Compliance · ISO 27001
ISO 27001 security awareness training requirements Annex A 6.3 and clauses 7.2 and 7.3
ISO/IEC 27001:2022 asks for awareness in two places: the mandatory clauses 7.2 and 7.3, and the Annex A control 6.3, “Information security awareness, education and training”.
The standard does not name phishing simulation, but simulation helps you show it. Here is what each clause asks for, why simulation helps, and the evidence SecurityRing gives you for your auditor.
Last reviewed 10 October 2026 against the official texts. Not legal advice.
The short answer
ISO 27001 in three lines
Who it applies to
Organisations that run an information security management system (ISMS) to ISO/IEC 27001:2022, usually to be certified by an accredited certification body.
What it asks on awareness training
Awareness of the policy and your contribution to the ISMS (7.3), competence evidenced by training (7.2), and awareness, education and training relevant to each role (Annex A 6.3).
Where phishing simulation fits
It helps you show training and resilience. ISO/IEC 27001 does not name phishing simulation; you choose the method and justify it through your risk treatment.
Who it applies to
Who has to follow ISO 27001
Clauses 4 to 10, including 7.2 and 7.3, apply to every ISMS that claims conformity. The Annex A controls are chosen through your risk treatment and recorded in your Statement of Applicability, with a justification for any control you leave out.
ISO/IEC 27001 is a licensed standard, so this page paraphrases the requirements instead of quoting them.
What it asks for
What ISO 27001 asks for on awareness training
The clauses that matter, with their numbers. “Official wording” is quoted exactly; “Our paraphrase” is our summary in plain words.
Annex A 6.3, Information security awareness, education and training (control)Our paraphrase
Personnel of the organisation and relevant interested parties receive appropriate awareness, education and training, and regular updates of the information security policy, topic-specific policies and procedures, as relevant for their job function.
Clause 7.3, AwarenessOur paraphrase
People doing work under the organisation’s control must be aware of the information security policy, of their contribution to the effectiveness of the ISMS, and of the implications of not conforming with its requirements.
Clause 7.2, CompetenceOur paraphrase
Determine the competence people need, ensure they are competent through appropriate education, training or experience, take actions to acquire competence and evaluate how effective those actions are, and retain documented information as evidence of competence.
Phishing simulation
Why phishing simulation helps
Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.
Test
A realistic simulated attack
SecurityRing sends a realistic simulated attack to your employees.
Teach
A short lesson after the click
A short lesson opens straight after the click, designed to take under two minutes.
Evidence
A report a reviewer can read
Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.
Campaign results
Evidence for ISO 27001 review
- People tested
- Opened
- Clicked
- Completed the lesson
In the report
- Completion records
- Trend report
- Audit trail
Export as
- PPT
- CSV
Show training and resilience
Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.
Faster, with less chasing
A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.
A short lesson at the right moment
When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.
Reports a reviewer can read
The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.
Clause 7.2 asks you to evaluate how effective your actions are and to retain documented information as evidence. Simulation results by department and the executive trend report show whether exposure is falling when people are tested, the completion records show which of the people who clicked finished the lesson, and dated exports and the audit trail go into your ISMS records.
What ISO 27001 says
The standard does not name phishing simulation, a frequency or a format.
It asks for appropriate awareness, education and training. What counts as appropriate is for you to decide and justify in your risk treatment, and for your certification auditor to assess.
Evidence from SecurityRing
Evidence for ISO 27001 from SecurityRing
SecurityRing gives evidence for the phishing and deepfake awareness part. This is how its outputs line up.
| What ISO 27001 asks | Evidence from SecurityRing |
|---|---|
| Awareness, education and training relevant to the job (Annex A 6.3) | Campaign reports and per-person completion records showing who clicked, on which attack, the result, and whether they finished the lesson. |
| Evaluate the effectiveness of actions taken (clause 7.2(c)) | Campaign results by department, and the executive trend report showing whether exposure is falling over time. |
| Retain documented information as evidence (clause 7.2(d)) | Dated exports (PPT, PDF, CSV) and the interaction audit trail for your ISMS records. |
| Awareness of the policy and consequences of non-conformity (clause 7.3) | Not covered by SecurityRing. Lessons teach people to spot and handle the attack they missed; they do not record acknowledgement of your policy. |
What SecurityRing produces
- Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
- Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
- Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
- Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
- PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.
What it does not do
- SecurityRing does not record policy acknowledgement, so clause 7.3(a) needs your own process alongside it.
- SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
- SecurityRing’s reports are not mapped to ISO 27001 clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
- ISO/IEC 27001 certification is awarded by an accredited certification body after an audit of your ISMS. SecurityRing is not a certification and is not endorsed by ISO.
This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.
Is security awareness training mandatory for ISO 27001?
Awareness is part of the standard. Clauses 7.2 (competence) and 7.3 (awareness) are mandatory for conformity, and Annex A 6.3 covers awareness, education and training unless you justify excluding it in your Statement of Applicability. The standard does not prescribe a format or frequency.
How does phishing simulation help with ISO 27001, and is it required?
Simulation results help you show both training and resilience, and clause 7.2 asks you to evaluate how effective your actions are. ISO/IEC 27001 asks for appropriate awareness, education and training for each role and does not name phishing simulation, so it is not required by name. Your certification auditor judges whether your approach is appropriate.
What ISO 27001 evidence can SecurityRing provide?
Dated campaign reports and per-person completion records showing who was trained and the results, an executive trend report showing change over time, and an audit trail, exported as PPT, PDF or CSV. They give evidence for Annex A 6.3 and clause 7.2. They are not mapped to clause numbers.
Does SecurityRing make us ISO 27001 certified?
No. Certification is awarded by an accredited certification body after it audits your ISMS. SecurityRing helps you demonstrate the awareness-training part with evidence, it is not a certification, and ISO does not endorse it.
Sources and how we checked
Last reviewed 10 October 2026. Clause and control wording was checked against a copy of ISO/IEC 27001:2022 on 10 October 2026. Because the standard is licensed, only the control title is quoted and the requirements are paraphrased. Buy the standard from ISO or a national body to read the exact text.
See the evidence your ISO 27001 reviewer will read
Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with ISO 27001.