EU compliance: 7 records SMEs must keep for security awareness training

Meeting security awareness training requirements means covering five things: foundational awareness for every employee, role-based training for anyone whose job affects security, documented records with version control and acknowledgements, regular phishing simulations, and measurable proof that behaviour is actually changing. Frameworks including ISO 27001, PCI DSS v4.0, NIST guidance, GDPR, NIS2, and DORA all converge on this same baseline, even where the wording differs.


TL;DR:

  • Training must include documented records with version control, individual completion logs, and acknowledgements to meet audit requirements.
  • Core topics must cover phishing, password hygiene, data handling, incident reporting, and role-specific modules tailored to job risks.
  • Regular, continuous training with frequent simulations and updates based on current threats is essential to demonstrate ongoing effectiveness.
  • Evidence such as phishing click and reporting trends, not just completion rates, are crucial metrics that prove behavior change over time.
  • Automation platforms can streamline compliance processes by collecting, mapping, and generating audit-ready documentation across major frameworks.

Table of Contents

What security awareness training requirements mean in practice

Awareness training and role-based training are not the same thing, and conflating them is the single most common reason audits stall. Awareness training covers what every employee needs to recognise, regardless of job title: phishing red flags, password discipline, acceptable use. Role-based training goes further. It targets people whose access or duties create specific risk, such as system administrators, finance staff who approve payments, developers who write code, or HR teams handling personal data.

Auditors rarely accept a spreadsheet showing "100% completion" as sufficient evidence. What they want is proof that the content was appropriate to the risk each employee carries and that the organisation can demonstrate this over time. A generic video watched once a year satisfies almost nobody reviewing against ISO 27001 or PCI DSS v4.0.

At minimum, compliance officers should be able to produce documentation showing training policies, individual completion records with dates and version control, role-specific training modules, phishing simulation results over time, and signed or logged acknowledgements as evidence.

This is the baseline auditors expect before they even look at whether the training content itself was good.

Core topics every compliant programme must include

Most frameworks, from PCI DSS v4.0 to ISO 27001, converge on a similar core curriculum, even when their exact wording varies. Building a programme around these topics covers the overwhelming majority of audit requirements without reinventing anything.

  • Phishing and social engineering across every channel: email, phone-based vishing, and SMS-based smishing, not just the inbox
  • Password hygiene and multi-factor authentication, including why shared credentials and password reuse remain leading breach causes
  • Data handling and classification, tied explicitly to GDPR obligations around personal data and lawful processing
  • Incident reporting and escalation, so staff know exactly who to tell and how fast, not just that something "seems off"
  • Acceptable use and malware protection, covering personal devices, removable media, and shadow IT
  • Role-specific modules for developers (secure coding basics), system admins (privileged access hygiene), finance (invoice fraud and payment diversion scams), and HR (data protection and social engineering targeting sensitive records)

From March 2025, PCI DSS v4.0 made phishing and social engineering training explicitly mandatory under its 12.6 clauses, formalising what many payment-handling organisations were already doing informally. That shift signals where every framework is heading: generic "cyber hygiene" content is being replaced by named, testable threats.

Engineering teams deserve particular attention here. Beyond basic phishing awareness, developers benefit from threat-modelling exercises and periodic hands-on sessions that build secure-by-design habits rather than one-off compliance box-ticking, according to Microsoft's security training guidance.

Who needs it and how major frameworks require training

Training obligations differ by framework, and knowing which clause applies to your organisation saves considerable audit preparation time.

  • ISO 27001:2022 separates awareness from competence outright. It requires organisations to identify role-specific competence needs and keep documented evidence of both training delivery and demonstrated competency, not just attendance.
  • PCI DSS v4.0 mandates formal awareness training on hire and at least annually for anyone touching cardholder data, with phishing-specific training now a named requirement rather than an implied one.
  • NIST SP 800-50 frames training as a life-cycle process. It recommends a mix of simulations, role-based workshops, and continuous awareness messaging rather than annual lectures, and this framing increasingly shapes how auditors judge "adequate" training elsewhere.
  • GDPR does not name specific training modules but requires organisations to demonstrate appropriate technical and organisational measures. Staff training on data handling is generally treated as a baseline expectation.
  • NIS2 extends training obligations across the supply chain for essential and important entities operating in the EU, meaning your suppliers' training posture can become your problem during an audit.
  • DORA adds sector-specific weight for financial entities, requiring ICT risk awareness training embedded into broader operational resilience testing, not treated as a standalone HR exercise.

Vendor and contractor training deserves its own line item. If a supplier can access your systems or data, their staff's awareness gaps become your exposure, particularly under NIS2's supply-chain provisions. Sectors handling payments, health data, or financial services typically face layered requirements, stacking a general framework like ISO 27001 with a sector-specific one like PCI DSS or DORA.

