What Training Records Get You to Baseline Compliance in 2 Hours?

What Training Records Get You to Baseline Compliance in 2 Hours?

Build training records for baseline compliance in two hours with a defensible ISO 27001 6.3 evidence pack for SMB customers.

LakeRidge Team
July 18, 2026
7 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

You need four training records for baseline compliance: an in-scope personnel roster, a role-to-training and policy mapping, dated completion evidence, and an exceptions list with owners and due dates. For ISO 27001 Annex A control 6.3, this is enough to show that personnel and relevant interested parties received appropriate awareness, education, training, and policy updates for their job functions—provided the completion records are real, not merely assigned. In two hours, an MSSP analyst can assemble this evidence pack when the customer already has a current policy and a way for staff to complete a short awareness module or acknowledgement.

Which training records for baseline compliance are minimally sufficient?

The minimum viable standard is not a polished learning-management program, a phishing simulation history, or a library of role-specific courses. It is a defensible answer to four auditor questions: who needed training, what they needed to receive, when they received it, and what happened when they did not complete it.

For an SMB customer, build one evidence folder or restricted SharePoint library containing the following records:

Record Minimum evidence needed Fastest credible source What it proves
In-scope roster Name, business email, department or role, manager, employment status, and inclusion date Microsoft Entra ID export, Google Workspace directory export, or HRIS report Who was required to receive awareness information or training
Training and policy mapping Course name, policy version, audience, delivery date, and why the content is appropriate A one-page control matrix approved by the customer’s security owner Training was relevant to job function and included policy updates
Completion evidence User name, course or acknowledgement title, completion date, status, and source-system export date KnowBe4, Microsoft Forms, Microsoft Viva Learning, Proofpoint Security Awareness, or LMS export Personnel actually received the assigned material
Exception and remediation log Non-completer name, reason, manager, due date, compensating action, and closure date SharePoint List, Jira Service Management, HaloITSM, or ticketing platform The customer is managing incomplete training instead of ignoring it

For control 6.3, do not limit the roster to employees. Include temporary workers, contractors, outsourced IT personnel, and other relevant interested parties when they access customer information, systems, facilities, or administrative tools. A contractor with a Microsoft 365 account and privileged access is in scope; a prospective supplier with no access is not.

Baseline training evidence should also identify the policy version communicated. An acknowledgement that says only “I read the policies” is weak if it cannot be tied to a specific information security policy and date. Use a clear title such as Information Security Policy v3.2 — July 2026 Acknowledgement.

What should happen during hours 0–4?

The first two hours produce the minimum evidence set; hours two through four are reserved for validating exports, chasing immediate completions, and documenting exceptions. This sequence matters because an assignment report alone does not demonstrate that personnel received the content.

Hours 0–1: establish scope and select the shortest credible content

  1. Confirm the customer’s control owner. This is usually the managing director, operations manager, IT manager, or designated information security manager—not the MSSP analyst.
  2. Export active users from Microsoft Entra ID or Google Workspace. Remove shared mailboxes, service accounts, disabled users, and clearly out-of-scope accounts.
  3. Identify relevant third parties with access. Ask the customer’s owner to confirm the list in writing or in the service ticket.
  4. Locate the current information security policy and any topic-specific procedures already in use, such as acceptable use, password management, incident reporting, and remote working.
  5. Select a short training package. For a rapid baseline, use a 10–20 minute security-awareness module plus a policy acknowledgement. For privileged administrators, add a short administrative-access or incident-reporting module if one already exists.

Do not write a new 30-page policy in the two-hour window. If the customer has no approved information security policy, record that as a governance gap. You can prepare the training structure, but you cannot credibly claim that staff received regular updates of a policy that does not yet exist.

Hours 1–2: issue training and preserve the evidence trail

Configure the campaign using a tool the customer already operates. In KnowBe4, create a campaign named ISO27001-A6.3-Baseline-July2026, assign the active-user group, enable completion tracking, and set a due date within five business days. In Microsoft 365, use Microsoft Forms for the policy acknowledgement, require organizational sign-in, record names, disable anonymous responses, and export the results to an access-controlled SharePoint location.

