Security Awareness Training Policy: What It Should Cover
Cyber insurance underwriters and CMMC assessors both ask for a documented security awareness training policy. Most organizations do training - but do not have the policy. Here is what it needs to say.
A security awareness training policy is one of the most straightforward documents to get right - and one of the easiest to get wrong. Most organizations either have no policy (they do training but it is not documented), or they have a generic policy that does not reflect how training is actually run.
This guide covers what a defensible training policy should include, why it matters for compliance and insurance, and what the common gaps are.
Why a Written Policy Matters
Cyber insurance underwriters ask whether you have a documented security awareness training program in almost every application and renewal questionnaire. "We do training" is not the same as "we have a documented policy that specifies frequency, topics, roles, and consequences." The first is an assertion; the second is evidence.
For CMMC Level 2 contractors, Practices 3.2.1 through 3.2.3 require awareness training for all personnel, role-based training for those with elevated access, and insider threat training. Assessors look for the written policy as evidence that the program is structured and repeatable - not just that you sent out one email about phishing in 2023.
What the Policy Must Define
New Hire Training Timeline
The policy should specify when new hires must complete initial security training. Best practice is before they are granted access to systems containing sensitive data. A common requirement is within 5 business days of the start date. Without a documented timeline, assessors (and insurers) have no way to know whether training actually happens before system access is granted.
Annual Refresher Requirement
Annual training is the baseline expectation from cyber insurance, CMMC, ISO 27001, SOC 2, and most regulatory frameworks. The policy should specify: what constitutes the annual training (topics, platform, minimum duration), who is responsible for assigning it, and the deadline for completion (typically within 12 months of the prior completion).
Role-Based Training Requirements
Not everyone needs the same training. A role-based training matrix documents which roles require additional or specialized training beyond the general annual requirement. Common role-specific training topics include:
- IT / System Administrators: Privileged access management, configuration security, vulnerability management
- Finance / Accounts Payable: Business email compromise, wire fraud prevention, invoice fraud
- HR: Phishing via job applications, social engineering, handling sensitive employee data
- Executives: Whaling attacks, impersonation, deepfake voice and video fraud
- Help Desk: Vishing (voice phishing), caller authentication, social engineering resistance
Phishing Simulation Program
Many organizations do training but skip simulated phishing. Insurers and auditors increasingly ask about phishing simulations specifically - not just awareness training. The policy should define the simulation cadence (quarterly is the standard), the escalating difficulty approach (templates range from obvious to sophisticated), and what happens when someone fails (remedial training, not punishment).
Insider Threat Awareness
CMMC Practice 3.2.3 specifically requires insider threat awareness training. This covers recognizing behavioral indicators of insider risk, the process for reporting concerns, and the organization's monitoring rights. Many general security training platforms include an insider threat module - the policy needs to document that this topic is covered and who is required to complete it.
Training Completion Tracking
The policy should specify how completion is tracked and for how long records are retained. Training completion records are the primary evidence for CMMC assessments, cyber insurance audits, and SOC 2 reviews. "We track it in the LMS" is acceptable; "we don't have a formal tracking process" is not.
Consequences for Non-Completion
A policy without teeth is a suggestion. The document should specify what happens when required training is not completed by the deadline: first, a reminder from the manager; then escalation to HR; then, in the most serious cases, suspension of system access until completion. The consequence language does not need to be harsh - it just needs to exist and be enforced.
Common Gaps That Surface During Audits
- No documented timeline for new hire training (training happens but timing is ad hoc)
- Annual training exists but the policy does not define what it covers
- Role-based training matrix not documented - just general training for everyone
- No phishing simulation program, or simulations happen but are not tracked against the policy
- Insider threat training not specifically addressed
- Training completion records not retained long enough (CMMC assessors want to see at least a year of records)
What Training Platform to Use
The policy should be platform-agnostic - it defines what training is required, not how it is delivered. Common platforms include KnowBe4, Proofpoint Security Awareness, Infosec IQ, and Microsoft Security training. Smaller organizations sometimes use internally developed training or free CISA resources. Any of these can satisfy a well-written policy as long as the platform can produce completion records.
Security Awareness Training Policy Template
Covers new hire timelines, annual refreshers, quarterly phishing simulations, role-based matrix, and training calendar. Editable .docx, instant download.
Get the Template - $49Frequently Asked Questions
Related Resources
Keep going - these are worth reading next.