# ISO 27001 awareness training: what the auditor wants to see in 2026

> ISO 27001 requires demonstrable awareness training through Annex A 6.3 and clause 7.2. Read which controls apply, what the auditor asks for and how to evidence competence.

- Canonical: https://cyberpulse.it/en/iso-27001-awareness-training
- Dutch version: https://cyberpulse.it/iso-27001-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

If you want to obtain or keep an ISO 27001 certificate, you have to do more than *deliver* security awareness training: you have to prove it. Annex A control 6.3 requires appropriate training with regular updates, and clause 7.2 obliges you to retain evidence of competence. This page sets out which controls apply, what an auditor actually asks for and how to get from scattered e-learning modules to demonstrable proof of competence.

## Which ISO 27001 controls require training?

ISO/IEC 27001:2022 touches awareness and training in three places.

**Annex A 6.3: “Information security awareness, education and training”.** This control requires personnel and relevant interested parties to receive appropriate awareness, education and training, with regular updates, relevant to their job function. Two things stand out: the circle is wider than your own personnel, and the training has to match what someone does in their role: a finance employee faces different risks from a system administrator.

**Clause 7.2: competence.** The standard obliges you to ensure that people are competent and to document it:

> “documented information as evidence of competence”
> – ISO/IEC 27001:2022, clause 7.2(d)

Having delivered a training course is therefore not enough; you have to be able to prove in documented form that the competence *is* there.

**Clause 7.3: awareness.** Employees must be aware of the information security policy, their own contribution to it and the implications of non-conformity. That is the substantive bar for your awareness programme: not only “do not click on phishing”, but also “this is our policy and this is your role in it”.

The implementation guidance in ISO 27002 adds, under control 6.3, that understanding should be tested. An attendance list proves that someone was present; only a test shows that the material landed.

The text of the standard itself is not freely available; you buy the official version through [iso.org](https://www.iso.org/standard/27001). Worth knowing: ISO 27001 certification is voluntary, but in practice contractually driven: customers and tenders ask for it. Statutory training obligations are a separate matter; the full overview of what really is required by law can be found at [is security awareness training mandatory](/en/security-awareness-training-mandatory).

## What does an auditor want to see?

On awareness and competence, auditors expect four kinds of evidence:

1. **A training plan.** Who do you train, in what, when and why? The plan shows that awareness is a managed process rather than a loose action, and that you have thought about which roles need which training.
2. **Participation records.** Per training course and per employee: who took part and when. This is the basic evidence that the plan was actually carried out, including employees who joined later in the year.
3. **Evidence of competence per role.** This follows directly from clause 7.2(d): documented proof that people are competent for their role. Think of quiz results, certificates obtained and completed role-specific modules.
4. **Effectiveness measurement.** Does the programme work? Test results and, for example, phishing simulation outcomes show whether the awareness required by clause 7.3 is there in practice, and where you need to steer.

Anyone with these four in order can answer virtually every audit question about awareness on the spot. Anyone missing one has a story without evidence.

### How awareness plays out on an audit day

Exactly how a certification audit runs differs per auditor, but around awareness the pattern is recognisable. Expect three moments:

1. **Documentation review.** The auditor asks for your training plan and records and holds them against your ISMS: does what you promised match what you can show? Missing records and expired schedules stand out immediately here.
2. **Sampling.** The auditor picks a few employees (often a recent joiner, someone in a key role and a random name from the list) and wants participation and results per person. A file that only holds up for the average employee is of no use to you.
3. **Interviews on the shop floor.** In conversation, the auditor tests the awareness from clause 7.3 in practice: does this employee know what the policy is, what their own role in it is and what to do in the event of an incident? A programme that exists only on paper is exposed here.

For an SME, the sampling is the nerve-racking part: with 60 employees, there is a good chance the auditor lands on exactly the person who started three weeks ago. A programme that picks up new joiners automatically takes the tension out of that.

## How often is ‘regular’?

The standard names no number: control 6.3 speaks of regular updates, and you may set that frequency yourself: as long as you can defend the choice. Other frameworks do give a reference point. PCI DSS v4.0 requires training on hire and at least annually thereafter (requirement 12.6.3), and CIS Controls v8 uses the same rhythm (control 14.1).

So treat annually as a floor, not an ambition. A continuous programme with short, frequent learning moments has three practical advantages: new employees are picked up automatically, you deliver on “regular updates” quite literally, and you build evidence continuously instead of at one registration moment a year. During an audit, that difference is immediately visible in your file.

Record your choice as well: a short justification in your training plan (“we train continuously, because …”) turns an implicit habit into a defensible decision, and gives the auditor exactly the kind of underpinning they are looking for.

## Common mistakes during audits

The nonconformities on awareness are rarely exotic: they almost always follow directly from the controls above:

- **Only participation recorded, understanding never tested.** ISO 27002 expects understanding to be tested under 6.3. An attendance list without a test result is half the evidence.
- **Exactly the same training for everyone.** Control 6.3 requires training relevant to the job function, and clause 7.2 asks for evidence of competence per role. One generic e-learning module for the whole organisation does not cover that.
- **One-off instead of regular.** A single training round at the start of the ISMS and then silence, while 6.3 requires regular updates.
- **Relevant interested parties forgotten.** Control 6.3 is not limited to your own personnel. External staff who work with your information belong in the programme too.
- **No effectiveness measurement.** Training happened, but nobody can show what it produced. Auditors expect that measurement explicitly.
- **Evidence scattered across mailboxes and loose spreadsheets.** It exists, but it is not reproducible during the audit, and evidence you cannot show does not count.

