A 12-month security awareness training calendar plan needs one theme per month, a monthly phishing simulation running underneath it, and at least one checkpoint where compliance deadlines get cross-checked against what staff actually completed. Most programs that fail their annual review didn't lack content — they scheduled everything reactively and missed the mid-year audit window.
TL;DR
- A security awareness training calendar plan works best with one theme per month plus a monthly phishing simulation running in parallel.
- Map compliance deadlines (ISO 27001, PCI DSS, the Notifiable Data Breaches scheme) before picking a single monthly topic.
- Onboarding and offboarding need their own track — new hires can't wait for the next quarterly cycle to start in 2026.
- Q3 is where most programs miss their mid-year audit checkpoint; that gap is the top reason annual reviews fail.
- Reserve Q4 for renewal, fatigue checks, and drafting next year's calendar before the current one closes.
Why this matters
An ad hoc training program looks fine until an auditor asks for evidence of completion dates tied to a specific control. Without a calendar, teams end up running three phishing simulations in March and none in July, then scrambling before a renewal deadline.
A written calendar also stops the most common complaint from staff: repeating the same content twice in one year. Once a person recognises a phishing template, a repeat run tells you nothing about awareness — it just tells you they remember an email.
How do you plan a 12-month security awareness training calendar?
Build the calendar in this order, not by picking topics first.
- Map every compliance deadline first. Pull dates for ISO 27001 Annex A control reviews, PCI DSS quarterly requirements, the Notifiable Data Breaches scheme, and APRA CPS 234 obligations if the business is regulated. Cyber Aware's guide on mapping training to ISO 27001 Annex A breaks down which controls need documented training evidence.
- Assign one theme per month. Twelve months, twelve distinct topics — phishing, password hygiene, physical security, vendor risk, business email compromise, and so on. No repeats inside the same calendar year.
- Layer phishing simulations independently of the monthly theme. Run one simulation a month at minimum, varying the lure so staff aren't just memorising a single template. A platform that automates scheduling removes the manual re-sending that causes most teams to skip a month.
- Build a parallel track for onboarding and offboarding. New hires and departing staff don't move on a quarterly clock, so their training needs to trigger on the hire or exit date, not the next scheduled month.
- Set four quarterly executive briefings. Tie each one to that quarter's theme and completion data so leadership sees a trend, not a single snapshot.
- Insert a mid-year audit checkpoint. Cross-check completion records against your written policy in Q3, before renewal season, not after.
Q1 (Jan-Mar): Onboarding and Fundamentals
Start 2026 with the basics: password hygiene, recognising phishing, and reporting a suspicious email. This is also the quarter to formalise your new employee onboarding training sequence, since January hiring cycles usually bring the year's first wave of new starters.
Keep Q1 content short. Long modules in the first quarter set the tone that security training is a chore, and that perception is hard to undo later in the year.
Q2 (Apr-Jun): Phishing and Social Engineering Deep Dive
April through June is the quarter to go beyond generic phishing emails. Cover vishing (voice phishing), business email compromise targeting payroll and finance teams, and fake calendar invite phishing — all social engineering variants that a generic annual module misses.
This is also the natural point to introduce a live-fire exercise: an unannounced phishing simulation with no advance warning, scored against your baseline click rate from Q1.
Q3 (Jul-Sep): Compliance and Audit Prep
July to September is your mid-year checkpoint. Pull completion reports against every compliance deadline mapped in step one, and flag any team below target before renewal negotiations start.
This is the quarter auditors ask about most, because it's the one program teams skip when a calendar wasn't planned in advance. A gap here in 2026 is far cheaper to fix in September than in December.
Q4 (Oct-Dec): Incident Response and Renewal
Close the year with incident response drills — simulated ransomware scenarios, breach communication exercises, and a review of how staff actually reported incidents during the year. This is also when training fatigue shows up most, since staff have completed 10-11 months of modules by October.
Use Q4 to draft next year's calendar while this year's data is still fresh — completion rates, click rates by department, and which months had the weakest engagement.