The minimum content should cover the customer’s security expectations, phishing and social engineering reporting, password and MFA expectations, data handling, incident escalation, and the consequences of bypassing security procedures. A role-based mapping can be simple: all staff receive awareness and policy content; finance receives payment-fraud guidance; IT administrators receive privileged-access and change-management reminders.

Hours 2–4: capture completed evidence and open exceptions

Download a dated completion export after the initial response period. Save the native CSV or PDF export, not only a screenshot. Screenshots are useful for context, but exports preserve user-level evidence that can be tested later.

  • Save the original roster export with its extraction date.
  • Save the course assignment configuration or Forms settings.
  • Save the completion export with the reporting date and system name.
  • Reconcile the roster against completion status.
  • Create a ticket or exception-log entry for every non-completer.
  • Ask the customer’s control owner to confirm the scope and approve the exceptions list.

If everyone in scope completes the short module and acknowledgement during the window, the customer has a credible baseline for this control. If some people are still outstanding, describe the result accurately: the customer has a functioning training process and an open compliance gap, not completed compliance. That distinction protects both the customer and the MSSP during an audit.

What must be completed during days 1–7?

The first week turns an emergency evidence pack into a repeatable control. The objective is to close exceptions, improve relevance by role, and establish the next update cycle required by ISO 27001.

  1. Send automated reminders at two and four business days before the due date, with managers copied only for overdue users.
  2. Escalate non-completion through the named manager and document the resulting decision: completion, access restriction, leave status, or approved extension.
  3. Provide targeted content to higher-risk groups. Finance users should receive payment-change verification guidance; help desk staff should receive identity-verification guidance; administrators should receive privileged-access and incident-handling reminders.
  4. Set an annual awareness campaign and a trigger-based update process for policy changes, major incidents, material technology changes, or new high-risk roles.
  5. Record new-hire training expectations, such as completion within five business days of account creation or employment start.

For managed customers, retain the training-evidence packet by campaign period: roster, policy version, assignment settings, completion export, exceptions, manager escalations, and final closure report. This makes future surveillance audits much easier than reconstructing evidence from old emails.

What have you intentionally deferred, and why is that acceptable?

A quick-start should defer maturity work that does not change whether the customer can demonstrate the core requirement today. You are not deferring the control; you are deferring optimization.

  • Phishing simulations: useful for measuring behavior, but not required to prove basic awareness delivery and policy communication.
  • Custom training production: customer-branded videos and tailored scenarios improve engagement, but a credible existing module is sufficient for an initial baseline.
  • Competency testing: quizzes and passing thresholds are valuable, especially for technical roles, but completion evidence and appropriate content are the urgent priorities.
  • Full HRIS and LMS automation: manual monthly roster reconciliation is acceptable while the customer evaluates integrations.
  • Detailed learning analytics: completion rates by department and risk trends are maturity indicators, not first-day evidence.

The important boundary is that deferred work must not hide a missing requirement. You may defer a sophisticated training catalogue, but not the communication of the current security policy. You may defer automated onboarding, but not training for a newly hired administrator with active access.

When should an SMB upgrade from quick-start to a mature training program?

Upgrade when the customer has recurring personnel changes, handles sensitive customer data, uses privileged cloud administration, experiences phishing incidents, or needs to demonstrate sustained effectiveness to customers, insurers, or auditors. A mature program adds role-based curricula, onboarding and offboarding integrations, policy-change triggers, periodic phishing exercises, manager dashboards, exception metrics, and periodic management review.

For the MSSP, the practical trigger is repeated manual effort: if you are rebuilding the roster, chasing the same overdue users, or explaining policy versions from email threads every quarter, move the customer to a managed workflow with recurring campaigns and retained evidence.

Open a customer ticket this week to validate the roster, issue the first campaign, and store the resulting evidence pack under the customer’s ISO 27001 control 6.3 folder.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.