Skip to content
AwareSprint

SOC 2 · Personnel and internal communication

SOC 2: evidencing security awareness across the observation window

SOC 2 does not hand you a checklist. The criteria expect the organisation to attract and retain competent people and to communicate its security commitments internally, and an auditor decides whether what you did was sufficient. Awareness training is where most organisations answer both.

What it actually asks for

Competent personnel
The criteria speak to attracting, developing and retaining people competent to meet the objectives. Training is the usual demonstration that competence is maintained and not just hired for.
Internal communication of commitments
They also expect internal communication of security objectives and responsibilities. People have to be told what is expected of them in a way you can show.
Consistent through the observation window
A Type II report covers a period, often six or twelve months. One training event in month one does not evidence a control that operated throughout.
Applied to everyone in scope
Contractors and anyone with system access generally fall inside the boundary. Auditors sample across the whole population, not just full time staff.

Where organisations come unstuck

Type I is a snapshot and forgiving. Type II asks whether the control operated consistently across the period, and a single annual session leaves ten months with no evidence. Auditors sample joiners in particular, because onboarding is where the trail usually breaks.

The evidence to keep

  • Completion records spread across the observation window, not clustered on one date
  • Evidence that new joiners were trained close to their start date
  • The population the training applied to, and who inside it did not complete
  • Content showing what security responsibilities were actually communicated
  • An audit trail that shows records were not created after the auditor asked

How AwareSprint helps

AwareSprint runs short security challenges for your whole team and produces a completion register with dates, content versions and participation across the population. That is the record this clause asks you to produce. It does not make you compliant, and no platform can. It gives you the training evidence, so the rest of your programme is what your auditor spends time on.

Work email only. Nothing to install and no card required.

Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.

Registering your whole company?Use the company form

Other standards

FAQ

Questions

What teams ask about SOC 2 and awareness training.

Does SOC 2 name security awareness training as a requirement?

Not in those words. The criteria set objectives around competent personnel and internal communication, and your auditor decides whether your approach meets them. Awareness training is the most common way organisations satisfy both.

How often do we need to train for a Type II?

Often enough that the control demonstrably operated throughout the observation period. Annual training with nothing in between leaves long gaps an auditor may question, particularly for people who joined mid period.

Does using AwareSprint mean we pass SOC 2?

No. SOC 2 covers your whole control environment. AwareSprint produces the awareness training evidence, which is one part of the picture your auditor assesses.