Training
The training both frameworks require, and check for.
SOC 2 and ISO/IEC 27001:2022 both expect documented, recurring training, not a one-time slide deck. We run that program for you and keep the records an auditor asks for.
Three tracks
Security awareness
The baseline every employee takes: phishing, password hygiene, data handling, incident reporting.
Phishing simulation
Ongoing, realistic simulations with reporting, not a one-time email that gets forgotten by next quarter.
Secure development
Role-based training for engineers on the controls that require it: the track most vendors skip.
Why this is a compliance requirement, not a nice-to-have
Both frameworks name training explicitly. SOC 2's Security criterion expects evidence that personnel understand their responsibilities; ISO/IEC 27001:2022's Annex A People theme requires it outright. An auditor isn't just checking that training happened once. They're checking that it's recurring, documented, and that engineers with elevated access get training scoped to what they actually touch.
That's the gap generic training platforms leave: a company-wide phishing module satisfies the baseline, but it doesn't cover secure coding for the engineers who ship the product, or the role-based tracks an auditor will ask about for anyone with production access. Radcore builds the program to match what your specific report will need to show.
Find out which gaps are actually blocking your report.
Thirty minutes with Luke, our security lead. No charge.