Security Awareness Training Programme Checklist Template
A completion rate close to 100% answers the auditor’s first question. It says nothing about whether your finance team would spot a convincing change-of-bank-details email on a busy afternoon.
Most organisations buy a training library, assign the annual course and spend the last month of the year chasing stragglers. That produces a certificate for every employee and very little change in behaviour. A security awareness programme that actually reduces risk runs all year. It starts from the threats your own people face, gives developers, administrators, finance staff and executives training that fits their work, uses phishing simulations to measure what people do rather than what they remember, and reviews the results before planning next year. This free security awareness training checklist gives security and GRC teams that annual cycle in six phases, from needs assessment to leadership sign-off. It follows the life cycle in NIST SP 800-50 Rev. 1 and produces the evidence ISO 27001, PCI DSS, SOC 2 and HIPAA reviewers ask for, without turning the programme into a box-ticking exercise.
NIST rewrote its guidance on this subject in September 2024. SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, replaced both the 2003 awareness guide and the 1998 role-based training model in SP 800-16. The new version treats the programme as a managed life cycle with four phases: plan and strategy, analysis and design, development and implementation, and assessment and improvement. It puts behaviour change at the centre. One of its example metrics is the share of people who received a simulated phishing email and reported it, rather than how many finished a module.
It is also clear about how simulations should be run. Tell staff that phishing exercises happen, involve your legal team in designing them, avoid using real brands as bait, and never single out individuals or punish them for clicking. A programme built on those rules produces honest data, and the data tells you where to spend next year’s training time.
Compliance-led training
One annual course for everyone
Content: the same generic library modules for every role.
Measure: completion percentage by the deadline.
Phishing tests: occasional, with clickers named or sent to remedial training.
Result: an audit trail, but little evidence of lower risk.
Risk-led programme
Planned from your own threats and roles
Content: a common baseline plus role-based modules for higher-risk jobs.
Measure: reporting rate, time to report and real incidents flagged by staff.
Phishing tests: regular, announced in principle and never punitive.
Result: the audit trail plus a trend you can show the board.
What the Security Awareness Training Checklist Covers
Six phases cover one programme year. The phishing and escalation tasks appear only when the answers call for them.
Phase 1
Phase 1: Assess Needs & Risks
Owned by the security awareness lead. Task 5 decides whether the phishing simulation tasks in Phase 4 are shown this year.
Review last year’s results — completion, phishing reporting and click rates, and incidents traced to human error
List the threats your people actually face — from incident reports, lessons-learned reviews and the risk register
Record the obligations that apply — ISO 27001, PCI DSS, HIPAA, NIS2, client contracts and cyber insurance terms
Define audience segments — all staff, new joiners, IT administrators, developers, finance, executives and contractors with system access
Decide whether to run phishing simulations this year — yes or no, with the reason recorded
Phase 2
Phase 2: Design the Programme
The finished plan is approved by the programme sponsor, usually the CISO.
Set the baseline topics for everyone — social engineering, passwords and MFA, data handling, reporting incidents and acceptable use of devices
Assign role-based modules — secure coding for developers, privileged access for administrators, payment fraud for finance
Choose or refresh the content — retire modules that no longer match your tools, policies or current attack methods
Build the year’s calendar — the annual course, short monthly reminders and themed campaigns
Approve the programme plan — goals, audiences, calendar and budget signed off by the sponsor
Phase 3
Phase 3: Launch & Deliver
Announce the programme from a senior leader — a message from the top gets more attention than one from IT
Enrol every in-scope person and set the deadline — including contractors and temporary staff with system access
Check that new-joiner training is working — sample recent starters to confirm they completed it during onboarding
Collect annual policy acknowledgements — each person confirms they have read and understood the security policy
Deliver the role-based sessions — live or online, with attendance recorded
Phase 4
Phase 4: Phishing Simulations
Switches on when Phase 1 records that simulations will run this year.
Agree the simulation rules with HR and legal — no punishment, no public naming and no real brands used as bait
Tell staff that simulations will happen — without giving dates or details
Run campaigns at varied difficulty — including lures tailored to finance, HR and executive roles
Measure reports as well as clicks — the reporting rate and time to first report show whether your early warning works
Offer extra support to repeat clickers — a short conversation or targeted module, never a disciplinary route
Phase 5
Phase 5: Track Completion & Chase
Task 4 appears only if completion is still below target at the deadline.
Monitor completion by team every week — against the target agreed in Phase 2
Send reminders, then escalate to line managers — managers see their own team’s outstanding names
Record approved exceptions — long-term leave or no system access, each approved and time-limited
Escalate remaining non-completion to the sponsor — with named teams and the action your policy allows
Export completion evidence — the learning platform report, attached with the date it was run
Phase 6
Phase 6: Measure, Review & Report
The annual review is signed off by the sponsor and closes the programme year.
