HomeBlogSecurity Policy
Security Policy2026-07-12SecReadyNow

Security Awareness Training Policy: What It Should Cover

Cyber insurance underwriters and CMMC assessors both ask for a documented security awareness training policy. Most organizations do training - but do not have the policy. Here is what it needs to say.

A security awareness training policy is one of the most straightforward documents to get right - and one of the easiest to get wrong. Most organizations either have no policy (they do training but it is not documented), or they have a generic policy that does not reflect how training is actually run.

This guide covers what a defensible training policy should include, why it matters for compliance and insurance, and what the common gaps are.

Why a Written Policy Matters

Cyber insurance underwriters ask whether you have a documented security awareness training program in almost every application and renewal questionnaire. "We do training" is not the same as "we have a documented policy that specifies frequency, topics, roles, and consequences." The first is an assertion; the second is evidence.

For CMMC Level 2 contractors, Practices 3.2.1 through 3.2.3 require awareness training for all personnel, role-based training for those with elevated access, and insider threat training. Assessors look for the written policy as evidence that the program is structured and repeatable - not just that you sent out one email about phishing in 2023.

What the Policy Must Define

New Hire Training Timeline

The policy should specify when new hires must complete initial security training. Best practice is before they are granted access to systems containing sensitive data. A common requirement is within 5 business days of the start date. Without a documented timeline, assessors (and insurers) have no way to know whether training actually happens before system access is granted.

Annual Refresher Requirement

Annual training is the baseline expectation from cyber insurance, CMMC, ISO 27001, SOC 2, and most regulatory frameworks. The policy should specify: what constitutes the annual training (topics, platform, minimum duration), who is responsible for assigning it, and the deadline for completion (typically within 12 months of the prior completion).

Role-Based Training Requirements

Not everyone needs the same training. A role-based training matrix documents which roles require additional or specialized training beyond the general annual requirement. Common role-specific training topics include:

Phishing Simulation Program

Many organizations do training but skip simulated phishing. Insurers and auditors increasingly ask about phishing simulations specifically - not just awareness training. The policy should define the simulation cadence (quarterly is the standard), the escalating difficulty approach (templates range from obvious to sophisticated), and what happens when someone fails (remedial training, not punishment).

Insider Threat Awareness

CMMC Practice 3.2.3 specifically requires insider threat awareness training. This covers recognizing behavioral indicators of insider risk, the process for reporting concerns, and the organization's monitoring rights. Many general security training platforms include an insider threat module - the policy needs to document that this topic is covered and who is required to complete it.

Training Completion Tracking

The policy should specify how completion is tracked and for how long records are retained. Training completion records are the primary evidence for CMMC assessments, cyber insurance audits, and SOC 2 reviews. "We track it in the LMS" is acceptable; "we don't have a formal tracking process" is not.

Consequences for Non-Completion

A policy without teeth is a suggestion. The document should specify what happens when required training is not completed by the deadline: first, a reminder from the manager; then escalation to HR; then, in the most serious cases, suspension of system access until completion. The consequence language does not need to be harsh - it just needs to exist and be enforced.

Common Gaps That Surface During Audits

What Training Platform to Use

The policy should be platform-agnostic - it defines what training is required, not how it is delivered. Common platforms include KnowBe4, Proofpoint Security Awareness, Infosec IQ, and Microsoft Security training. Smaller organizations sometimes use internally developed training or free CISA resources. Any of these can satisfy a well-written policy as long as the platform can produce completion records.

Security Awareness Training Policy Template

Covers new hire timelines, annual refreshers, quarterly phishing simulations, role-based matrix, and training calendar. Editable .docx, instant download.

Get the Template - $49

Frequently Asked Questions

CMMC Practice 3.2.1 requires security awareness training for all personnel. It does not specify a frequency, but annual training is the defensible baseline that assessors expect to see documented and evidenced. Some organizations do semi-annual training for higher-risk roles.
CMMC does not explicitly require phishing simulations by name, but Practice 3.2.1 requires training that addresses security risks associated with user activities - which assessors often interpret to include phishing simulation as evidence of an active awareness program. Cyber insurance underwriters are more explicit: many renewal questionnaires now ask specifically whether you run phishing simulations.
CMMC Practice 3.2.3 requires organizations to train personnel to recognize and report potential insider threat indicators - behaviors that might suggest a colleague is a security risk. This includes unusual access patterns, downloading large volumes of data, circumventing security controls, and behavioral warning signs. The training requirement exists because insider threats are among the most damaging and hardest to detect.
No. Best practice is to keep the policy platform-agnostic by defining requirements (topics, frequency, roles, completion tracking) rather than naming a specific vendor. This makes the policy more durable - if you switch platforms, you do not need to update the policy.
Keep training completion records for at least 3 years. CMMC assessors look back through your records to verify that training is happening consistently. Cyber insurance underwriters may ask for completion records during renewal. Some regulatory frameworks require longer retention - check the requirements specific to your industry and contracts.

Related Resources

Keep going - these are worth reading next.

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, no spam.