SOC 2's Trust Services Criteria require an organization to communicate information that improves security knowledge and awareness, but they don't prescribe a curriculum. In practice, auditors expect annual training, new-hire training within the first 30 days, and, for a Type II audit, documented proof it happened continuously, not just once. Most startups build this reactively, around a Series A or a scheduled audit, instead of planning for it.
SOC 2 has no fixed syllabus. The AICPA's Trust Services Criteria, specifically CC2.2 and CC2.3, set a principle: communicate information internally to support the functioning of internal controls, including security awareness. There's no mandated seat time and no required phishing-simulation frequency written into the standard itself. What auditors do expect in practice: training for all employees at least annually, new-hire training within roughly the first 30 days of start date, and, critically for a Type II report (which evaluates controls operating over a period, not a point in time), evidence that training happened continuously across that window, logged with names, dates, and completion status, not a one-time slide deck nobody can prove anyone watched.
Commonly expected topics: information security policy, acceptable use, phishing and social engineering awareness, data handling, and incident reporting. Role-specific add-ons are common too, engineers typically need secure development or access-control training beyond the general-awareness baseline everyone gets.
Below roughly 50 employees, informal onboarding, Notion or Confluence docs, a Slack channel, a founder walking new hires through the basics, is the default, and it's genuinely fine for that stage. The trigger that changes things is usually Series A or an enterprise customer's procurement process: investors and enterprise buyers start expecting SOC 2 evidence during due diligence, and compliance vendors consistently warn that scrambling to build this after the fact can delay a deal by three to six months. The practical lesson isn't "build it earlier than you need it," it's "know which milestone is coming and have a plan before it arrives," since building a defensible program under deal pressure is worse than building it deliberately a quarter ahead.
Beyond the security-awareness baseline, a startup training academy that holds up under scrutiny usually needs role-specific tracks (engineering security practices look different from general acceptable-use training), a completion log an auditor can actually read, an annual refresh cadence rather than a one-time build, and, increasingly, a customer- or product-education track if the company is using education as a growth or retention lever with its own customers. None of this requires enterprise-scale infrastructure, it requires the same instructional design discipline at a scope that matches a startup's stage and budget.
This is part of our broader work with funded companies. See how we work with funded startups for the full picture, including customer education and onboarding academies.
Book a 20-minute call and walk through where onboarding and compliance training actually stand today. We'll tell you honestly what's urgent and what can wait.
Book Your 20-Min Discovery Call →