Add-on packs

The modules your regulator names. Cited by section.

A pack adds three or four modules written by people who work in that sector, cites the provision it supports on screen and in the record, and exports in the form that framework's reviewer expects. Core first, pack on top, one record.

Available now · design-partner pilot

Clinical & GxP

Clinical sites, CROs, sponsors, and the recruitment and data vendors around them.

  • E.1Clinical trial and regulated data protection
  • E.2Electronic records, audit trails and data integrity
  • E.3Security incident identification, escalation and reporting

21 CFR § 11.10(i) · ICH E6(R3) · ALCOA+

More on this pack →

Roadmap · built with a design partner

Healthcare & HIPAA

Covered entities and business associates: providers, health plans, and the vendors that touch their data.

  • Protected health information and the minimum-necessary standard
  • Recognizing a breach and who to tell, in what order
  • Security reminders, malware, log-in monitoring and passwords as the rule lists them

45 CFR § 164.308(a)(5) · § 164.530(b)(1)

Become the design partner →

Roadmap · built with a design partner

Financial services

Lenders, brokers, advisers, insurers and fintech under the FTC Safeguards Rule.

  • Customer financial information and who may see it
  • Payment fraud, invoice redirection and executive impersonation
  • Training that tracks the risk assessment, as the rule requires

16 CFR § 314.4(e)(1) · NY DFS 23 NYCRR Part 500

Become the design partner →

Roadmap · built with a design partner

Payment card

Merchants and service providers with a cardholder data environment.

  • What cardholder data is and where it is allowed to exist
  • Skimming, tampering and social engineering at the point of sale
  • Handling card data on the phone and in support tools

PCI DSS v4.0 · Requirement 12.6

Become the design partner →

Roadmap · built with a design partner

Cleared & government contractors

Facility security officers running the annual refresher for cleared staff, and suppliers handling controlled unclassified information.

  • Classified and controlled unclassified information: marking, handling, disclosure
  • Counterintelligence, insider threat and operations security awareness
  • Reporting requirements, continuous vetting and foreign travel
  • Periodic security bulletins, read and acknowledged on the record

32 CFR § 117.12(k) · § 117.12(g) · NIST SP 800-171 · CMMC 2.0

Become the design partner →

Roadmap · built with a design partner

SaaS & technology vendors

Companies proving SOC 2 or ISO 27001 to their customers.

  • Customer data handling and tenant isolation, for non-engineers too
  • Secrets, tokens and access hygiene
  • What the auditor will ask about your training, and the evidence they accept

ISO/IEC 27001:2022 · Annex A 6.3 · SOC 2 Trust Services Criteria

Become the design partner →

Roadmap · built with a design partner

Privacy & data protection

Organizations processing EU, UK or state-privacy-law personal data.

  • Lawful handling, purpose limitation and data minimization in daily work
  • Data subject requests and what not to say in the reply
  • Breach notification duties and the internal escalation that makes them meetable

GDPR Art. 32 · Art. 39(1)(b)

Become the design partner →

Roadmap · built with a design partner

Energy & critical infrastructure

Utilities and operators with personnel who touch bulk electric system cyber systems.

  • Operational technology is not IT: the differences that matter to the person at the console
  • Physical and electronic access to protected systems
  • Awareness and role-based training as the standard separates them

NERC CIP-004 · Personnel & Training

Become the design partner →

Roadmap packs are built with a design partner in that sector. If yours is on the list, that partner could be you.

Why packs

Everyone can sell you phishing simulation.

Nobody else will teach your people the module your assessor actually cites.

Incumbents sell one generic curriculum with a compliance module bolted on. Packs are written by people who have sat on the wrong side of an audit in that sector, and every module names the provision it supports — on screen, in the record and in the export.

  • Core first. Everyone completes Tracks A through D. A pack adds to the core; it never replaces it, because the phishing email does not care which regulation you are under.
  • Role variants. Each pack module has a full version for the people who do the work and a short version for everyone else who needs to recognize it.
  • Cited, not implied. A pack module says which section it supports and what a reviewer would look for. No acronym soup, no claims we cannot back.
  • One record. Core and pack completions land in the same training record and the same inspection packet, with the same timestamps, versions and signatures.

What it maps to

Every module cites the provision it supports.

On screen, in the record, and in the export — because that is what the reviewer is checking for.

FrameworkProvisionObligationWhere
HIPAA Security Rule45 CFR § 164.308(a)(5)A security awareness and training program for all workforce members, including periodic reminders, malware protection, login monitoring and password management.Core · Healthcare
HIPAA Privacy Rule45 CFR § 164.530(b)(1)Training of all workforce members on the policies and procedures for protected health information, as necessary for their functions.Healthcare
FDA 21 CFR Part 11§ 11.10(i)Determination that persons who develop, maintain or use electronic record and electronic signature systems have the education, training and experience to perform their assigned tasks.Clinical & GxP
ICH E6(R3) GCPComputerised systemsExpanded expectations for computerised systems, data governance and risk-proportionate quality management across sponsors, CROs and sites.Clinical & GxP
FTC Safeguards Rule16 CFR § 314.4(e)(1)Security awareness training for personnel, updated as necessary to reflect risks identified by the risk assessment.Financial services
PCI DSS v4.0Requirement 12.6Security awareness education as an ongoing activity for all personnel, with acknowledgment of the security policy.Payment card
NISPOM rule32 CFR § 117.12(k)Security education for all cleared employees every 12 months. Methods may include dissemination of instructional materials, and contractors must maintain records about the programs offered and employee participation in them.Cleared & government
NIST SP 800-171Family 3.2Awareness and training requirements for organizations handling controlled unclassified information, the basis of CMMC assessment.Defense & government
ISO/IEC 27001:2022Annex A 6.3Information security awareness, education and training for personnel and relevant interested parties.SaaS & technology
GDPRArt. 32 · Art. 39(1)(b)Security appropriate to risk, and an explicit data protection officer duty covering awareness-raising and training of staff involved in processing.Core · Privacy
NERC CIP-004Personnel & TrainingSecurity awareness and role-based training for personnel with access to bulk electric system cyber systems.Energy
NIST SP 800-53AT control familyAwareness and training controls, for customer security questionnaires and federal or government-contract-adjacent work.Core

Pilot program

Start with the core. Add the pack.

We're onboarding a small number of design partners. Clinical research organizations get the Clinical & GxP pack now; if your sector's pack is on the roadmap, a design partner is how it gets built. You get the program first, we get your audit findings and your people's honest opinion of the content. Fair trade.

Developed with a clinical research design partner · STACSTRAT LLC