### What such a mistake looks like as a nonconformity

Three recognisable examples of how findings like these end up in an audit report: anonymised and simplified, but typical:

- **Joiners missed.** A service provider trained everyone each January; three employees who started in the spring had still completed nothing by the October audit. Nonconformity against control 6.3: the programme did not cover all personnel.
- **No evidence of competence.** An organisation had everyone do the same e-learning module and recorded only completion. The auditor asked for the evidence of competence for the system administrators (clause 7.2(d)): it was not there, because nothing had ever been tested or recorded per role.
- **Effectiveness never measured.** The training plan promised an annual evaluation of the awareness programme; it had never taken place. Failing to follow your own policy is one of the easiest nonconformities for an auditor to establish.

The lesson from all three: the nonconformity rarely arises because no training was delivered, but because the process around it (onboarding, testing, measurement, record-keeping) does not add up. So do not focus only on the content, but above all on that process.

Whether such a finding is classified as a minor or a major nonconformity is up to the auditor and depends on the severity and the pattern. But every nonconformity costs you the same: corrective actions, extra attention at the next assessment and a conversation with your management that you would rather not have.

## From e-learning to demonstrable evidence of competence

The common thread: ISO 27001 does not assess whether you train, but whether you can prove it. So design your programme for recording and measurement from day one, not just for content.

CyberPulse combines weekly micro-learning and quizzes with phishing simulations, and records participation, quiz results, certificates and phishing outcomes per employee. That gives you participation records, evidence of competence and effectiveness measurement in a single report for the auditor. [Try it for free](/trial).

### Checklist for your next audit

- Document a training plan with target groups and role-specific components.
- Record every instance of participation per employee, new joiners included.
- Test understanding with quizzes or exams, not just attendance.
- Retain certificates and results as evidence of competence (clause 7.2(d)).
- Measure effectiveness, for example through test and phishing simulation results.
- Repeat regularly and document that rhythm.
- Include relevant interested parties beyond your own personnel.

Do you work in healthcare? Then NEN 7510 (the Dutch healthcare information security standard) gives you the same structure: the 2024 version follows ISO 27002:2022 and awareness sits in control 6.3 there too: read [NEN 7510 awareness training](/en/nen-7510-awareness-training). And if you process personal data (as virtually every organisation does), the GDPR also expects demonstrable awareness as an appropriate organisational measure: read [GDPR security awareness training](/en/gdpr-security-awareness-training).

## Frequently asked questions

### Is an annual e-learning module enough for ISO 27001?

Sometimes, but it is thin. The standard names no frequency, so annually can suffice: provided you also test understanding (ISO 27002 under control 6.3), differentiate per role and retain evidence of competence (clause 7.2(d)). One generic e-learning module without testing and without role-specific evidence does not cover the controls. A continuous programme is easier to defend: it catches new employees and produces evidence for the auditor all year round.
### Is ISO 27001 certification required by law?

No. Certification is voluntary, but in practice it is contractually driven: customers and tenders increasingly demand the certificate. Note that separately from ISO 27001, statutory training obligations may well apply, such as the duty of care under NIS2 and the Dutch Cybersecurity Act. Those obligations stand apart from your certification and apply even if you never start an ISO project.
### What evidence does an auditor ask for on awareness training?

Four things: a training plan, participation records per employee, evidence of competence per role (such as quiz results and certificates, in line with clause 7.2(d)) and an effectiveness measurement showing whether the programme works. If you can show all four straight away, awareness is a formality during the audit; if you are missing one, you have a story without underpinning.
### What is the difference between clause 7.2 and 7.3?

Clause 7.2 is about competence: people must be capable in their role, and you must retain documented evidence of that (7.2(d)). Clause 7.3 is about awareness: employees know the information security policy, their own contribution to it and the implications of non-conformity. In short: 7.2 is being able to do it and proving it, 7.3 is knowing and understanding. Your training programme has to cover both.
### Do I have to test understanding, or is recording participation enough?

Test it. The implementation guidance in ISO 27002 indicates under control 6.3 that understanding should be tested. A participation record only proves attendance; a quiz or test result proves that the material was understood, and that result is immediately usable as evidence of competence under clause 7.2(d) and as input for your effectiveness measurement.
### Where can I find the text of ISO 27001?

The standard is not available free of charge. You buy the official text of ISO/IEC 27001:2022 through iso.org (or through your national standards body). Summaries online often reproduce only the control titles; for the exact wording of Annex A 6.3 and clauses 7.2 and 7.3 you need the text of the standard itself.

## Sources

- [ISO, standard page ISO/IEC 27001](https://www.iso.org/standard/27001)
- [PCI Security Standards Council, document library (PCI DSS v4.0)](https://www.pcisecuritystandards.org/document_library/)
- [NEN, NEN 7510-1:2024](https://www.nen.nl/nen-7510-1-2024-nl-331311)
