The security awareness training policy template, with a training log

Who is screened and trained, when, on what, and the log that proves it happened.

A security awareness training policy template covers the people side of security: background checks and acknowledgments at hire, training within 30 days and every year after, what happens when someone is overdue, and discipline. SOC 2 tests it against CC1.4, developing competent people, and CC1.5, holding them accountable.1

The policy is below, and a training log workbook downloads beside it, because the log is what gets sampled.

What an auditor checks

  1. New hires trained on time. For each sampled new hire, the start date beside the training date.
  2. Annual refreshers. For people employed all period, a completion inside the last twelve months.
  3. Acknowledgments and background checks. A signed acknowledgment and a completed check for each sampled hire.
  4. Follow-up on the overdue. If anyone was late, the reminder and escalation the policy describes.

The full policy text

The program shape, a defined audience, a curriculum, a completion record and follow-up, follows National Institute of Standards and Technology (NIST) Special Publication 800-50 Rev. 1 on building a learning program.2 Delivery can be a recorded session with a short quiz.

[Company name]

Security Awareness Training Policy

Owner
[Security owner role]
Approved by
[Policy approver role]
Effective date
[Effective date]
Next review
[Next review date]
Version
[Version]

1. Purpose and scope

This policy sets how [Company name] (the "Company") screens, trains and holds accountable the people who work for it. It supports the SOC 2 common criteria CC1.4 and CC1.5 by defining security requirements throughout the employee lifecycle.

This policy applies to all [In-scope personnel].

2. Onboarding and employee conduct

  • Background checks: Background checks are completed for new hires before they receive access to customer data, where the law allows.
  • Confidentiality: All employees must sign a confidentiality agreement.
  • Acceptable use: Personnel must adhere to the Acceptable Use Policy.
  • Standards of conduct: All personnel acknowledge the general standards of conduct in the Acceptable Use Policy at hire and each year.

3. Who is trained and when

AudienceTrainingDeadline
All new employees and contractors with access to Company systemsFull curriculum in section 4, plus the Acceptable Use Policy and the information security policiesWithin 30 days of their start date
All employees and contractorsFull curriculum in section 4, refreshed with any new threats, incidents or policy changes from the past yearOnce every 12 months
Engineers and anyone with production access to the production cloud environmentSecure development topic in section 4, in addition to the full curriculumWithin 30 days of being granted production access, then once every 12 months
Anyone involved in a security incident caused by human error, or who fails a phishing simulation twice in a rowTargeted refresher on the relevant topicWithin 14 days

The [People owner role] tells the [Security owner role] of every new starter so that training is assigned in their first week. Access to Restricted data is not granted until the person has completed training.

4. What the training covers

TopicWhat it covers
Phishing and social engineeringRecognizing phishing emails, texts and calls; checking sender and link details; payment and gift card fraud; reporting a suspected phish instead of deleting it.
Passwords and multi-factor authenticationUnique passwords for every account; using the Company password manager; enabling multi-factor authentication; never sharing credentials or approving unexpected login prompts.
Data classification and handlingThe four levels in the Data Classification and Retention Policy; where Restricted and Confidential data may be stored and shared; keeping customer data from the Company's product out of personal accounts and public AI tools.
Device securityKeeping laptops updated and encrypted; screen lock; approved software only; working safely on public Wi-Fi; what to do with a lost or stolen device.
Acceptable use of company systemsBusiness use of the Company's approved systems; limited personal use; monitoring; prohibited activity.
Incident reportingWhat counts as an incident; how and where to report within 1 hour; not investigating alone; the no-blame reporting rule.
Physical and remote working securityProtecting screens and conversations in public and at home; locking devices away; handling visitors and printed material.
Secure development (engineers only)The most common web application risks and how the Company prevents them; secrets management; code review; safe handling of production data in the production cloud environment.

5. Recording completion

Training is delivered through [Training method]. Every completion is recorded in the training log with the person, the training, the date and the result, and signed policy acknowledgments are filed with it. The [Security owner role] checks the log each month against the current staff list.

6. When training is overdue

  1. A person who is overdue receives a reminder from the [Security owner role] with a 7-day deadline.
  2. If still overdue after 7 days, the matter is escalated to their manager and the [People owner role].
  3. If still overdue after 14 days, access to Restricted and Confidential data and to production systems is suspended until training is complete.
  4. Repeated or deliberate non-completion is handled as a breach of the Acceptable Use Policy.

7. Performance management

Employee performance is formally reviewed at least annually to ensure competence and alignment with their responsibilities.

8. Sanctions

A disciplinary process, documented in [Disciplinary process document], is in place for violations of security policies.

9. Leaving the Company

When a person leaves, access is removed under the Access Control Policy and the offboarding checklist, Company equipment is returned, and confidentiality obligations continue after the last day.

