For US security, IT, and compliance teams

Security Awareness Training Quiz Generator: Cybersecurity Awareness Quiz Questions From Your Own Policy

Upload your acceptable use policy, information security policy, or phishing awareness deck and get a scored quiz with a matching answer key. Questions come from your language, so the record names your reporting address and your rules rather than a vendor's.

PDF, Word, and PowerPoint accepted. Files are processed securely and deleted automatically.

Upload your security policy and generate the quiz

Click to upload or drag and drop

PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF

up to 20MB

Please wait, your quiz is being created...

Uploading...

The short answer

A security awareness training quiz is a scored set of questions drawn from your own security policies, given to each employee and kept on file with a name and a date. The frameworks that require the training disagree sharply on how often: PCI DSS v4.0 says upon hire and at least once every 12 months, New York's 23 NYCRR 500.14(a)(3) says at a minimum annual and names social engineering as required content, and the FTC Safeguards Rule, HIPAA, and NIST SP 800-171 all leave the interval to you and tie the content to your risk assessment instead. What they agree on is that the training has to reflect your risks and your policies. Upload the policy here and the questions are written from it.

Last updated July 2026. Citations verified against 16 CFR 314.4, 45 CFR 164.308, 23 NYCRR 500.14, NIST SP 800-171 Rev. 3, and the published text of PCI DSS v4.0 Requirement 12.6.3. General information, not legal advice.

How often is security awareness training required, by framework

Almost every article on this subject answers "annually" and moves on. Only two of the six rules below actually say that. Here is what each one requires, and what it means for the quiz you build and the record you keep.

Framework Required frequency Required content, per the text Who it applies to
PCI DSS v4.0
Req. 12.6.3
Upon hire and at least once every 12 months Phishing and social engineering (12.6.3.1) and acceptable use of end user technologies (12.6.3.2), both mandatory since March 31, 2025 Anyone handling or with access to cardholder data or the CDE
NYDFS Part 500
500.14(a)(3)
Periodic, but at a minimum annual Cybersecurity awareness training that includes social engineering, updated to reflect risks identified in the risk assessment All personnel of NY regulated financial services covered entities
HIPAA Security Rule
45 CFR 164.308(a)(5)
No interval stated. Security reminders are an addressable specification Security reminders, protection from malicious software, log-in monitoring, password management All workforce members of covered entities and business associates, including management
FTC Safeguards Rule
16 CFR 314.4(e)
No interval stated. Updated as necessary to reflect risks identified by the risk assessment Security awareness training, plus separate ongoing updates and training for security personnel Non bank financial institutions under GLBA, which reaches auto dealers, mortgage brokers, and tax preparers
NIST SP 800-171 Rev. 3
03.02.01
Initial training for new users, then at an organization defined frequency, plus after defined events Recognizing and reporting indicators of insider threat, social engineering, and social mining Contractors handling controlled unclassified information, and the basis for CMMC assessment
SOC 2
Common Criteria
Not a regulation. Your own stated commitment becomes the tested control Whatever your policy says, which is why auditors ask for the policy before they ask for the records Any service organization under audit, most commonly SaaS vendors

Regulatory text quoted from 16 CFR 314.4(e), 45 CFR 164.308(a)(5), and 23 NYCRR 500.14(a)(3). PCI DSS requirement numbering and dates per PCI DSS v4.0. If more than one applies to you, build to the strictest one and you satisfy the rest.

Why the annual course keeps failing the audit

Three of the six rules above tie training content to your risk assessment. The FTC Safeguards Rule says awareness training updated as necessary to reflect risks identified by the risk assessment. New York says updated to reflect risks identified by the covered entity in its risk assessment. NIST leaves the frequency to you but names insider threat, social engineering, and social mining as content.

A purchased annual course cannot satisfy that link, because it was written before your risk assessment existed. The efficient answer is not to drop the course. It is to add a short quiz built from your own policy on top of it, so the file contains the vendor certificate and a dated, scored record tied to the version of the policy your people actually operate under.

Phishing simulation and quiz measure different things

A simulation is a behavioral test on one day, in one inbox, against one lure. It is genuinely useful and it produces a click rate you can trend. What it does not produce is evidence that a named employee knows your reporting mailbox, your rule on personal cloud storage, or what to do when someone calls claiming to be from your help desk.

A scored quiz drawn from the policy produces exactly that, per person, per policy version. Run the simulation for the behavior signal and the quiz for the knowledge record. When the simulation click rate spikes on a new lure, upload the updated guidance and regenerate the quiz that week rather than waiting for the annual cycle.

What to ask each role

A uniform company wide quiz is easy to administer and weak as evidence, because the threats are not uniform. Upload the policy sections each group actually touches and generate a separate short quiz per group.

