Security Awareness Training for MSPs: How to Build and Sell It as a Recurring Compliance Service in 2026
Security awareness training is explicitly required under HIPAA, SOC 2, CIS Controls, and most cyber insurance policies. This guide covers what each framework requires, how to run SAT across dozens of client environments, and how to package it as a recurring service.
Security Awareness Training for MSPs: How to Build and Sell It as a Recurring Compliance Service in 2026
TLDR: Security awareness training (SAT) is explicitly required under HIPAA, SOC 2, CIS Controls, NIST CSF, and most cyber insurance policies — and it's one of the most defensible recurring services an MSP can offer. This guide covers what each framework mandates, how to run a multi-tenant SAT program efficiently, and how to package it as a monthly compliance service that generates evidence auditors and insurers will actually accept.
Every MSP conversation about compliance eventually hits the same wall: you can lock down the firewall, enforce MFA, and patch every known vulnerability, and your client's employees will still open phishing emails, reuse passwords, and plug unknown USB drives into their workstations.
68% of breaches involve a non-malicious human element — errors, social engineering, and credential misuse rather than technical exploits ([Verizon 2024 Data Breach Investigations Report](https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom)). That percentage hasn't moved meaningfully in years, despite billions spent on endpoint tooling. The reason is simple: technology controls technology. Human behavior requires training.
Security awareness training addresses the single largest category of breach causation. It satisfies multiple compliance frameworks simultaneously. And when packaged correctly, it generates a recurring revenue stream your clients renew annually without being asked. This guide covers how to build it.
Why Human Risk Is the Control Technology Can't Replace
Before any training, one in three employees will click a phishing simulation link — the global baseline phish-prone percentage is 33.1%. Run a consistent program with monthly simulations and quarterly content updates for twelve months, and that number drops by 86%, to 4.1% ([KnowBe4 Phishing by Industry Benchmarking Report, 2025](https://www.knowbe4.com/press/knowbe4-report-reveals-security-training-reduces-global-phishing-click-rates-by-86)).
That's not a marginal improvement. It's a structural change in how your clients' employees respond to the most common initial access vector in modern attacks. Annual-only training doesn't produce sustained change — click rates drop for a few weeks, then climb back to baseline. Ongoing programs hold the improvement.
The business case for your clients is straightforward: credential phishing is the leading cause of ransomware incidents and business email compromise (BEC) events, and cyber insurance carriers are actively tracking training programs at renewal. A client without documented SAT is paying more for coverage — and may face coverage gaps if they file a claim and can't prove ongoing training existed. The MSP cyber insurance approval checklist covers what carriers require and how to document it.
What the Frameworks Actually Require
Security awareness training is a documented compliance obligation in every major framework, not an optional best practice.
HIPAA. The Security Rule at 45 CFR §164.308(a)(5) requires covered entities to "implement a security awareness and training program for all members of its workforce (including management)" ([HIPAA Journal, 45 CFR §164.308(a)(5)](https://www.hipaajournal.com/45-cfr-164-308a5-security-awareness-and-training/)). This applies to every employee connected to organizational IT — not only clinical staff with direct patient data access. Four addressable implementation specifications accompany it: security reminders, malware protection training, log-in monitoring awareness, and password management. Documentation must be retained for six years.
SOC 2. Common Criteria CC1.4 requires the entity to hire, train, and retain personnel with the security competencies needed to meet its control objectives. Missing employee training completion records are among the most common SOC 2 qualified findings — auditors need per-employee logs covering the full audit period, not a summary report ([SOC 2 Auditors, CC1.4 Security Awareness Training](https://soc2auditors.org/insights/soc-2-employee-security-awareness-training/)). See the [SOC 2 compliance checklist for MSPs](/blog/soc-2-compliance-checklist-msp-2026) for the complete evidence list.
CIS Controls v8. Control 14 (Security Awareness and Skills Training) covers role-based training, phishing simulation cadence, and annual completion tracking — all mapped to Implementation Groups 1, 2, and 3.
NIST CSF 2.0. The PR.AT (Awareness and Training) category under the Protect function requires role-appropriate training for all users as a baseline cybersecurity program element.
Cyber insurance. Coalition, Chubb, Travelers, At-Bay, and most other major carriers include security awareness training as a standard underwriting question. Carriers increasingly ask for phishing simulation programs and completion rates — not just a checkbox. A carrier that requires "ongoing training" and gets a 45-minute annual video as evidence has grounds to dispute a social-engineering claim.
The Four Components of a Defensible SAT Program
An MSP-delivered security awareness program that satisfies all of these frameworks simultaneously has four components. Each one maps directly to the evidence artifacts auditors and underwriters request.
1. Baseline Phishing Assessment
Run a phishing simulation before any training begins. The baseline phish-prone percentage serves two purposes: it gives you a before/after metric to demonstrate ROI, and it identifies which employees and departments represent the highest current risk. The baseline report is also a compelling sales tool — most clients have no idea a third of their employees would click a phishing link.
