Obligations & standards

Which part of your obligations you can tick off with me.

Awareness is required by several sets of rules — and expected in contracts. Choose your context and see openly which requirements secureIT’s training and phishing simulations cover, where you need to add something, and what deliberately stays outside.

ISO/IEC 27001

Standard

A certified ISMS requires that staff are made aware of and trained for their tasks – in a planned, recurring and verifiable way.

5 of 6 requirements you cover with me · 1 stay with your IT
In short
Information security management system (ISMS)
Minimum requirement
Appropriate, recurring awareness measures for all roles, with documented proof of competence.
Basis

ISO/IEC 27001:2022 – clauses 7.2 (Competence), 7.3 (Awareness) and Annex A 6.3 (Information security awareness, education and training); implementation guidance in ISO/IEC 27002:2022, section 6.3.

The requirements in detail

✓ covered
All staff receive awareness training and regular updates on the policies relevant to their role. · Annex A 6.3 / ISO 27002 6.3

Structured awareness courses with lessons that build on each other, suitable for every role.

✓ covered
Security awareness is promoted and checked in practice (e.g. recognising phishing). · Annex A 6.3

Phishing simulations train and measure how well real attacks are recognised.

✓ covered
Staff competence is ensured and documented. · Clause 7.2

Proof of participation and completion with a timestamp for each person.

◐ partly
Awareness of the information security policy and of the consequences of violations. · Clause 7.3

The content conveys principles and consequences; you add your own company policy yourself.

✓ covered
Awareness is planned, recurring and measured. · Annex A 6.3

Repeatable training and campaigns with evaluation (click and completion rates).

– your IT
Technical safeguards (access control, cryptography, backup, etc.). · other Annex A controls

Not part of awareness training – an organisational/technical matter for you or your IT.

Proof at the push of a button

Businesses generate confirmation of the training carried out in the Cockpit — with time stamp and reference to the chosen context.

Get started now

This overview is meant to create transparency and is not legal advice. Whether, and to what extent, a standard or obligation applies to you depends on your sector, your size and your contracts. What is covered in each case is the awareness part (training, simulation, proof) – not the technical measures.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first