How Often Is Security Awareness Training Required?

2026/07/23

Click to upload or drag and drop

PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF

up to 20MB

Please wait, your quiz is being created...

Uploading...

The honest answer is that it depends on which rule you answer to, and they do not agree. PCI DSS v4.0 requires security awareness training upon hire and at least once every 12 months. New York's cybersecurity regulation requires periodic, but at a minimum annual, training. The HIPAA Security Rule, the FTC Safeguards Rule, and NIST SP 800-171 all require the training and name no interval at all, tying the content to your risk assessment instead.

"Annually" became the default answer because it is the safest reading of the vaguer rules and because that is how courses are sold. It is a reasonable operating cadence. It is not what most of these rules say, and the difference matters when an examiner asks you to point at the requirement you are meeting.

What each framework actually requires

FrameworkFrequency in the textContent named in the text
PCI DSS v4.0, Req. 12.6.3Upon hire and at least once every 12 monthsPhishing and social engineering (12.6.3.1) and acceptable use of end user technologies (12.6.3.2), both mandatory since March 31, 2025
NYDFS, 23 NYCRR 500.14(a)(3)Periodic, but at a minimum annualCybersecurity awareness training that includes social engineering, for all personnel, updated to reflect risks identified in the risk assessment
HIPAA Security Rule, 45 CFR 164.308(a)(5)No interval stated. Security reminders are an addressable implementation specificationSecurity reminders, protection from malicious software, log-in monitoring, password management
FTC Safeguards Rule, 16 CFR 314.4(e)No interval stated. Updated as necessary to reflect risks identified by the risk assessmentSecurity awareness training for personnel, plus separate ongoing updates and training for security staff
NIST SP 800-171 Rev. 3, 03.02.01Initial training for new users, then at an organization-defined frequency, plus after defined eventsRecognizing and reporting indicators of insider threat, social engineering, and social mining
SOC 2Not a regulation. Whatever your own policy commits to becomes the tested controlWhatever your policy says, which is why the auditor asks for the policy first

The two rules that genuinely say annual

PCI DSS Requirement 12.6.3 is the most prescriptive of the set: personnel receive security awareness training upon hire and at least once every 12 months. The detail teams miss is that the clock runs per person from their own training date, not on your calendar year. If you run one company-wide session every January, an employee hired in February is out of window the following February, and a January-only program will not show that.

Section 500.14(a)(3) of New York's Part 500, as amended in November 2023, requires periodic, but at a minimum annual, cybersecurity awareness training that includes social engineering, for all personnel. Two things in that sentence do real work. Social engineering is named, so a course about password hygiene alone does not meet it. And "all personnel" is broader than "employees," which is where contractors and executives usually go missing from the completion roster.

The rules that deliberately do not say annual

The FTC Safeguards Rule at 16 CFR 314.4(e) requires providing your personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment. There is no interval, and that is the point: the trigger is your risk assessment changing, not a date. This rule reaches a lot of businesses that do not think of themselves as financial institutions, including auto dealers, mortgage brokers, and tax preparers.

HIPAA's Security Rule requires a security awareness and training program for all workforce members including management, and lists security reminders, protection from malicious software, log-in monitoring, and password management as addressable specifications. Addressable does not mean optional. It means you implement it, or you document why it is not reasonable and what you did instead.

NIST SP 800-171 Rev. 3 leaves the ongoing frequency as an organization-defined parameter, which means you have to define it, write it down, and then meet the number you wrote. Contractors get assessed against their own stated frequency, so a policy that says quarterly and a practice that runs annually is worse than a policy that said annually.

So what cadence should you actually run?

If more than one of these applies to you, build to the strictest and you satisfy the rest. In practice that means: training within the first week of hire, a refresh at least every 12 months measured per person, and an out-of-cycle refresh whenever your risk assessment changes materially or a new threat pattern shows up in your own incident data.

The out-of-cycle piece is what separates a program from a checkbox. When a new invoice fraud lure starts landing, or you roll out a new tool that changes what people may paste into it, that is the moment to push a short update and a five-question check, not eleven months later. Organizations that map obligations across several frameworks at once usually run this out of a compliance obligation tracker rather than a shared calendar, because the same event can trip requirements in three rules with different wording.

Does completing a course count as evidence?

Partly. A course certificate says the vendor's curriculum was completed by a person on a date. Three of the frameworks above tie the obligation to your own policies and your own risk assessment, and no purchased course can speak to those, because it was written before your risk assessment existed.

The efficient fix is not to drop the course. It is to add a short quiz drawn from your own acceptable use policy or incident reporting procedure on top of it, so the file holds both the general certificate and a dated, scored record naming your reporting mailbox, your MFA rules, and your escalation path. You can generate that draft from the policy document itself with the security awareness training quiz generator and then review every answer before it goes out.

What the completion record needs to contain

Whichever cadence you land on, examiners converge on the same fields. A complete roster including contractors and executives, not just full-time staff. A per-person completion date, because the 12-month clock is individual. The specific policy and version the training covered. A score against a pass mark set in advance, since a completion tick is a participation record. And a documented retake for anyone who failed.

PCI DSS separately asks for a personnel acknowledgment that policies have been read and understood. Keep the signature, and keep the quiz next to it, because only one of the two says anything about "understood."

Related workflows

The same document-to-quiz approach covers the neighboring obligations that tend to land on the same person's desk. Privacy training has its own two-rule structure and a six-year retention clock, covered on the HIPAA training quiz generator page, and the rest of the annual stack runs through the compliance training quiz generator. If your policy set lives inside a staff handbook rather than standalone documents, the employee handbook quiz generator handles that shape.

From the same family of tools