks and understand their roles in managing these risks.

15. Digital Operational Resilience Act (DORA) 

What is DORA?

The Digital Operational Resilience Act (DORA) is a European Union regulation that strengthens the financial sector’s resilience to digital disruptions. It aims to ensure that financial entities, such as banks, insurers, and investment firms, can withstand, respond to, and recover from all types of information and communications technology (ICT) disruptions and threats.

DORA establishes requirements for ICT risk management, incident reporting, and third-party risk management. Its deadlines, scope and checklist are set out in full in the DORA regulation summary. It strengthens the financial sector’s resilience against increasing cyber threats and digital dependencies. DORA has applied since 17 January 2025. Because it is a regulation rather than a directive, it binds financial entities directly and did not need transposing into national law, which is why the same text applies across every member state.

Does DORA require security awareness training?

Yes. Security awareness training is needed to stay compliant with DORA. It ensures that employees in the financial sector can effectively recognize, respond to, and manage ICT-related risks and threats.

Where is this mentioned?

DORA Article 13 (6):

“Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions. Where appropriate, financial entities shall also include ICT third-party service providers in their relevant training schemes in accordance with Article 30(2), point (i).”

That last sentence is the part most summaries leave out. DORA does not stop at your own payroll: where it is appropriate, the suppliers who run your information and communications technology come into the training scheme too.

16. EBA Guidelines on ICT and security risk management (narrowed 2025) 

What are the EBA Guidelines?

The EBA Guidelines on ICT and security risk management, issued by the European Banking Authority (EBA), provide guidance for financial institutions on how to manage and mitigate risks associated with ICT and security.

These guidelines set out requirements for risk management frameworks, incident reporting, business continuity, and governance. It aims to ensure that institutions can effectively withstand, respond to, and recover from ICT disruptions and cyber threats.

Do the EBA Guidelines require security awareness training?

It’s expected, not strictly mandated. The EBA Guidelines say institutions should establish a training program, including periodic security awareness sessions, for all staff and contractors.

Status update. The EBA amended these guidelines through EBA/GL/2025/02, applicable from 20 May 2025, narrowing their scope after DORA started to apply on 17 January 2025. DORA now carries the harmonized requirements for information and communications technology risk management for the entities it covers, and for those entities the training obligation sits in DORA Article 13(6), quoted under DORA above. What remains in scope for these guidelines is the management of the relationship with payment service users.

Where is this mentioned?

EBA 3.4.7 (49):

“Financial institutions should establish a training programme, including periodic security awareness programmes, for all staff and contractors to ensure that they are trained to perform their duties and responsibilities consistent with the relevant security policies and procedures to reduce human error, theft, fraud, misuse or loss and how to address information security related risks.”


17. SWIFT Customer Security Program Requirements 

What are the CSP Requirements?

The SWIFT CSP Requirements are a set of mandatory security controls that help financial institutions around the world protect their SWIFT-related infrastructure against cyber threats. SWIFT stands for Society for Worldwide Interbank Financial Telecommunication, and CSP for Customer Security Program.

The program focuses on three areas: environment security, access management, and incident detection and response.

Complying with the CSP Requirements keeps the global financial messaging network secure and makes institutions more resilient against cyber attacks.

Does SWIFT require security awareness training?

Yes. Security awareness training is required as part of the controls to ensure that all personnel involved in managing SWIFT-related infrastructure understand their role in safeguarding the system and are aware of potential threats.

Implementing training will prevent human errors that could compromise the security of financial transactions. It also helps ensure employees can recognize and report suspicious activity, which strengthens the SWIFT network’s overall security.

Where is this mentioned?

SWIFT Customer Security Controls Framework v2026, control 7.2 Security Training and Awareness, a mandatory control across every Swift architecture type. Its control statement:

“Annual security awareness sessions are conducted for all staff members with access to Swift-related systems. All staff with privileged access maintain knowledge through specific training or learning activities when relevant or appropriate (at management’s discretion).”

Version 2026 of the framework changed what that awareness has to cover. Swift’s own summary of the release records that control 7.2 “is updated with a reference to Deepfake as an example of AI-based threats”, and the topics the control now lists for staff training include:

“Safe operating habits (for example, spam and phishing, including “spear” phishing identification or AI-based (deepfake text, voice and video) phishing, downloading files, browsing practices)”

Text, voice and video are named separately, so a programme that only teaches people to spot a suspicious email no longer covers the control. This is the first framework in this guide to put deepfake recognition inside a mandatory training requirement.

18. EIOPA Guidelines (revoked 2025) 

What are the EIOPA Guidelines?

The EIOPA Guidelines were a set of recommendations from the European Insurance and Occupational Pensions Authority (EIOPA). They promote sound governance and risk management across insurance and pensions sectors in the EU.