10. Roles and responsibilities

RoleHeld byResponsibility
Policy approver[Policy approver role]Approves this policy, each new version, and any risk the Company accepts instead of meeting it.
Policy owner[Security owner role]Maintains this policy, makes sure the controls in it operate, keeps the evidence, and reviews it at least once a year.
People owner[People owner role]Runs background checks, onboarding, acknowledgments and the disciplinary process.
All personnelEveryone in scopeFollow this policy and report a suspected breach of it to the [Security owner role].

11. Evidence and records

The records below show that this policy operates. Each is dated, kept for at least [Evidence retention period], and stored where an auditor can be given it.

RecordWhat it showsWhere it is kept
Approved policyThis document, signed by the approver, with its version history.[Documentation system]
Training completionRecords of security awareness training.[Human resources system]
Signed acceptable use acknowledgmentEach person confirms the Acceptable Use Policy at hire and each year.[Human resources system]
Background check confirmationsA completed check for each new hire, without the report contents.[Human resources system]

12. Exceptions and enforcement

A deviation from this policy needs a written exception approved by the [Security owner role] before it begins. Each exception records the rule not met, the business reason, the compensating control and an expiry date no more than 12 months away. Exceptions are reviewed at each annual review.

A breach of this policy is handled under the Company disciplinary process and may lead to action up to and including termination of employment or contract. A breach that exposes customer data is also handled as a security incident.

13. Review and approval

The [Security owner role] reviews this policy at least once a year and after any significant change to the business, the systems in scope or the risks they face. The [Policy approver role] approves each version. Personnel are told of material changes and acknowledge the current version.

VersionDateSummary of changeApproved by
[Version][Effective date]First version.[Policy approver role]

Sign-off. Name, signature and date for: Policy approver.

14. Fields to complete

Replace every bracketed field in this document with your own detail, then delete this section.

FieldWhat to enter
[Company name]Your legal company name.
[Effective date]The date the approver signs this version.
[Version]Start at 1.0 and increase it each time the document changes.
[Security owner role]The role that runs the security program day to day, for example Chief Technology Officer.
[Policy approver role]The officer who approves policies and accepted risks, for example Chief Executive Officer.
[Documentation system]Where policies and procedures are published, for example the company wiki.
[In-scope personnel]Who the policy covers, for example employees and contractors with access to company systems.
[Human resources system]Where start and end dates are recorded.
[Evidence retention period]How long audit evidence is kept, for example three years.
[Training method]How training is delivered, for example a recorded session with a quiz.
[Disciplinary process document]Where the disciplinary process is written down, for example the employee handbook.
[People owner role]The role that runs hiring and departures, for example head of people.
[Next review date]The date this version must be reviewed by, at most 12 months after the effective date.

How to adapt it in an afternoon

  1. Decide how training is delivered. A recorded session and a quiz form is enough. Write the method into section 5.
  2. Check the background check rule. Where the law limits checks, write what you do instead.
  3. Open the training log. One row per person per training, with the proof linked.
  4. Train everyone once. Before the audit period opens, so every current person has a completion on record.
  5. Approve it. Then put the monthly log check in the calendar.

What produces a finding

A new hire trained after the deadline. A contractor with production access and no training record. A policy that promises phishing simulations nobody ran. When someone leaves, access removal runs through the offboarding checklist, and the rules they acknowledged at hire are in the acceptable use policy. SOC 2 for a small team covers how training works when the trainer is also a founder, and the SOC 2 policy list shows the full set.

The version written for your company

Polara G.R.C. onboarding is $2,000 one time. It writes the thirteen policies in its pack, which cover security awareness training, from your intake answers, with your systems, owners and review dates named, for you to review and approve. No template passes an audit on its own, this one included. An independent licensed U.S. CPA firm tests whether the policy operated.

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

Does SOC 2 require security awareness training?
CC1.4 expects the company to attract, develop and keep competent people, and CC2.2 expects it to communicate security responsibilities internally. Training at hire and once a year, with a completion record, is the plainest evidence for both, and auditors sample it.
How often must employees complete security training for SOC 2?
The template sets within 30 days of starting and every 12 months after. The criteria do not fix the numbers, but whatever you write is tested, so a new hire trained on day 45 against a 30 day rule is an exception.
What evidence of training does an auditor want?
A record per person: name, training, date completed and result, with the certificate or screenshot behind it. The Excel training log on this page has those columns and a summary sheet for the completion rate.
Do contractors need security training?
If they have access to company systems, yes. The template treats contractors with access the same as employees, and so does the population an auditor samples from.
Is a training policy template enough for SOC 2?
No. An independent licensed U.S. CPA firm samples people who joined and people who were there all year, and asks for their completion records. The log, not the policy, carries that test.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1) NIST. Designing and recording security awareness training. Checked 2 October 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.