Practical compliance checklist: the artefacts and records auditors will ask for

Auditors consistently request the same seven categories of evidence, according to compliance guidance from Adaptive Security. Missing even one tends to trigger follow-up questions that stretch out an otherwise straightforward review.

  1. Training records — who completed what, and when
  2. Curriculum versions — proof that content was updated and which version each employee saw
  3. Signed acknowledgements — confirmation staff received and understood the material
  4. Phishing simulation trend data — results across multiple cycles, not a single snapshot
  5. Written training policy — the governing document naming scope, frequency, and ownership
  6. Onboarding records — evidence new hires received training within a defined window
  7. Vendor and contractor training logs — proof third parties meet the same baseline

For each record, capture at minimum: employee name, completion date, training title, content version number, and a score or pass/fail result. Skipping the version number is the most common gap. Without it, you cannot prove which employees saw outdated content after a policy change.

Pro Tip: Most documentation failures are not about weak training content. They come from poor record-keeping: no versioning, missing acknowledgements, or no clear mapping between roles and the modules assigned to them. Fix the records before you fix the curriculum.

A simple version log tied to your training platform closes most of these gaps in a single afternoon.

Designing a compliant, effective programme: cadence, methods and lifecycle

Annual training alone no longer satisfies most auditors, and it barely dents actual risk. A defensible cadence looks like this: onboarding training within the first two weeks of hire, a minimum annual refresh for all staff, and more frequent microlearning or phishing simulations running between the two, ideally quarterly.

Security training cadence timeline

NIST SP 800-50 recommends treating awareness as a continuous life-cycle built from simulations, role-based workshops, and ongoing messaging, rather than a single annual event. The EU-focused ECSO minimum reference curriculum reinforces this, recommending blended learning methods and simulation or cyber-range exercises for building practical skills rather than passive knowledge.

A workable delivery mix typically includes:

  • Short workshops for onboarding and major policy changes
  • Regular phishing simulations with immediate, targeted feedback for those who click
  • Microlearning modules of five to ten minutes for ongoing reinforcement
  • Deeper role-based sessions for developers, admins, and finance staff
  • Brief manager briefings so leadership can reinforce messaging within their teams

Curriculum content should not sit static for twelve months. Update it whenever a real incident occurs internally, when a new phishing technique emerges publicly, or when a regulatory change shifts what "appropriate measures" means under GDPR or NIS2. A programme like the one outlined in ShieldIQ's guide to phishing testing and human risk shows how behaviour-change campaigns work in practice for smaller teams without dedicated security staff.

Measuring effectiveness: metrics auditors value and how to show improvement

Completion rates alone tell an auditor almost nothing about whether training actually reduced risk. The metrics that matter most are click rate on simulated phishing emails, reporting rate (how many employees flagged the suspicious email rather than clicking or ignoring it), and assessment scores from post-training quizzes.

Metric What it shows Why auditors value it
Phishing click rate Susceptibility to social engineering Declining trend over cycles proves training works
Reporting rate Active vigilance, not just avoidance Rising trend shows behavioural change, not luck
Completion rate Basic coverage across the organisation Baseline evidence, but weakest signal alone
Assessment score Retention of core concepts Flags roles needing remedial training

Insurers and auditors are increasingly asking for active phishing simulation programmes with remedial training tied to failures, not just static course completion. Presenting a quarter-by-quarter trend line showing click rates falling and reporting rates rising is far more persuasive during an audit than a single completion percentage. Package these figures alongside your training records so the evidence tells a coherent story rather than sitting as isolated data points.

How ShieldIQCyber can help operationalise compliance and evidence management

Building and maintaining this evidence manually, across spreadsheets, email acknowledgements, and separate phishing tools, is where most SMEs lose time and where audit gaps quietly accumulate. Some platforms address this directly through:

  • Automated assessments that score training gaps against the framework you're targeting, whether ISO 27001, NIS2, or DORA
  • Control mapping that links training records to the specific clauses auditors will check
  • Audit-ready documentation, generated automatically rather than assembled by hand before every review
  • Versioned records and role mapping, so curriculum changes and role-specific assignments stay traceable over time

The practical effect is fewer manual handoffs and fewer missing fields at exactly the point an auditor asks for them. For organisations without a dedicated security team, that structure often matters more than the training content itself.

Legal consequences and penalties of non-compliance related to security awareness training

Weak or undocumented training rarely triggers a standalone penalty on its own. Instead, it surfaces as an aggravating factor once a breach occurs, and this is where the financial exposure becomes real. Under GDPR, regulators assessing fines explicitly weigh whether "appropriate technical and organisational measures" were in place, and a demonstrable absence of staff training on data handling weakens an organisation's defence considerably during an investigation.

For organisations under PCI DSS v4.0, failing to deliver mandatory annual training, or skipping the now-required phishing and social-engineering modules, can result in loss of payment processing privileges, increased transaction fees, or removal from card scheme compliance programmes entirely. That is a direct commercial consequence, separate from any regulatory fine.