These guidelines cover areas such as system governance, outsourcing, product oversight, and cybersecurity. They help institutions comply with EU regulations, maintain financial stability, protect consumers, and improve transparency.

Do the EIOPA Guidelines require security awareness training?

It’s expected, not strictly mandated. The EIOPA Guidelines recommend that undertakings establish periodic security awareness programs to educate their staff.

Status update. EIOPA revoked the Guidelines on information and communication technology security and governance with effect from 17 January 2025, on the grounds that DORA fully encompasses their objectives and provisions. Insurers and pension funds in scope of DORA should read the training obligation in DORA Article 13(6) instead.

Where is this mentioned?

EIOPA 13 (41):

“Undertakings should establish and implement periodic security awareness programmes to educate their staff, including the AMSB, on how to address information security related risks.”

19. EU AI Act (Article 4)

What is the EU AI Act?

The EU AI Act, Regulation (EU) 2024/1689, is the European Union’s regulation on artificial intelligence. It sorts AI systems by risk level and sets obligations both on the organizations that build them, called providers, and on the organizations that put them to use, called deployers.

It belongs in this list because of one article that sits outside the risk classification: Article 4, on AI literacy, which applies to every provider and deployer whatever the risk level of the system.

Does the EU AI Act require security awareness training?

Not security awareness training specifically. Article 4 requires measures that ensure a sufficient level of AI literacy among staff and anyone else operating AI systems on the organization’s behalf. It is a training obligation rather than a security training obligation, and it is the newest one in this guide: Article 4 has applied since 2 February 2025, and the European Commission’s supervision and enforcement of it start on 2 August 2026.

In practice the two programs meet in the middle. Staff who use AI tools have to understand what those tools can and cannot be trusted with, which is the same ground a current awareness program covers when it teaches people to recognize AI generated phishing and deepfakes.

Where is this mentioned?

EU AI Act Article 4:

“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”

20. SCORM

The Sharable Content Object Reference Model (SCORM) is a set of technical standards for e-learning software products. It standardizes how online learning content and Learning Management Systems (LMS) communicate, so they remain compatible.

SCORM makes learning content reusable and easy to share across systems. It tracks learner progress and performance, and it supports the sequencing of learning activities. These capabilities make SCORM a widely used standard in online education and training programs.

Does SCORM require security awareness training?

No. SCORM is a technical standard for e-learning, not a regulatory or compliance framework, so it doesn’t inherently require security awareness training.

However, if SCORM-compliant e-learning courses are used to deliver security awareness training within an organization, then the content and structure of the training would have to adhere to SCORM standards and be compatible across various Learning Management Systems.

Following SCORM standards makes it easier to track employee progress in mandatory security awareness training programs.


How to maintain security awareness training compliance?

Maintaining compliance across multiple frameworks is an ongoing process, not a one-time checklist. The recommendations below will help your organization stay aligned as regulations and training requirements evolve.

Understand the requirements

Thoroughly review what is actually included in each framework

Conduct a detailed analysis of each compliance framework and its regulatory requirements to identify the specific training requirements related to security awareness.

Questions to ask

Ensure you understand the nuances of each framework:

  • How frequently does training need to be conducted?
  • What should content include?
  • What kind of documentation do you need?

Consult experts if needed

If in doubt, you can always reach out to legal or compliance experts to clarify any ambiguities and ensure that your interpretation of the requirements is accurate.

Develop a comprehensive training program

Tailor content to your specific needs

Make sure your training addresses the specific security risks and regulatory requirements outlined in each framework.

Your training will most likely need to cover core topics like data protection, phishing prevention, incident response, and privacy regulations.

Platforms differ a great deal in how much of that they cover out of the box and in whether they can evidence completion the way an auditor expects, so it is worth seeing how the main security awareness training platforms compare before committing to one.

Use interactive modules

Incorporate interactive elements such as quizzes, simulations, and case studies to engage employees and reinforce learning outcomes.

These interactive elements keep the training engaging so it doesn’t feel like a box-ticking exercise.

Use SCORM-compliant content

Standardize your training content

Implement SCORM-compliant e-learning content to facilitate compatibility with various Learning Management Systems (LMS).

This standardization allows for consistent delivery, tracking, and reporting of training across different platforms.

Use customizable modules

In order to keep the training relevant and effective, opt for SCORM content that can be easily updated and customized to reflect changes in compliance requirements or organizational policies.

Regularly update your training

Stay on top of regulatory changes

Your training content will need to be aligned with any updates to key requirements, so make sure you stay informed about updates to relevant compliance frameworks by subscribing to industry news, participating in webinars, and consulting with regulatory bodies.

Keep content up-to-date with the latest threats

Security threats are always evolving, so your training should be updated continuously to cover new and emerging risks. Regularly review and refresh training content to address new threats.

Make sure you have the necessary documentation and tracking in place

Don’t forget about record-keeping

Keep detailed records of who has completed training, when it was completed, and what content was covered.

