Skip to main content

Insights / Training Requirements

Cybersecurity Awareness Training Requirements, By Regulation

A regulation-by-regulation look at employee cybersecurity awareness training obligations.

By Joseph Boyd, Licensed Virginia Insurance ConsultantLast updated

Direct answer

Several federal and state regulations require cybersecurity awareness training for employees, including HIPAA, the FTC Safeguards Rule, PCI DSS, New York's cybersecurity regulation, and Virginia's Insurance Data Security Act. Whether a specific requirement applies to your organization depends on your industry, location, and the type of data you handle.

Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check

Published · Last reviewed

Scope: Cybersecurity awareness training requirements in selected United States regulations · Jurisdiction: United States

General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.

Training requirements by regulation

Cybersecurity awareness training requirements by regulation
RegulationWhat It RequiresCitationWho It Generally Applies To
HIPAA Security RuleRequires a security awareness and training program for all workforce members, including management45 CFR 164.308(a)(5)(i)Healthcare providers, health plans, and their business associates that handle electronic protected health information
FTC Safeguards RuleRequires security awareness training for all personnel, updated to reflect the organization's risk assessment16 CFR 314.4(e)Non-bank financial institutions, including auto dealers, mortgage brokers, tax preparers, and retailers offering financing
PCI DSS v4.0Requires a formal, documented security awareness program, with training at hire and at least annuallyRequirement 12.6Any organization that stores, processes, or transmits payment card data
New York DFS Cybersecurity RegulationRequires regular cybersecurity awareness training for all personnel, updated to reflect identified risks23 NYCRR 500.14Banks, insurers, and other entities licensed by the New York Department of Financial Services
Virginia Insurance Data Security ActRequires licensees to provide personnel with cybersecurity awareness training as part of a written information security programVa. Code 38.2-623Insurance licensees operating in Virginia
NAIC Insurance Data Security Model LawThe model law that Virginia and a number of other states adopted, generally including a personnel training requirementVaries by state adoptionInsurance licensees in states that have adopted the model law

This table identifies training provisions that exist in the text of each regulation. It does not determine whether a specific regulation applies to your organization, which depends on your industry, the states you operate in, and the type of data you handle. Confirm applicability with counsel or another appropriate adviser before relying on this page for a compliance decision.

Frequently asked questions

Does completing security awareness training satisfy a specific regulation?

Training is one requirement among several under most of these regulations. Satisfying a specific regulation typically requires the training to meet that regulation's frequency, content, and documentation standards, in addition to other program elements the regulation requires.

Which regulation applies to my business?

Applicability depends on your industry, the states you operate in, and the type of data you handle. A regulatory applicability assessment can help identify which requirements are relevant to your specific situation.

Clarify Your Position

How certain are you that your organization could prove its cybersecurity answers today?

A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.

Call Infosec Check

(855) 624-6262
Prefer a return call?

Your information will be used only to respond to this inquiry. See our Privacy Policy.