NIS2 introduces personal liability considerations for management bodies at essential and important entities, meaning inadequate training oversight can expose leadership, not just the organisation, to accountability. DORA carries similar weight for financial entities, where ICT risk training gaps can factor into supervisory findings and remediation orders.

Beyond formal penalties, insurers increasingly review training evidence during underwriting. A poorly documented programme can mean higher premiums, reduced coverage, or denied claims following a breach traced to a phishing incident an employee should reasonably have caught. The absence of training records, more than the absence of training itself, is often what turns an incident into a liability.

Best practices for tailoring training content to different industries or organisational sizes

A ten-person accountancy firm and a 200-person software company face the same core threats but need different delivery. Smaller organisations without dedicated security staff generally do better with shorter, more frequent microlearning rather than lengthy annual workshops, since time pressure is the biggest barrier to completion. A platform-driven approach that automates scheduling and reminders tends to outperform manually chased email campaigns at this scale.

Larger or mid-market organisations can support more role differentiation: separate tracks for developers, finance, HR, and leadership, each with content matched to their actual risk exposure. Sector matters too. Payment-handling businesses need PCI DSS-aligned phishing and cardholder data modules. Healthcare organisations need data classification training that reflects the sensitivity of patient records. Financial entities under DORA need ICT risk content woven into operational resilience training, not delivered as a separate, disconnected course.

Regardless of size, the content should reflect real, recent threats. Generic "spot the phishing email" examples from a template library age quickly and lose relevance. Pulling in current threat intelligence, including commentary on live phishing and AI-driven scam trends from sources like Bootable USBs' cybersecurity coverage, keeps simulations grounded in what employees are actually likely to encounter rather than what a template designer imagined three years ago.

Best practices for tailoring training content to different industries or organisational sizes — overview diagram

Why continuous, evidence-focused training now matters

Annual, tick-box training stopped satisfying auditors some time ago, and insurers moved even faster. What changed is the expectation of proof: not that training happened, but that it changed behaviour, measurably, over time. A single course completion tells nobody whether an employee would actually spot a convincing phishing email six months later.

The organisations passing audits comfortably are the ones treating awareness as an operating habit, not an HR formality. That means simulations, updated content, and records that show a trend line, not a snapshot. Culture shifts slower than compliance deadlines, which is exactly why starting the measurement habit early matters more than perfecting the curriculum first.

— Matthew Lemon

Next steps with ShieldIQCyber: audit-ready compliance for SMEs

Building this evidence trail by hand, chasing acknowledgements, versioning curriculum, tracking phishing trends across spreadsheets, is exactly the overhead that pulls compliance officers away from the work that actually reduces risk. Certain compliance platforms automate the assessment, mapping, and documentation side of this, generating audit-ready records across ISO 27001, NIS2, GDPR, and DORA without needing a dedicated security team to maintain them.

ShieldIQ

If your organisation is preparing for an upcoming audit or simply wants clarity on where its current training programme falls short, ShieldIQ's compliance platform gives you a structured starting point. For organisations that want hands-on support building the programme itself, ShieldIQ's consulting services cover implementation and audit preparation directly. Book a walkthrough to see exactly which gaps your current records would expose in a real audit.

Authoritative guidance and primary sources

For readers who want to go straight to the primary documents:

  • NIST SP 800-50 sets out the life-cycle approach to security training programmes referenced throughout this guide.
  • ISO/IEC 27001:2022 defines the awareness versus competence distinction auditors check against.
  • The ECSO Minimum Reference Curriculum offers EU-specific guidance on blended learning and simulation design.
  • ShieldIQ's NIST CSF guide for SMEs translates framework language into practical control mapping.

Sources

FAQ

What Are the Requirements for Security Awareness Training?

At minimum, organisations need foundational awareness training for all staff, role-based training for higher-risk positions, documented records with version control, regular phishing simulations, and measurable evidence of behavioural improvement, mapped to whichever framework applies, such as ISO 27001 or PCI DSS v4.0.

What Are the 5 C's in Security?

There is no single, universally agreed "5 C's" framework specific to security awareness training. Definitions vary by source, so treat any list claiming this as informal shorthand rather than a recognised standard.

How Often Should Security Awareness Training Be Conducted?

Most frameworks expect training on hire and at least annually thereafter, with more frequent microlearning and phishing simulations, ideally quarterly, running between the formal annual cycles.

What Are the Steps Involved in the Security Awareness Training Process?

The typical process runs: assess risk and roles, design core and role-based content, deliver via workshops and microlearning, run ongoing phishing simulations, document everything with versioning and acknowledgements, and measure metrics like click and reporting rates to refine the next cycle. Some platforms can automate the assessment and documentation stages of this cycle.

Recommended