This documentation is crucial for demonstrating compliance during audits.

Set automated reminders

Set up automated reminders and notifications to ensure that employees complete their training on time.

Stay compliant with Hoxhunt

Want to easily manage and customize your security awareness training based on your company policies?

Hoxhunt was specifically designed to meet your security awareness and compliance needs with modern and engaging training.

  • Boost security knowledge: Make training relevant by educating employees based on their role and location. Automatically trigger mandatory training for new joiners.
  • Cover every training need: Meet your compliance and awareness requirements with an always up-to-date training library. When unique needs arise, use our powerful generative AI to create content tailored to you.
  • Achieve compliance easily: Our training library contains ready-made and easily customizable training content packages to meet regulatory requirements.

Hoxhunt security compliance training: assigning a training package, with a compliance field tagging it to ISO 27001, SOC 2, HIPAA and PCI DSS

Go beyond compliance and measurably change behavior

Effective security awareness programs do more than tick a compliance box.

Building a true security-first culture, one where employees are genuinely committed, not just compliant, means engaging, educating, and rewarding each individual.

And that’s exactly what Hoxhunt is built for. It automatically adapts training content to each employee’s role, department, and location, which keeps you compliant while making sure your message actually lands.

  1. Embed your training into your employees’ workflowAutomatically train your employees during their workday with micro-training moments delivered in their workflow.
  2. Reach employees across multiple channelsEnhance your security awareness with intuitive training that integrates directly into employees’ daily tools. Activate Hoxhunt with a single click on platforms like Microsoft Office, Google Workspace, Slack, and Microsoft Teams.
  3. Increase your training engagementCreate a self-reinforcing training experience with reward-based incentives that motivate employee participation.
  4. Track your progress with powerful dashboardsGain real-time visibility into your program performance with modern dashboards and next-level metrics. Set your priorities with data-driven decisions, and report to leadership with ease and confidence.
Hoxhunt security awareness training dashboard showing gamified progress, a leaderboard, reported and clicked simulation rates, and reporting streaks

Compliance frameworks for security awareness training FAQ

What are security compliance frameworks?

Security compliance frameworks are structured approaches that organizations use to ensure they meet industry standards and legal requirements, like GDPR and NIST CSF. These frameworks help organizations establish internal controls, promote ethical business practices, and maintain customer trust.

Why is security awareness training important for compliance?

Security awareness training is crucial for maintaining compliance with various regulatory standards. It helps employees understand compliance policies, recognize potential risks, and adhere to legal requirements, which reduces the risk of legal penalties and the loss of customer trust.

How does security awareness training align with industry standards like PCI DSS and HIPAA?

Training modules tailored to industry standards such as PCI DSS and HIPAA ensure that employees understand the specifics of handling sensitive data, such as cardholder and healthcare information. This alignment is essential for compliance programs in healthcare organizations, financial institutions, and service organizations, particularly those dealing with cloud service providers and transaction monitoring.

What are the consequences of non-compliance?

Non-compliant organizations can face civil and criminal penalties, loss of certification, and significant damage to customer trust. In the context of cybersecurity programs, non-compliance also brings substantial costs, since fixing it requires ongoing improvement efforts and proactive risk management measures.

Sources

GDPR Fines · GDPR.eu, 2024
Cost of a Data Breach Report
· IBM, 2025
Data Breach Investigations Report (DBIR)
· Verizon, 2026
ISO/IEC 27001 Standard
· ISO, 2022
CIS Controls v8.1
· CISecurity
NIST Cybersecurity Framework 2.0
· NIST, 2024
NIS2 Directive
· Digital Strategy, European Commission, 2023
PCI DSS v4.0.1
· PCI Security Standards Council, 2024
GDPR Info
· GDPR-Info, 2024
NIST SP 800-53 Rev. 5
· NIST
Gramm-Leach-Bliley Act
· FTC, 2023
FTC Safeguards Rule
· FTC, 2023
NERC CIP-004-7, Cyber Security: Personnel & Training
· NERC
HIPAA Overview
· HHS, 2024
COBIT Framework
· ISACA, 2023
Information security manual (June 2025)
· Australian Signals Directorate
PAS 555 Cybersecurity Governance · EN Standard, 2013 (withdrawn by BSI, 2025)
Digital Operational Resilience Act (DORA)
· EIOPA, 2023
Guidelines on ICT and Security Risk Management
· EBA, 2025 (EBA/GL/2025/02)
SWIFT Customer Security Controls Framework v2026
· SWIFT
EIOPA Guidelines on ICT Security and Governance
· EIOPA, 2023 (revoked 2025)
Regulation (EU) 2024/1689 (EU AI Act), Article 4 · Official Journal of the European Union, 2024

SCORM Overview
· SCORM.com, 2023

Want to learn more?
Be sure to check out these articles recommended by the author:
Get more cybersecurity insights like this