← SecureAZ Blog

Compliance · 6 min read · Published 24 April 2026 · Reviewed 17 August 2026

SOC 2 Security Awareness Training: What CC2.2 and CC1.4 Require

SOC 2 common criteria CC2.2 and CC1.4 require you to communicate security responsibilities to staff. Here's what that means in practice and how to satisfy auditors.

SOC 2 audits trip up more NZ and Australian businesses than any other compliance framework — not because the technical controls are hard, but because auditors keep finding the same gap: staff haven't been told what their security responsibilities are.

That gap sits squarely inside two common criteria: CC2.2 and CC1.4. If you're pursuing SOC 2 Type I or Type II, understanding exactly what these require — and how to evidence them — will save you a failed audit.

What CC2.2 Actually Requires

CC2.2 sits under the Communication and Information category of the Trust Services Criteria. It requires that the organisation "communicates with external parties regarding matters affecting the functioning of internal controls."

In practice, auditors interpret this broadly. It covers communicating security responsibilities to employees, contractors, and anyone with access to your systems. A security awareness training programme is the most direct, auditable way to demonstrate this.

The key word is *communicates* — passive policies sitting in a wiki nobody reads don't satisfy CC2.2. You need evidence that people received, understood, and acknowledged their responsibilities. Completion records, quiz scores, and signed acknowledgements are what auditors look for.

What CC1.4 Requires

CC1.4 falls under the Control Environment category. It requires the organisation to "demonstrate a commitment to attract, develop, and retain competent individuals in alignment with objectives."

For security, this means your people need to be competent in recognising and responding to threats — not just technically skilled at their jobs. Regular security awareness training is the primary control mapped to CC1.4 in most SOC 2 engagements.

Combined, CC2.2 and CC1.4 mean you need a training programme that:

  • Covers all personnel with system access
  • Runs at least annually (quarterly is better for Type II)
  • Produces completion and assessment records
  • Includes content relevant to your actual threat environment

The Evidence Trail Auditors Expect

SOC 2 Type II audits cover a period — typically 6 or 12 months. Auditors will ask for:

  • Training completion reports showing who completed what and when
  • Assessment scores demonstrating comprehension
  • Records of new-hire onboarding training
  • Evidence that the programme was updated when your threat environment changed

A PDF report exported from your training platform on audit day is worth far more than a spreadsheet you've tried to recreate from memory. Build the evidence trail as you go.

Phishing Simulations Strengthen Your SOC 2 Position

CC2.2 requires evidence of communication — but auditors increasingly want to see that you *tested* whether communication was effective. Phishing simulations sit alongside awareness training as corroborating evidence.

A simulation programme that shows you identified vulnerable staff, provided targeted remediation, and tracked improvement over time tells a compelling story of continuous improvement — exactly what a Type II audit rewards.

> "Our SOC 2 auditor specifically called out the phishing simulation results as strong evidence of our control environment. It's not just training records — it's proof the training works."

Practical Steps to SOC 2 Readiness

  1. Deploy a training platform that produces exportable completion records — not a shared folder of videos
  2. Cover the right topics: phishing, social engineering, password hygiene, data handling, incident reporting
  3. Run simulations quarterly and track click rates over time
  4. Onboard new staff within 30 days and keep a record
  5. Review and update content annually — document the review
  6. Retain records for the full audit period — at least 12 months for Type II

For NZ and Australian organisations building toward SOC 2, cybersecurity awareness training is the foundation that ties CC1.4 and CC2.2 together. Get the programme right and the evidence follows naturally.

What a Failed SOC 2 Audit Looks Like

The most common finding against CC2.2 and CC1.4 isn't a lack of a policy — it's a lack of evidence the policy was communicated and acted on. Auditors will specifically ask:

  • "Show me your training completion records for the past 12 months"
  • "What percentage of staff completed training?"
  • "How do you handle staff who don't complete training?"

If you can't answer these questions with data, you have a gap. The good news is it's entirely fixable with the right platform in place before your audit window opens.

SecureAZ provides the training completion records, assessment scores, and phishing simulation reports that SOC 2 auditors accept. Start your free 45-day trial and have your evidence trail building from day one.

External references: