Home » Case studies » IT Compliance Training LMS Case Study
A software company pursuing SOC 2 Type II and ISO 27001 certification while already subject to GDPR, needing to prove ongoing, role-specific security awareness training across its engineering, DevOps, and IT staff.
One annual security-awareness video covered every employee identically, tracked in a spreadsheet someone updated by hand whenever a completion email came in. That held up fine when the only ask was “does everyone get trained once a year,” but pursuing SOC 2 and ISO 27001 at the same time, on top of existing GDPR obligations, meant proving something more specific: which employee completed which module, on what date, against which exact control. No single system was set up to answer that.
| Statistic | Description |
|---|---|
| 66% | Share of U.S. CISOs who name human error, not a technology gap, as their organization’s most significant cyber vulnerability. |
| 3 | Overlapping frameworks—SOC 2 (CC1.4/CC2.2), ISO 27001 (Annex A 6.3), and GDPR (Article 39)—each independently requiring documented, ongoing security awareness training for technical staff. |
| Missing evidence | The most common finding in security-awareness audits is not missing training itself, but the absence of per-employee, per-control completion records. |
For a software company whose engineers and DevOps staff carry the most access to production systems and customer data, the training itself mattered less to auditors than proving, employee by employee and control by control, that it had actually happened.
The company moved compliance and cybersecurity training onto SimpliTrain, assigning role-based modules automatically and generating audit-ready evidence as a byproduct of training running instead of a separate project before every audit.
| Metric | Before | After |
|---|---|---|
| Training assignment | One annual video, same for everyone | Role-based, triggered at time of access |
| Completion evidence | Manually tracked spreadsheet | Automated, per-employee, per-control records |
| New hire security training | Waited for next annual cycle | Assigned immediately upon role access |
| Audit prep for training evidence | Days of manual reconciliation | Pulled directly as a report |
“Auditors don’t want to hear that everyone watched a video once. They want to know who completed which module, on what date, against which specific control. We used to spend days pulling that together by hand before an audit; now it’s a report I generate in a few minutes.”
– IT Compliance Manager
Pursuing SOC 2 and ISO 27001 at the same time, on top of existing GDPR obligations, meant the training itself was never really the hard part. Proving it happened, employee by employee and control by control, was. Moving it onto one platform turned that proof into a report instead of a scramble before every audit.
Reach out to us to learn more.