2. Structured Training Content
Annual training is the compliance minimum; quarterly refreshers are standard for HIPAA and SOC 2 clients. Content must cover phishing recognition, password hygiene, social engineering tactics, safe data handling, and incident reporting procedures. Add role-based modules for privileged users — finance, HR, IT administrators — to satisfy CC1.4's competency requirements and HIPAA's heightened obligations for workforce members with elevated system access.
3. Ongoing Phishing Simulations
Monthly or quarterly phishing simulations are what separate a compliant program from a sustainable one. Ongoing simulations maintain the behavioral improvement that annual campaigns cannot hold, and they generate the dated per-campaign records that cyber insurance underwriters are starting to request at renewal. Employees who fail a simulation should automatically receive remedial micro-training — most enterprise SAT platforms support this workflow.
4. Completion and Evidence Records
This is where most in-house programs fail. Auditors do not accept a screenshot of a training platform dashboard or a summary email from an LMS. They need per-employee completion logs with employee name, training module, completion date, and assessment score — covering the entire audit period, with no gaps. For HIPAA clients, those records must be retained for six years. Building a program that automatically generates exportable, per-employee evidence at month-end is not optional — it is the deliverable.
Running SAT Across Multiple Client Environments
The MSP challenge is multi-tenant scale. Manually tracking completion rates and scheduling phishing campaigns across 30 separate client tenants is not a repeatable operation.
The practical approach is to standardize on an SAT platform that supports multi-tenant management from a single admin console: tenant isolation with separate client environments, centralized completion reporting you can aggregate without logging into each instance individually, bulk phishing campaign scheduling, and automated escalation when an employee fails a simulation threshold.
The platforms most commonly deployed in MSP SAT programs are KnowBe4 (largest content library, mature multi-tenant reporting, MSP partner program), Proofpoint Security Awareness Training (strong integration with email security controls), and Hoxhunt (behavior-change methodology, strong for high-frequency simulation programs). Platform choice matters less than the tenant structure you configure and the deliverable you commit to.
Your monthly deliverable to each client should be a compliance summary: completion rates by department, phishing simulation results versus baseline, trend over time, and a flagged list of employees who are persistently non-compliant. That summary is both the client's compliance evidence and the visible proof of your service value — the thing that makes them renew without needing to be sold again.
The Evidence Package Auditors and Insurers Want
When an auditor or insurance underwriter requests SAT evidence, they are looking for:
- **Per-employee completion logs**: Name, date, module, and assessment score. Not a summary. Not a percentage. Individual records for every employee, covering the full audit or policy period.
- **Phishing simulation records**: Dated records of every campaign — who was targeted, what template was used, who clicked, who reported, and what follow-up training was triggered.
- **Policy acknowledgment records**: Signed (digital) acknowledgment of the security policy, acceptable use policy, and framework-specific policies such as a HIPAA Workforce Security policy or SOC 2-aligned information security policy.
- **Role-based training records**: Evidence that privileged users received additional training beyond the standard annual module.
- **Remedial training records**: Documentation that employees who failed phishing simulations completed follow-up training, with dates.
Six years for HIPAA. Full audit period for SOC 2. Two to three years for most insurance purposes. Build the record-keeping into the platform — not into a spreadsheet.
How to Package and Price SAT as a Service
Security awareness training sells best as part of a compliance services package rather than standalone. Clients who understand they need HIPAA or SOC 2 compliance already understand SAT is part of that obligation — bundling removes the line-item price negotiation.
A practical packaging structure:
- **Base compliance tier (included)**: Annual training module, quarterly phishing simulations, per-employee completion records, annual policy acknowledgment.
- **Regulated vertical add-on** (healthcare, finance, defense): Monthly phishing simulations, role-based training for privileged users, semi-annual program review, framework-specific module content (HIPAA workforce security, SOC 2 information security policy training).
- **Standalone SAT** (for clients who need the control but aren't on a full compliance program): Per-seat pricing, typically $8–$18/seat/month depending on platform and content tier, with a minimum seat count to make it worth managing.
The ROI conversation is easy when you show a client their baseline phish-prone percentage. A third of their employees clicking a phishing link in a controlled simulation is the most compelling argument for security investment you will ever deliver — more effective than threat statistics or technical briefings, because it is their own data about their own people.
Build It Now
Security awareness training closes the human gap that no technical control can fully address. It satisfies HIPAA, SOC 2, CIS Controls, and cyber insurance requirements simultaneously — the rare compliance service that earns its keep across every framework your clients fall under.
Nuronus maps security awareness training requirements across all 11 compliance frameworks, including HIPAA, SOC 2, CIS Controls v8, and NIST CSF, so you always know exactly what evidence each client needs and which gaps remain open. The free plan covers two clients with all features, no credit card required. Your clients' employees are one phishing email away from a breach. The training program that changes that is your service to deliver.
Ready to Add Compliance Services to Your MSP?
Free forever for 2 clients. All features included. No credit card required.
Get Started FreeBrett Coffin
Founder, Nuronus
20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.