Track A
Human attack surface
- A.1Phishing, spear phishing, smishing and social engineering
- A.2Password security and multi-factor authentication
- A.3Secure email, internet and communication practices
Security awareness with a defensible record
Continuous security awareness for any organization that has to prove its people were trained. Twelve core modules, monthly reinforcement, and a training record built to be inspected — so when an auditor, an assessor or a customer says show me your evidence, it takes ninety seconds, not two weeks.
Regulated? Add the pack your framework names: 21 CFR Part 11 · HIPAA · GLBA · PCI DSS · NIST 800-171 · ISO 27001
Illustrative export. Every completion produces one of these.
The problem
Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.
Then someone asks for proof. A customer security questionnaire, a SOC 2 auditor, a HIPAA risk analysis, a cyber-insurance renewal, an FDA inspector. Every one of them wants the same thing: who was trained, on what, when, and can you show it. A completion checkbox in a generic LMS is not an answer.
Annual compliance video
Trained State
Core curriculum
Tracks A through D are the security awareness canon, written for busy professionals rather than for a generic office. Every organization gets them. Add-on packs go deeper where a specific framework says you must.
Track A
Track B
Track C
Track D
Add-on packs
A pack adds three or four modules written by people who work in that sector, cites the provision it supports on screen and in the record, and exports in the form that framework's reviewer expects. Core first, pack on top, one record.
Design-partner pilot · available now
Clinical sites, CROs, sponsors, and the recruitment and data vendors around them.
21 CFR § 11.10(i) · ICH E6(R3) · ALCOA+
The clinical research page →Roadmap · built with a design partner
Covered entities and business associates: providers, health plans, and the vendors that touch their data.
45 CFR § 164.308(a)(5) · § 164.530(b)(1)
Roadmap · built with a design partner
Lenders, brokers, advisers, insurers and fintech under the FTC Safeguards Rule.
16 CFR § 314.4(e)(1) · NY DFS 23 NYCRR Part 500
Roadmap · built with a design partner
Merchants and service providers with a cardholder data environment.
PCI DSS v4.0 · Requirement 12.6
Roadmap · built with a design partner
Suppliers handling controlled unclassified information under CMMC and DFARS.
NIST SP 800-171 · Awareness and training family (3.2) · CMMC 2.0
Roadmap · built with a design partner
Companies proving SOC 2 or ISO 27001 to their customers.
ISO/IEC 27001:2022 · Annex A 6.3 · SOC 2 Trust Services Criteria
Roadmap · built with a design partner
Organizations processing EU, UK or state-privacy-law personal data.
GDPR Art. 32 · Art. 39(1)(b)
Roadmap · built with a design partner
Utilities and operators with personnel who touch bulk electric system cyber systems.
NERC CIP-004 · Personnel & Training
Roadmap packs are built with a design partner in that sector. If yours is on the list, that partner could be you.
Why packs
Nobody else will teach your people the module your assessor actually cites.
Incumbents sell one generic curriculum with a compliance module bolted on. Packs are written by people who have sat on the wrong side of an audit in that sector, and every module names the provision it supports — on screen, in the record and in the export.
How it runs
Four modes, one program. The annual course is the floor, not the whole building.
Annual
The core curriculum plus your packs, assessed against a pass threshold and closed with an electronic signature. Roughly an hour, adjusted by role. This is the artifact an auditor asks for.
Monthly
One unit of three to five minutes, plus a phishing simulation. Rotates through the tracks so no topic goes more than a quarter without contact.
On event
Triggered by a real incident, a new customer requirement or an emerging threat. Under three minutes, published within 48 hours. This is what makes a program feel alive rather than annual.
Always on
Every completion writes a durable record: what, when, which version, what score, whose signature. Export the whole population as an inspection packet, or one person as a training file.
The record
Most training platforms treat reporting as an afterthought — a CSV of names and dates, assembled the week before an audit. When someone is checking your work, the record is the deliverable. It has to be attributable to a real person, contemporaneous with the act, tied to the exact content version, and impossible to quietly change.
Trained State applies the data integrity principles that regulated industries have used for decades to its own records. The audit trail is computer-generated, independently timestamped, and retained for the life of the record. Content versions are frozen at completion, so a record from 2026 still shows what the person was actually taught in 2026.
Trained State supports your Part 11, HIPAA, GLBA and similar obligations. It does not make an organization compliant on its own — compliance depends on your procedures, your validation and how you use the system.
What it maps to
On screen, in the record, and in the export — because that is what the reviewer is checking for.
| Framework | Provision | Obligation | Where |
|---|---|---|---|
| HIPAA Security Rule | 45 CFR § 164.308(a)(5) | A security awareness and training program for all workforce members, including periodic reminders, malware protection, login monitoring and password management. | Core · Healthcare |
| HIPAA Privacy Rule | 45 CFR § 164.530(b)(1) | Training of all workforce members on the policies and procedures for protected health information, as necessary for their functions. | Healthcare |
| FDA 21 CFR Part 11 | § 11.10(i) | Determination that persons who develop, maintain or use electronic record and electronic signature systems have the education, training and experience to perform their assigned tasks. | Clinical & GxP |
| ICH E6(R3) GCP | Computerised systems | Expanded expectations for computerised systems, data governance and risk-proportionate quality management across sponsors, CROs and sites. | Clinical & GxP |
| FTC Safeguards Rule | 16 CFR § 314.4(e)(1) | Security awareness training for personnel, updated as necessary to reflect risks identified by the risk assessment. | Financial services |
| PCI DSS v4.0 | Requirement 12.6 | Security awareness education as an ongoing activity for all personnel, with acknowledgment of the security policy. | Payment card |
| NIST SP 800-171 | Family 3.2 | Awareness and training requirements for organizations handling controlled unclassified information, the basis of CMMC assessment. | Defense & government |
| ISO/IEC 27001:2022 | Annex A 6.3 | Information security awareness, education and training for personnel and relevant interested parties. | SaaS & technology |
| GDPR | Art. 32 · Art. 39(1)(b) | Security appropriate to risk, and an explicit data protection officer duty covering awareness-raising and training of staff involved in processing. | Core · Privacy |
| NERC CIP-004 | Personnel & Training | Security awareness and role-based training for personnel with access to bulk electric system cyber systems. | Energy |
| NIST SP 800-53 | AT control family | Awareness and training controls, for customer security questionnaires and federal or government-contract-adjacent work. | Core |
Who it's for
Security and compliance leads answering questionnaires and SOC 2 or ISO 27001 auditors, who need training evidence that does not have to be assembled by hand.
Providers, plans and business associates whose risk analysis and workforce training are the first two things a HIPAA reviewer asks about.
Sites, CROs, sponsors and trial vendors who get audited by sponsors and inspected by regulators. There is a page for you.
Organizations whose regulator or contract names a training requirement by section, and whose assessor will check for it.
Pilot program
We're onboarding a small number of design partners. Clinical research organizations get the Clinical & GxP pack now; if your sector's pack is on the roadmap, a design partner is how it gets built. You get the program first, we get your audit findings and your people's honest opinion of the content. Fair trade.
Developed with a clinical research design partner · STACSTRAT LLC