Compliance · SOC 2
SOC 2 security awareness training requirements CC2.2 explained
SOC 2 does not prescribe a training course. The AICPA’s Trust Services Criteria include a point of focus under CC2.2 about communicating security knowledge and awareness to personnel “through a security awareness training program”, and your auditor decides what evidence is enough.
Here is the wording, what points of focus are, and the evidence SecurityRing gives you for the audit period.
Last reviewed 10 October 2026 against the official texts. Not legal advice.
The short answer
SOC 2 in three lines
Who it applies to
Service organisations that have a SOC 2 examination by an independent CPA firm against the AICPA Trust Services Criteria. The Security criteria are part of every SOC 2 report.
What it asks on awareness training
A CC2.2 point of focus: communicate information to improve security knowledge and awareness through a security awareness training programme.
Where phishing simulation fits
It helps you show training and resilience across the audit period. SOC 2 names a security awareness training programme, not phishing simulation, and points of focus are guidance rather than checklist items.
Who it applies to
Who has to follow SOC 2
SOC 2 is an attestation report, not a certification: an independent CPA firm examines your controls against the Trust Services Criteria and reports. A Type 2 report covers how controls operated over a period, so awareness evidence has to span that period rather than a single date.
Customers usually ask for the report as part of vendor due diligence.
What it asks for
What SOC 2 asks for on awareness training
The clauses that matter, with their numbers. “Official wording” is quoted exactly; “Our paraphrase” is our summary in plain words.
CC2.2 (COSO Principle 14)Official wording
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
CC2.2 point of focusOfficial wording
Communicates Information to Improve Security Knowledge and Awareness — The entity communicates information to improve security knowledge and awareness and to model appropriate security behaviors to personnel through a security awareness training program.
CC1.4 (COSO Principle 4), relatedOfficial wording
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
AICPA on points of focusOur paraphrase
Points of focus “represent important characteristics of the criteria” and “may assist” management and the auditor in judging whether controls were suitably designed and operated effectively. They do not change the criteria.
Phishing simulation
Why phishing simulation helps
Phishing simulation lets you show that people were trained and that they were tested. Four reasons it helps come first; then, so you are not misled, we say exactly what the framework text itself asks for.
Test
A realistic simulated attack
SecurityRing sends a realistic simulated attack to your employees.
Teach
A short lesson after the click
A short lesson opens straight after the click, designed to take under two minutes.
Evidence
A report a reviewer can read
Campaign report, completion records, trend report and audit trail, exported as PPT, PDF or CSV.
Campaign results
Evidence for SOC 2 review
- People tested
- Opened
- Clicked
- Completed the lesson
In the report
- Completion records
- Trend report
- Audit trail
Export as
- PPT
- CSV
Show training and resilience
Employees are tested with realistic attacks, not only shown a course. Your reports show who was tested, how they behaved and what followed, so you can evidence resilience as well as training.
Faster, with less chasing
A simulation reaches people in their inbox. There is no long course to schedule and no constantly chasing employees to finish it, so your time goes where it is needed.
A short lesson at the right moment
When someone clicks, a short lesson opens straight away on the exact attack they just met, designed to take under two minutes. That saves you and your employees time compared with a long course.
Reports a reviewer can read
The campaign report, per-person completion records, executive trend report and dated audit trail, exported as PPT, PDF or CSV, serve as evidence of security training and phishing awareness and of actual resilience testing. Offer them alongside your other evidence.
A Type 2 report covers how a control operated over a period. Recurring simulations give dated, measurable results across that period, so your awareness control produces evidence your auditor can sample: campaign reports, completion records for the people who clicked, the executive trend report and the interaction audit trail.
What SOC 2 says
SOC 2 names a security awareness training programme, not phishing simulation.
How often you train, in what format, and how you show it works are for you to define in your own controls, and for your auditor to test.
Adding phishing simulations is a choice about your control design; the criteria do not ask for it.
Evidence from SecurityRing
Evidence for SOC 2 from SecurityRing
SecurityRing gives evidence for the awareness-training control across your audit period. This is how its outputs line up.
| What SOC 2 asks | Evidence from SecurityRing |
|---|---|
| A security awareness training programme (CC2.2 point of focus) | Campaign reports and per-person completion records, dated within your examination period. |
| The control operated across the period (Type 2) | Recurring campaigns you schedule, with dated reports, and an executive trend report over a six-month lookback. |
| Evidence the auditor can sample | The interaction audit trail and CSV, PPT or PDF exports of reports and completion records. |
What SecurityRing produces
- Campaign report. For each campaign: sent, opened, clicked, video completed and training completed, time to action, results by department, location, seniority and manager cohort, repeat exposure and recommended follow-up.
- Completion records. A per-person roster for each campaign, with drill-downs, showing who was phished, who finished the lesson and when. The lesson goes to people who act on a simulation, so this is not a record of training for your whole workforce.
- Executive trend report. Across campaigns over a six-month lookback: phishing exposure score, trends by department and senior management, response speed and a 30-day action plan.
- Audit trail. A dated interaction audit trail for each campaign: what each recipient did and when.
- PPT, PDF and CSV export. Download the campaign and executive trend reports as PPT, PDF or CSV for your auditor, or present them on screen.
What it does not do
- SecurityRing’s reports are not mapped to SOC 2 criteria, and a SOC 2 report is issued by a CPA firm, not by a tool.
- Training on phishing and deepfake attacks is one control. The other criteria in the Security category are outside SecurityRing.
- SecurityRing’s lesson goes to people who click or submit in a simulation, not to every employee. Where a requirement covers all staff, keep your baseline training programme and use SecurityRing for simulation results and follow-up.
- SecurityRing’s reports are not mapped to SOC 2 clause numbers. You decide which report supports which clause, and your auditor decides whether it is enough.
This page is a plain-language summary for GRC teams, not legal advice. SecurityRing gives you evidence for the awareness-training part of a framework and helps you demonstrate it. Using SecurityRing does not make you compliant, it is not a certification, and no regulator or standards body endorses it. Your auditor or regulator decides whether the evidence is enough.
Does SOC 2 require security awareness training?
SOC 2 does not prescribe a specific programme. CC2.2 includes a point of focus about communicating security knowledge and awareness to personnel through a security awareness training programme. Points of focus are guidance, not checklist items, so your auditor decides what evidence of training is sufficient for your system.
How does phishing simulation help with SOC 2, and is it required?
Recurring simulations give dated, measurable results across your audit period, which helps you show both training and resilience. The Trust Services Criteria name a security awareness training programme and do not mention phishing simulation, so whether you add simulations is part of your own control design, and your auditor tests the control you describe.
What SOC 2 evidence can SecurityRing provide?
Dated campaign reports, per-person completion records, an executive trend report over a six-month lookback and an interaction audit trail, exported as PPT, PDF or CSV. They give evidence that your awareness control operated across the period. They are not mapped to SOC 2 criteria, and your auditor decides what is enough.
Does SecurityRing make us SOC 2 compliant?
No. A SOC 2 report is an attestation by an independent CPA firm about your controls. SecurityRing helps you demonstrate the awareness-training control with evidence, it is not a certification, and no standards body endorses it.
Sources and how we checked
Last reviewed 10 October 2026. Criteria and point-of-focus wording are from the AICPA 2017 Trust Services Criteria with revised points of focus (2022). Our statement about points of focus paraphrases AICPA’s background section. Your auditor may apply a more recent AICPA update.
See the evidence your SOC 2 reviewer will read
Book a demo to see how a campaign report, completion records and the executive trend report would look for your team, and how they line up with SOC 2.