Role Policy sections to upload The question that actually matters
All employees Acceptable use, incident reporting, password and MFA standard You get a text from your CEO's personal number asking for gift cards. Where exactly do you report it, and what do you not do first?
Finance and AP Payment authorization procedure, vendor bank change controls A vendor emails new bank details on their letterhead. What is the callback rule, and to which number?
Engineering and IT Production access policy, secrets handling, change management, logging Where do credentials belong, and what is the procedure when one is exposed in a commit?
Help desk and support Identity verification procedure, MFA reset policy A caller says they lost their phone and need MFA reset now. What proof do you require before you touch the account?
Sales and marketing Data classification, approved tools list, AI and cloud storage rules Which customer data may be pasted into an external AI tool, and where is the approved list kept?
Executives and finance approvers Wire approval thresholds, business email compromise procedure, travel rules Which payments require a second approver, and what is the out of band verification step?

How to build the quiz from your security policy

1

Upload the right policy

Acceptable use, the incident reporting procedure, or the phishing awareness deck you already deliver. One document per quiz. A whole ISMS binder gives you broad, shallow questions.

2

Set count and format

Ten to fifteen multiple choice for a general refresher. Add short answer where you want people to write out the reporting path in their own words, which is the item that most often exposes a gap.

3

Review every answer

Check each key against the current policy, especially any mailbox address, phone number, or threshold. Cut questions on procedures you are mid revision on. Ten minutes, every time.

4

File the scored result

Download the employee copy and the answer key separately, or share a scored link. Keep the name, the date, the policy version, the score, and the retake if there was one.

What an auditor asks for, and what to keep

None of these frameworks hands you a record template. In practice a PCI assessor, a SOC 2 auditor, and a NYDFS examiner ask for the same six things, so build the record to contain them from the first quiz you send.

A complete roster

"All personnel" in the NYDFS text and "personnel" in PCI mean everyone in scope, including contractors and executives. The first thing an examiner does is compare your completion list against HR's headcount.

A per person date

PCI's 12 month clock runs from each employee's own training date. A single "completed in Q1" note across the company cannot demonstrate that, and new hires are where this breaks first.

The content, named

Which policy and which version. This is the field almost everyone omits, and it is what connects your record to the risk assessment that two of these rules explicitly require.

Evidence of understanding

A score against a pass mark you set in advance. A completion tick is a participation record, and it invites the obvious follow up about whether anyone learned anything.

The failure path

A retake, a date, and a second score. A file full of first attempt failures with no follow up documents that you knew about a gap and left it open.

The acknowledgment, separately

PCI DSS also asks for a personnel acknowledgment that policies have been read and understood. A signature proves receipt. Pair it with the quiz, because only one of the two speaks to "understood."

Questions people ask about security awareness quizzes

How often is security awareness training required?

It depends entirely on which framework you answer to, and they do not agree. PCI DSS v4.0 Requirement 12.6.3 says upon hire and at least once every 12 months. New York's cybersecurity regulation at 23 NYCRR 500.14(a)(3) says periodic, but at a minimum annual. HIPAA's Security Rule at 45 CFR 164.308(a)(5) requires a program and calls security reminders addressable, with no interval stated. The FTC Safeguards Rule and NIST SP 800-171 both leave the frequency to you.

Does a phishing simulation count as security awareness training?

It is a test of behavior, not a record of knowledge, and the two prove different things. A simulation shows whether someone clicked a link on one Tuesday. A scored quiz drawn from your own acceptable use policy shows they know your reporting address, your rules for personal devices, and your escalation path. Most mature programs run both, and only the quiz produces a per employee comprehension record tied to a policy version.

What should a security awareness training quiz cover?

Cover what your own policy tells people to do: how to report a suspected phishing message and to whom, the rules on personal devices and removable media, what is allowed in cloud storage and AI tools, password and MFA requirements, how to handle a call from someone claiming to be IT, and the physical rules on visitors and unattended screens. Skip questions about what an acronym stands for.

Does NYDFS require annual cybersecurity awareness training?

Yes, and it goes further than most rules by naming the subject matter. Section 500.14(a)(3) of 23 NYCRR Part 500, as amended in November 2023, requires covered entities to provide periodic, but at a minimum annual, cybersecurity awareness training that includes social engineering for all personnel, updated to reflect risks identified in the entity's risk assessment. Social engineering is named in the text, not left to interpretation.

What does PCI DSS require for security awareness training?

PCI DSS v4.0 Requirement 12.6.3 requires personnel to receive security awareness training upon hire and at least once every 12 months. Two sub requirements that became mandatory on March 31, 2025 add specific content: 12.6.3.1 covers phishing and social engineering, and 12.6.3.2 covers acceptable use of end user technologies. The clock runs per person from their own training date, not on your calendar year.

How many questions should a security awareness quiz have?

Ten to fifteen questions for a general workforce refresher, and twenty to twenty five where the audience handles cardholder data, protected health information, or production systems. Short and role specific beats long and uniform: an engineer with production access and a warehouse worker with a shared kiosk face different threats and should not sit the same quiz.

Can I build the quiz from my own security policy instead of buying a course?

That is usually the stronger record. A purchased course teaches general good practice and issues a certificate that says the vendor's curriculum was completed. Every framework above ties the obligation to your own policies and your own risk assessment. Upload the acceptable use policy or the incident reporting procedure and the questions are written from your language, so the file names your process, not somebody else's.

Turn your security policy into a scored quiz

Upload the file, review the draft, and file a dated record tied to the policy version it came from. A few minutes per role, once per revision.

Upload your policy and start