ClickCerts
Back to all posts

What Auditors Actually Accept as Proof of Training

A sign-in sheet isn't evidence. What assessors look for when they evaluate security awareness training, and the five artifacts that close the finding.

October 1, 2026ClickCerts Team
What Auditors Actually Accept as Proof of Training

Most training findings don't come from companies that skipped training. They come from companies that trained people and couldn't prove it afterward.

The distinction matters because the fixes are completely different. One requires buying a program. The other requires understanding what an assessor is actually looking at when they evaluate this control — which is narrower and more mechanical than most people assume.

The three questions behind every control

An assessor works from objectives, not vibes. For any control, they're determining three things:

  1. Is there a documented expectation? A policy or procedure that says this happens, to whom, and how often.

  2. Is there evidence it was performed? Artifacts showing the activity actually occurred.

  3. Does the evidence cover the assessment period? Dates that fall inside the window under review, for the people in scope.

Policy, artifact, period. Any answer that satisfies all three closes the item. Any answer missing one of them generates a follow-up, and follow-ups are where assessments stall.

For security awareness training specifically, NIST 800-171 and CMMC frame the requirement in two parts that people often collapse into one: general awareness for everyone with system access, and role-based training for people whose jobs carry specific security responsibilities. There's a third piece on insider threat awareness. An assessor will look at them separately, so it helps to know which of your evidence answers which.

One thing worth clearing up, because it comes up constantly: the fifteen basic safeguarding requirements at CMMC Level 1 don't include a security awareness training practice. If you're a Level 1 contractor, this control isn't scored against you. Your cyber insurance application still asks about it, and your prime may still flow it down — but they're separate obligations from the CMMC Level 1, and it's worth knowing which pressure you're actually responding to.

What doesn't count

None of these are hypothetical. They're all things companies confidently hand over.

A sign-in sheet. It proves attendance, not completion, and it proves it for whoever happened to sign. It doesn't tell an assessor what was covered or whether anyone absorbed it.

A screenshot of the training platform. Shows the tool exists. Says nothing about who finished. A vendor invoice. Proves you bought training. Same gap.

"All staff completed training in Q1." An assertion, not evidence. The obvious follow-up is show me the list — and if the list has to be reconstructed from memory and email threads, you've turned a five-minute item into a week.

Content with no completion data. The deck or the video library is the what. The assessor needs the who and when attached to it.

A record that doesn't reconcile to your access list. This is the subtle one, and it's where otherwise-organized companies get caught. Your training report lists 34 people. Your system access list has 41. The seven-person delta is now the entire conversation. Contractors, seasonal staff, the shop-floor account, the person who left in March and whose account is still enabled — every one of those is a finding waiting to happen, and it's frequently an access-control problem surfacing through the training control.

The five artifacts that close it

A training policy. One or two pages. Who must be trained, on what, how often, what happens when someone doesn't complete it, and who owns the program. Dated and approved. This is the "documented expectation" leg, and the most commonly missing one — plenty of companies train diligently with no written policy behind it.

A roster reconciled to your access list. Every person with system access, tied to a completion status. This is the artifact that turns "we trained everyone" into a verifiable claim. Build it from your access list, not from your training tool's user list, or you'll rebuild the delta problem.

Per-person completion records with dates. Name, course, completion date. Dates inside the assessment period, or a documented cadence showing the coverage is continuous.

The course content or a syllabus. Enough for an assessor to see the material maps to what's required — phishing and social engineering, handling of sensitive information, incident reporting, insider threat indicators. A module list with descriptions is usually sufficient; you rarely need to hand over the videos.

Evidence of role-based training where it applies. Your finance team on payment fraud verification. Your admins on privileged access handling. This is the leg most often missing entirely, because companies treat "everyone took the annual module" as the whole requirement.

Assemble those five and this control stops being an assessment problem. It becomes a folder.

The cadence question

"Annual" is the reflex answer, and it's frequently not what the framework actually says. NIST-derived requirements talk about periodic training and training triggered by events — new hires, role changes, significant system changes. HIPAA's language is similarly periodic rather than calendar-annual. Your carrier's application may ask for something more specific than either.

Where annual gets you in trouble is coverage. If training happens every January and your assessment window is a rolling twelve months ending in September, someone hired in February has been in scope for seven months with no completion record. Technically you train annually. Practically you have a gap in the period under review, and the assessor is looking at the period.

A shorter cycle solves this structurally instead of procedurally. Quarterly training means any twelve-month window contains multiple completion events for every active employee, and a new hire is never more than 90 days from their first record. You stop having to remember to run an off-cycle session for new starts.

That's the design behind how ClickCerts works: quarterly courses on 90-day windows, each ending in a dated certificate with a verifiable serial, plus an exportable completion record you can reconcile against your access list. It handles one row of the assessment — the training row — and does it completely. It won't write your policy or fix your access list, and you'll still want both.

Two things to do this week

Run the reconciliation. Export your system access list. Export your training completion data. Compare them. Whatever the delta is, that number is what an assessor will find, and you'd rather find it first. This takes twenty minutes and is the single highest-value thing in this post.

Write the policy if you don't have one. One or two pages. Who, what, how often, what happens on non-completion, who owns it. Date it and get it approved. It's the cheapest finding you'll ever close, and it's the one companies most often walk into an assessment without.

The reframe

Assessors aren't trying to catch you. They're trying to determine whether a control operated during a defined period, using documents.

That's a much easier bar to clear than "prove your security program is good" — but only if your program produces documents as a byproduct rather than requiring an archaeology project every time someone asks. Training that generates a dated, per-person record every quarter clears it without anybody having to remember anything.

If your company is seeking CMMC certification, you may be interested in these posts.

CMMC Phase 2 Is Suspended. Your Training Obligation Isn't CMMC and Security Awareness Training: What the Framework Actually Requires CMMC Assessors: Here's a Security Awareness Training Tool You Can Actually Recommend

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.