Compile the programme metrics — completion, reporting rate, click rate and real incidents reported by staff
Gather learner feedback — which modules were useful, which were ignored
Compare results with the goals set in Phase 1 — and note why any were missed
Review and update the programme for next year — new threats, changed roles and content that needs replacing
Report to leadership and sign off the review — one page of trends and next year’s priorities
What Each Framework Expects From Awareness Training
Almost every security framework requires awareness training, but they differ on frequency, topics and evidence. The table sets out the main references and where the checklist produces the proof. Your obligations depend on your sector and certifications, so treat it as a starting point, not legal or audit advice.
Framework
Reference
What it expects
Evidenced in
NIST SP 800-50 Rev. 1 (September 2024)
Programme life cycle
Plan and strategy, analysis and design, development and implementation, assessment and improvement, with metrics that show behaviour change
Phases 1–6
ISO/IEC 27001:2022
A.6.3
Personnel and relevant interested parties receive awareness, education and training, and regular updates on policies relevant to their job
Phases 2, 3 and 5
PCI DSS v4.0.1
12.6.1–12.6.3.2
A formal programme reviewed at least once every 12 months; training on hire and at least once every 12 months; annual policy acknowledgement; phishing and social engineering; acceptable use of end-user technologies
Phases 2, 3 and 6
HIPAA Security Rule
45 CFR 164.308(a)(5)
A programme for the whole workforce, including management; addressable specifications cover security reminders, malicious software, log-in monitoring and password management
Phases 2–3
SOC 2 (2017 TSC, revised points of focus 2022)
CC1.4, CC2.2
A commitment to developing competent people; a CC2.2 point of focus calls for a security awareness training programme to improve knowledge and model good behaviour
Phases 2, 3 and 5
CIS Controls v8.1
14.1–14.9
Training at hire and at least annually, content reviewed annually, specific topics from social engineering to insecure networks, and role-specific training
Phases 1–3, 6
NIS2 Directive (EU) 2022/2555
Art. 20(2), 21(2)(g)
Management bodies must follow cybersecurity training; basic cyber hygiene and cybersecurity training are among the required risk management measures
A recurring schedule opens the new programme year on the same date every year, with Phase 1 assigned to the awareness lead and due dates set for each phase. The annual review cannot slip quietly into the following spring.
2
Only the work that applies
Conditional logic hides the phishing phase in a year you decide not to run simulations, and adds the sponsor escalation only when completion misses its target. The checklist stays as long as the year actually requires.
3
Evidence that matches the question
Completion reports, policy acknowledgements, campaign results and the signed annual review sit on the tasks that produced them, with the name and date of each completion. When an auditor asks for last year’s programme, you export it.
CheckFlow is not a learning management system or a phishing simulation platform. It runs the planning, approvals, chasing and review around them, and holds the evidence those tools produce. CheckFlow’s compliance checklist software shows how this programme sits alongside the other annual controls in your compliance calendar.
Training on hire works best when it is a task in the onboarding process rather than a separate reminder. The Employee Onboarding Checklist is the place to add it. For executives, the most effective awareness session is often a scenario: the Incident Response Tabletop Exercise Checklist shows how to run one.
Training completion and phishing results are part of the evidence an annual IT Security Audit Checklist reviews, so the completion export from Phase 5 does double duty.
What should a security awareness training programme include?
+
A baseline for everyone covering social engineering and phishing, passwords and multi-factor authentication, handling sensitive data, reporting incidents and acceptable use of devices. On top of that, role-based training for people whose jobs carry extra risk, such as administrators, developers, finance staff and executives. Around the content you need training on hire, an annual refresher, regular short reminders, a way to measure behaviour, and a yearly review of what worked.
How often is security awareness training required?
+
On hire and at least once a year is the most common expectation. PCI DSS v4.0.1 requirement 12.6.3 sets exactly that for personnel, and CIS Controls v8.1 safeguard 14.1 asks for training at hire and at a minimum annually. ISO 27001 and HIPAA do not fix a frequency, so the annual cycle is usually what organisations adopt and auditors expect to see. Short monthly reminders between annual courses help keep the topics current.
Should employees be disciplined for failing phishing tests?
+
NIST SP 800-50 Rev. 1 advises against it. It recommends treating phishing exercises as learning opportunities, not singling people out, and telling staff that simulations happen. Punishment discourages the behaviour you most want: people reporting suspicious messages quickly, including ones they have already clicked. Extra support for repeat clickers works better than sanctions.
How do we measure whether training is working?
+
Completion shows the programme was delivered, not that it worked. Better signals are the percentage of people who report a simulated phishing email, how quickly the first report arrives, the number of real incidents raised by staff and whether human-error incidents fall over time. Track them year on year in the Phase 6 review rather than judging a single campaign.
Do contractors need security awareness training?
+
If they have access to your systems or data, they should be in scope. ISO 27001 control A.6.3 extends to relevant interested parties as well as personnel, and auditors commonly expect contractors and temporary staff with system access to appear in the training records. The checklist enrols contractors and temporary staff alongside employees and records any approved exceptions.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Run a Programme That Changes Behaviour, Not Just One That Passes Audit
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more