How long does security awareness training take to complete?

Security awareness modules typically run 3-10 minutes for microlearning and 45-60 for annual compliance courses. See what the evidence says about duration, retention and completion.

A short security awareness module takes most people three to ten minutes to complete; a full-length compliance course typically runs 45 to 60 minutes; and a structured programme — short monthly modules plus occasional phishing simulations — adds up to roughly 60 to 90 minutes of an employee's entire year. The duration question matters less for the calendar than for the outcome: shorter, repeated lessons are consistently shown to be completed more often and retained better than one long annual session.

TL;DR

Typical completion times by format

FormatTypical lengthWhen it's used
Microlearning module3-10 minutesMonthly topic refreshers
Phishing simulation lesson3-5 minutesAuto-assigned after a simulated click
Onboarding course30-60 minutesNew-starter induction
Annual compliance course45-60 minutesRegulator or insurer requirements
Tabletop / workshop session60-90 minutesIncident-response rehearsal

For planning purposes, a practical rule: budget ten minutes per microlearning module, allow an hour for onboarding, and expect the annual compliance block — if your industry still requires one — to consume most of its hour per person, once a year.

Why duration matters more than it looks

Completion collapses as length grows. Anyone who has run an LMS knows the pattern: short modules assigned monthly are finished by nearly everyone; a 45-minute annual course sits in inboxes for weeks. The completion gap between short and long formats is one of the most replicated observations in workplace learning, and it matters because uncompleted training has a retention rate of exactly zero.

The forgetting curve erodes long courses first. Memory research going back to Ebbinghaus shows rapid initial forgetting that repetition flattens. A single annual session fights that curve with one repetition per year. Short modules repeated monthly align repetitions with the decay curve instead of racing it.

Behaviour decays after training too. A large study of nearly 20,000 healthcare employees across eight months of phishing simulations found that the protective effect of annual security awareness training faded measurably in the months after completion — employees who had recently completed training failed simulations less, and the effect weakened as time passed (Grantho et al., IEEE S&P 2025). The implication is direct: if your only training is annual, its effect is decaying for most of the year.

Repetition in simulation beats one-off instruction. In a hospital phishing-simulation case study, click rates fell significantly across successive rounds of campaigns (published in PMC) — for custom lures, from 55% in the first round to 21% in the second. Repeated, spaced exposure is itself the training mechanism.

How long your programme should be per person

For a small or mid-sized business, a defensible annual time budget looks like this:

Total: around two hours per employee per year, spread across the calendar — and none of it requiring anyone to block out an afternoon. That cadence is also what phishing programmes like Cyber Aware's simulations assume: a monthly rhythm where the training arrives in small doses the team actually finishes.

What stretches completion time (and what to do about it)

Measuring it properly

Duration is an input, not an outcome. Two numbers tell you more than any single completion stat:

Both live in your human risk reporting, which is also what auditors and insurers increasingly ask to see: not that training happened, but that it changed something measurable.

FAQ

How long is a typical security awareness training course? A microlearning module runs 3-10 minutes; a phishing-simulation remediation lesson is about 3-5 minutes; a full onboarding or annual compliance course typically runs 45-60 minutes.

How much total time should an employee spend on security training per year? For most small and mid-sized teams, roughly 60-95 minutes of training plus 3-5 minutes per simulation lesson — achievable with a monthly microlearning cadence rather than one long annual session.

Is a long annual course better than short monthly ones? For retention and behaviour, no. The forgetting curve erodes annual training within months, and studies of repeated phishing simulations show click rates falling with spaced exposure — something an annual event cannot produce.

Do shorter modules actually get completed? Yes — completion is the main practical advantage of microlearning; short modules fit into a working day, while long courses sit overdue and inflate backlog metrics.

Can training be too short to matter? A module can be too short to change understanding, which is why the healthy signal is a normal completion time paired with improving simulation results — and why abnormally fast completions should be flagged rather than celebrated.

How do we prove completion time to an auditor? Export time-on-course and completion data from your platform; human risk reporting is built to export exactly that per learner and per course.

One last thing

The right question is not "how long should training be?" but "how often does it repeat?" A three-minute module that appears twelve times a year beats a sixty-minute course that appears once — in completion, in retention, and in the click-rate trend you can actually show an auditor.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.