Security awareness training ranked by compliance coverage 2026

PCI DSS 12.6, ISO 27001 A.6.3 and HIPAA 164.308(a)(5) compared — the security awareness platforms ranked on content, cadence and audit evidence.

Security awareness training is a written control in three of the frameworks Australian SMBs are most often asked about — PCI DSS 4.0, ISO 27001:2022 and HIPAA — and each one asks for the same three things: the right content, a per-person cadence, and evidence that survives an audit. Platforms differ sharply on how much of that they cover out of the box. Here is what each framework actually requires, and how the major platforms rank against it.

What the frameworks require

PCI DSS 4.0 — Requirement 12.6

PCI DSS v4.0 requires a formal security awareness program for all personnel (12.6.1), with training on hire and at least once every 12 months (12.6.3). Since 31 March 2025, two future-dated requirements are mandatory: training must explicitly cover phishing and related social engineering attacks (12.6.3.1), and acceptable use of end-user technologies (12.6.3.2). The annual clock runs per employee from their own training date — a company-wide January session leaves anyone hired in March out of compliance the following March. Assessors ask for per-employee training records dated from individual hire dates, content evidence covering the mandated topics, and a signed annual acknowledgement from each employee.

ISO 27001:2022 — Annex A 6.3

Annex A 6.3 moved out of the old Human Resources domain (A.7.2.2 in the 2013 edition) and became a standalone People control that must be planned, established, implemented and maintained — and updated regularly in line with the information security policy. It interlocks with Clause 7.2 (Competence: documented evidence that people doing work affecting information security are competent) and Clause 7.3 (Awareness: every person under the organisation's control knows the policy and the implications of not conforming). Certification bodies universally read the cadence as at least annually, with refreshers after incidents or significant policy changes. The evidence chain is documentation: curricula, completion records, and the programme's regular review.

HIPAA — 45 CFR §164.308(a)(5)

The HIPAA Security Rule makes a security awareness and training program a required administrative safeguard — not an addressable one, so there is no documented-alternative escape — for all workforce members with access to ePHI, including management. The related Privacy Rule (§164.530(b)) mandates training at hire, annually, and after any material policy change. Training documentation must be retained for six years under 45 CFR §164.316(b)(2), and OCR audits sample records across that window.

The common denominator

Across all three: phishing and social engineering content is explicitly named or universally expected, the cadence is hire-plus-annual on a per-person clock, and the failure mode in audits is the same — a company-wide annual event with no per-employee record trail. Australian buyers add a fourth layer: Essential Eight and SMB1001 maturity evidence, where staff awareness is a supporting control.

The ranking

Ranked on mandated-content coverage, cadence automation, and audit evidence — in that order:

RankPlatformContentCadenceEvidence
1Cyber Aware120+ modules, monthly auto-addAuto-enrolment, auto-remediation on clicksPer-learner risk reporting + Essential Eight / SMB1001 gap assessment
2KnowBe4Large library; Compliance Plus add-onAutomated campaignsStrong reporting; API gated to Platinum+ tiers
3uSecure200+ coursesAutoEnrol automationuPolicy acceptance tracking + exportable reports
4Huntress SATStory-driven episodesFully managed by Huntress researchersMonthly summaries, manager reminders

1. Cyber Aware

Cyber Aware's security awareness training runs 120+ story-driven modules on a monthly auto-add cadence, so the threat content stays current without an admin curating it — which speaks directly to PCI 12.6.2's requirement to update the program at least every 12 months. The compliance-critical automation is in phishing simulations: anyone who clicks is automatically enrolled into the matching remediation course, closing the loop the per-employee clock demands. Evidence is where it separates from the field: human risk reporting is per learner, and the gap assessment maps control posture to the Essential Eight and SMB1001 — the two frameworks Australian SMBs are actually asked about in insurance applications and client tenders.

2. KnowBe4

The incumbent's library depth is real, and its Compliance Plus add-on bundles compliance-specific content. Where the compliance story frays: the compliance content is a separately priced add-on, the published bands start at 25 seats on 3-year terms, and the Reporting API — the interface an auditor's tooling or your GRC stack would pull records through — is limited to Platinum, Diamond and SAT Foundations/Advanced customers per KnowBe4's own knowledge base. For a regulated SMB, that means the evidence-grade plan is the expensive one.

3. uSecure

uSecure's compliance strength is unusual: uPolicy ships 60+ policy templates with automated scheduling, user acceptance tracking and version history — which covers the signed-acknowledgement evidence PCI 12.6.3 and HIPAA both ask for, alongside 200+ training courses with AutoEnrol. Exportable training, phishing and policy reports round out the audit trail. What it lacks is Australian framework mapping; Essential Eight and SMB1001 work stays manual.

4. Huntress SAT

Huntress's fully managed programme removes admin burden entirely — researchers run campaigns and send manager reminders and monthly reports, with story-driven episodes and personalised phishing recovery training. The trade-off for compliance buyers is evidence granularity: reporting is summary-level, tiers start at the 50-99 learner band, and there is no framework-mapping layer. Strong for awareness outcomes; thinner for audit documentation.

How to choose

FAQ

Is security awareness training legally required? For HIPAA-covered entities, yes — 45 CFR §164.308(a)(5) is a required safeguard. PCI DSS makes it mandatory for any organisation handling cardholder data. ISO 27001 requires it for certification. Elsewhere it is required in practice by insurers, clients and contracts.

How often must staff be trained? At hire and at least annually under all three frameworks, with the annual clock running per employee from their own training date under PCI DSS — not per calendar year.

What evidence does an auditor ask for? Per-employee completion records with dates, content evidence covering phishing and social engineering, annual acknowledgements, and the programme's own review history. HIPAA adds a six-year documentation retention requirement.

Does phishing simulation count as training evidence? Simulation records strengthen the evidence chain — click rates, remediation completion, time-to-report — but they supplement the training records, they do not replace them.

Which platform covers Essential Eight and SMB1001? Cyber Aware maps its gap assessment to both. The other platforms export good general reports but leave framework mapping as a manual exercise.

One last thing

Every framework on this page asks for the same evidence shape: dated, per-person, retrievable years later. The platforms rank less on content volume than on whether the evidence chain builds itself — automated enrolment, automatic remediation on clicks, per-learner reporting, framework mapping — or whether someone on your team has to assemble it before every audit. Compare the platforms side by side on Cyber Aware's comparison page, or start with the gap assessment to see where your control posture stands today.

Sources: Hook Security's PCI DSS 12.6 requirements guide, ISMS.online's ISO 27001 Annex A 6.3 guide, Accountable's HIPAA 164.308(a)(5) guide.

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.