Build your 2026 training calendar
See how Cyber Aware schedules monthly themes and phishing simulations automatically.
Why the calendar varies month to month
No two organisations run an identical 12-month security awareness training calendar plan. The shape changes based on:
- Team size and structure — a 15-person business can run one theme across the whole company; a 500-person business often needs to segment by department risk.
- Regulatory load — a business tracking ISO 27001, PCI DSS, and the Notifiable Data Breaches scheme simultaneously needs more compliance checkpoints than one tracking none of them.
- Remote and distributed workforces — time zones and asynchronous work change how simulations get scheduled and how completion gets tracked.
- MSP multi-tenant management — an MSP running the calendar across multiple client tenants needs a template that scales, not a bespoke plan per client.
- Staff turnover and seasonal hiring — high-turnover industries need a heavier onboarding track relative to the rest of the calendar.
- Executive buy-in and budget cycle — quarterly reviews only work if leadership actually reads them; some businesses need monthly summaries instead.
Should new hires follow the same calendar as existing staff?
No — new hires need a compressed onboarding sequence that runs on their start date, not the next scheduled month on the annual calendar. A person hired in October shouldn't wait until the January refresh to get basic phishing and password training.
How many phishing simulations should run each month?
One phishing simulation a month is the practical minimum for a 12-month security awareness training calendar plan to generate usable trend data. Running fewer than 12 a year makes it hard to separate a genuine improvement in click rates from random monthly variation.
How do you know if the training calendar is working?
Completion rate alone doesn't tell you the calendar is working — track click rate trend across the full 12 months alongside how quickly staff report suspicious emails. A calendar that only measures completion percentage misses the behavioural signal that actually predicts a real incident.
FAQ
What's the best way to structure a 12-month security awareness training calendar plan?
The best structure assigns one theme per month, runs a phishing simulation independently every month, and reserves a mid-year checkpoint in Q3 to cross-check compliance deadlines. Skipping the Q3 checkpoint is the most common reason annual reviews find gaps.
How often should phishing simulations run in a training calendar?
Phishing simulations should run at least once a month across all 12 months of the calendar. Running fewer makes it difficult to tell a genuine improvement in click rates from normal monthly variation.
Is a quarterly training calendar better than a monthly one?
A monthly calendar with quarterly executive reviews layered on top works better than a purely quarterly structure, because quarterly-only training leaves long gaps where new hires and phishing tactics go untracked. Keep the granular tracking monthly and save the quarterly cadence for leadership reporting.
When should compliance deadlines be mapped onto the calendar?
Compliance deadlines for frameworks like ISO 27001 Annex A, PCI DSS, and the Notifiable Data Breaches scheme should be mapped before a single monthly theme is chosen. Building the calendar around content first and compliance second is why most programs fail their annual audit.
How do you handle new employees who start mid-year?
New employees need a separate onboarding track triggered by their start date rather than waiting for the next scheduled month on the annual calendar. A compressed sequence covering phishing recognition and password hygiene in the first week is standard practice.
What causes training fatigue in a 12-month calendar?
Training fatigue typically shows up by month 10 or 11 when staff have completed the bulk of the year's modules and engagement drops. Shortening Q4 content and adding variety rather than repeating earlier modules keeps completion rates steady through December.
Should the training calendar differ by department?
Yes, departments with higher exposure like finance and payroll need business email compromise and invoice fraud content layered on top of the standard monthly theme. A single generic calendar for every department under-trains the highest-risk teams.
How do you present calendar results to executives?
Present completion rate, click rate trend, and reporting speed together each quarter rather than a single completion percentage. A quarterly briefing tied to that quarter's theme shows leadership a trend instead of one isolated data point.
One last thing
The calendar detail most teams get wrong isn't the topics — it's the reuse of phishing templates. A program that runs the same simulated email in March and again in September isn't testing awareness the second time around; it's testing whether staff remember a specific subject line. Vary the lure every month even if the underlying lesson repeats, and build that variation requirement into the calendar template itself before 2026 planning starts, not after the first repeat complaint from staff.