ClickCerts
Security awareness training

Security awareness training that's priced like a product, not a pricing puzzle.

Fixed annual pricing. Four certificates per user, every year. The only thing that grows is your team's awareness.

CMMC Level 2 readyNIST 800-171 alignedQuarterly content releases
Why ClickCerts

Built for the way training is actually used —not the way it's invoiced.

Most security awareness platforms charge by the certificate, the credit, the seat-month, or some opaque combination. ClickCerts charges per user, per year. That's it.

Fixed annual pricing

One number per user, per year. Four certificate-awarding courses included, full recertification, automatic expiry tracking. No credits to count, no overage emails to dread.

A new module every quarter

Four releases a year, refreshed annually for the current threat landscape. Auditors see ongoing evidence of training. Employees don't see the same phishing module four times.

Verifiable certificates

Every completion produces a real certificate with a unique serial number and a public verification page. Scan the QR code or tap the link — auditors, partners, and customers can verify it instantly, no emails needed.

Quarterly cadence

Four releases a year. One reason your team keeps coming back.

Compliance training fails when it ships once and disappears. We release a new module every quarter and refresh the existing content annually so your team stays current — and auditors always see ongoing evidence.

  1. Q1

    Foundations

    Core security awareness, password hygiene, device basics. The bedrock module every employee starts with.

    View outline

    The bedrock module every employee starts with. We cover the foundational concepts the rest of the year builds on, with no assumed prior training.

    Course outline

    • 01What "security awareness" actually means in practice
    • 02Password hygiene that doesn’t drive your team crazy
    • 03Multi-factor authentication: the what, why, and how
    • 04Recognizing physical security risks — tailgating, shoulder surfing, lost devices
    • 05Personal vs. work devices: what crosses the line
    • 06Knowing when and how to escalate

    Outlines reflect our standard curriculum. Custom course development is available on request for an additional fee.

  2. Q2

    Phishing & email

    Social engineering, email defense, real-world case studies refreshed for the current attack landscape.

    View outline

    Email remains the #1 attack vector. This module teaches your team to spot the patterns attackers use, not just the obvious red flags.

    Course outline

    • 01Anatomy of a phishing email — and how attackers update their playbook
    • 02Spear phishing, whaling, and the targeted attack
    • 03Business Email Compromise (BEC): the long con
    • 04Smishing, vishing, and other "ishing" attacks
    • 05Real case studies: where small mistakes became breaches
    • 06What to do when you click — and why telling someone fast matters

    Outlines reflect our standard curriculum. Custom course development is available on request for an additional fee.

  3. Q3

    Data & privacy

    Data handling, insider threat, regulatory updates aligned to CMMC and NIST 800-171 revisions.

    View outline

    How your team handles data day-to-day determines whether you survive an audit — and whether you’re an insider threat without knowing it.

    Course outline

    • 01Classifying data: what’s sensitive, what’s not, and what’s gray
    • 02Insider threat awareness: recognizing patterns in yourself and others
    • 03CMMC and NIST 800-171: what your job actually requires
    • 04Cloud storage, file sharing, and personal accounts
    • 05Privacy regulations that apply to your role (GDPR, HIPAA, GLBA)
    • 06Reporting privacy incidents the right way

    Outlines reflect our standard curriculum. Custom course development is available on request for an additional fee.

  4. Q4

    Incident response

    Reporting, escalation, year-end review. Lessons learned from the last twelve months of incidents.

    View outline

    When something goes wrong, the first 30 minutes determine the outcome. This module is what your team actually does when an incident hits.

    Course outline

    • 01What counts as an incident vs. a problem
    • 02Your role in the response, no matter your title
    • 03Reporting: who, what, when, and how fast
    • 04Containment basics: what NOT to do
    • 05Lessons learned from the year’s incidents
    • 06Year-end refresher: what changed, what to remember

    Outlines reflect our standard curriculum. Custom course development is available on request for an additional fee.

+ Role-based training

Some roles hold the keys. Train them like it.

Awareness training covers what every employee needs to know — but attackers don’t target job titles equally. The people who administer your systems, move your money, or sign your approvals face threats the rest of the org never sees. Role-based modules train those users for the risks that come with the role, and document that you did.

Each is a full certificate course, assigned person-by-person to the people who hold the role — separate from the quarterly rotation.

  • IT
    First release

    IT Global Admin Security Awareness

    Elevated privileges make an elevated target. For the people who hold the keys to every system.

  • Finance

    Finance & Payments Security Awareness

    Wire fraud and business email compromise aim squarely at the people who move the money.

  • Leadership

    Executive & Leadership Security Awareness

    Whaling, spoofed approvals, and travel exposure — aimed at the names on the org chart.

  • HR

    HR & People Operations Security Awareness

    Résumé-borne malware and PII exposure across hiring, onboarding, and offboarding.

Role-based modules join the catalog as they’re released, starting with IT Global Admin.

+ Monthly bulletins

Between quarters, short-form bulletins keep your team current.

Quick video tips, fresh threat callouts, anything urgent enough that waiting for the next quarterly release isn’t the right answer. Bulletins track participation so admins see who watched — the certificate stays reserved for the quarterly modules.

Admins choose the workflow: bulletins push directly to your team, or sit in a review queue for admin approval before they go out.

Quarterly proves it. Monthly keeps it sharp. Together, a complete SAT program.

Compliance & content

Strong enough for CMMC. Simple enough for everyone else.

Whether you need formal compliance documentation or just want your team trained, the same program works. Our content is CMMC Level 2-ready, NIST 800-171-aligned, and includes the insider threat awareness module that most platforms charge extra for.

Insider threat awareness

Recognize and respond to suspicious behavior, social engineering, and credential abuse. Required for CMMC; valuable for everyone.

CMMC & NIST alignment

Content maps to CMMC Level 2 controls and NIST 800-171 awareness requirements. Audit-ready records, no extra paperwork.

General security awareness

Phishing, password hygiene, data handling, device security, incident response — the bedrock topics every team needs.

Pricing

One certificate per quarter. Monthly bulletins in between. Twelve months at a time.

All plans include the complete security awareness program, M365 SSO, and admin reporting. Annual billing. Monthly available.

Monthly billing still carries a 12-month minimum term.

What's included in every plan

  • 4 certificate-awarding courses per user, per year
  • Quarterly module releases + annual content refreshes
  • Microsoft 365 SSO with multi-domain support
  • Admin dashboards, CSV import, and self-join links
  • Public certificate verification page
  • Recertification and audit-ready records
  • Email support
Nonprofit or school? Security awareness matters everywhere —ask about our discount →

Let's keep this simple.

A short call to understand your environment, your compliance needs, and exactly what an annual program would cost for your team.