Thought Leadership

SOC 2 Type II Security Awareness Training: What Auditors Really Check

September 25, 2026

Your sales team needs a SOC 2 report to close a deal that’s been sitting in procurement for weeks. You know security awareness training shows up somewhere in the Trust Services Criteria. It’s on every readiness questionnaire you’ve filled out. What you don’t know is what your auditor is going to test, and fieldwork is a rough time to find out.  

Here’s the good news: The answer isn’t vague. Once you know where SOC 2 compliance training requirements come from, the rest is easy. Training lives in two places in the Criteria, and how you prove it depends entirely on whether you’re pursuing a SOC 2 Type I or Type II report. 

Where training lives in the SOC 2 Trust Services Criteria

The COSO (Committee of Sponsoring Organizations) framework underlies the SOC 2 Trust Services Criteria. Nine common Criteria apply to every SOC 2 report, and you can add four more categories depending on what your customers ask for. Security is the only one that’s mandatory, and it’s the one that matters here.  

Training doesn’t get its own dedicated criterion. It shows up inside two of the nine categories. CC1.4 security awareness requirements sit inside the Control Environment and require you to demonstrate a commitment to competence: People actually understand what’s expected of them and have what they need to meet it.  

CC2.2 lives under Communication and Information, and it’s more specific. It requires you to communicate security policies and individual responsibilities clearly enough that your controls can actually work as designed. 

That’s the complete picture of SOC 2 security awareness requirements. There’s no separate training clause hiding somewhere else. 

Type I vs. Type II: Why timing is the whole story

A SOC 2 Type I report asks one question: Were your controls designed correctly on a given date? Type II asks a harder one: Did those controls actually work, consistently, over a stretch of time? 

For SOC 2 Type II audit training specifically, that difference decides everything. Say your company ran a solid onboarding session back in January and hasn’t touched training since. A Type I auditor looking at your program in February might sign off.

A Type II auditor won’t, because they’re not checking a moment; they’re sampling across the whole monitoring window, which commonly runs 3-6 months for the first Type II audit and settles into 12 months for renewals after that.  

Picture a mid-sized SaaS company gearing up for its first Type II audit. Their compliance lead pulls up their training records expecting a straightforward export. Instead, they find three different tools: An LMS report from Q1, a spreadsheet someone updated by hand in Q2, and a folder of email confirmations for the rest of the year.  

Nothing lines up by date, and nobody can say for certain who completed what in month nine. That’s not a training problem. It’s an evidence problem, and it’s the single most common way an otherwise well-run program stumbles during fieldwork.  

What auditors want to see

Saying “we did training” isn’t evidence. When auditors sample against CC1.4 and CC2.2, it usually comes down to three things. This is what auditors mean by SOC 2 audit evidence: 

  • Written policy that spells out who’s in scope  
  • What curriculum covers 
  • How often training runs 
  • How training is delivered 
  • What happens when someone misses a session 

A policy that only lives in someone’s head doesn’t survive sampling. Auditors want to see that the curriculum actually connects to your risk assessment, so if phishing and credential theft are your top concerns, the training content should visibly reflect that rather than reading like generic material any company could have licensed.  

Auditors also want per-person, timestamped completion records spread across the entire observation period, not a single completion percentage pulled at the end of the year.  

That last request trips people up more than the other two combined.  

Why completion rate isn’t the number that matters

A 98% completion rate feels like proof that the control is working, but it isn’t (at least not to an auditor). Completion rate tells you people clicked through something at some point.  

It doesn’t tell you training ran on a consistent cadence; that the content matched your actual risk profile; or that you can hand over dated, individual evidence for month three and month nine of your window, not just the month you happened to run a big push before the audit.  

The programs that get you through Type II fieldwork without drama aren’t the ones with the highest completion numbers. They’re the ones that never had to scramble to reconstruct a year’s worth of records from three different systems.   

What actually closes the gap

None of this requires a more elaborate training program. It requires a provable one: 

  • Write the policy down and keep it current.  
  • Map your curriculum to your risk assessment, so an auditor can trace the connection without explaining it out loud.  
  • Run training on a rhythm that actually spans your observation window instead of front-loading it.  
  • Make sure completion records are dated and attributable to individuals from day one, not stitched together after the fact.  

This is the same thinking behind NINJIO’s CISO’s Guide to Cybersecurity Awareness Training: The human side of security is where most breaches start. It’s also where the strongest evidence of a working program comes from.   

One thing to check this week

Pull your last training export and look at it honestly. Does it show dated, individual completion records spanning your full observation window, or does it show one completion percentage from a push you ran months ago? That answer will tell you more about your Type II readiness than any checklist could. 

If your team is also evaluating platforms, the real question isn’t whether a platform offers training — they all do. It’s whether it automatically produces dated, per-person, continuous records, or whether your team ends up assembling that picture by hand every audit cycle.   

Frequently Asked Questions

Yes, though not as a standalone requirement. It’s built into CC1.4 and CC2.2 of the Common Criteria, covering competence and communication rather than sitting under its own dedicated control.

It requires proof that training happened consistently across the entire observation period, typically 6-12 months, not just that it happened once. That means dated, per-person completion records, not a single completion percentage.

Type I checks whether you designed your training program correctly on one date. Type II checks whether the program actually ran, consistently, across months of sampling. A program can pass Type I and still fail Type II if it isn’t ongoing.

With a written policy defining scope and cadence, curriculum mapped to your risk assessment, and individual completion records timestamped across your full observation window. All three need to hold up to sampling, not just exist somewhere.

Ready to reduce your organization’s human risk?