ISO 27001 security awareness training your team will actually finish.

ISO/IEC 27001 makes security awareness a control your certification auditor checks directly — Annex A 6.3, "Information security awareness, education and training." HACKIN'GAMES delivers that training as fourteen hands-on games across phishing, social engineering, cloud, AppSec and AI, then gives you per-employee completion records you can export as evidence. Real training your people finish, plus the paper trail your auditor wants.

Set up your team — free Free phishing test ▸

Awareness training and completion evidence for Annex A 6.3 — not a full GRC or ISMS platform. Your auditor makes the final certification determination.

Does ISO 27001 require security awareness training?

Yes. Security awareness training is an explicit requirement of ISO/IEC 27001. In the 2022 revision it is Annex A control 6.3, "Information security awareness, education and training" — the same control that was numbered A.7.2.2 in the 2013 version of the standard. It requires that personnel receive appropriate awareness education and training, and regular updates, relevant to their role and to the organization's information security policies.

Awareness also runs through the main clauses of the standard. Clause 7.2 (Competence) requires that people doing work affecting information security are competent and that the organization keeps evidence of it, and Clause 7.3 (Awareness) requires that personnel are aware of the information security policy, their contribution to the ISMS, and the implications of not conforming. Awareness is not a one-off box to tick — it is a recurring obligation woven through the management system.

In practice, a certification auditor checks two things: that an awareness program exists, and that staff have actually completed it, with records to prove it. A documented program with no completion evidence is a finding waiting to happen. Annex A 6.3 is one control among many in an Information Security Management System, so it does not make you certified on its own — but it is one of the controls auditors most reliably ask to see evidence for.

How HACKIN'GAMES satisfies Annex A 6.3

HACKIN'GAMES covers the awareness-training side of control 6.3 — the actual training and the per-person completion evidence — so you can show your auditor both the program and proof your people finished it.

Training and the evidence for control 6.3

Annex A 6.3 wants an awareness program that people complete, with records. Here is how each piece maps:

To be clear about scope: this is security-awareness training plus completion evidence for one control. It does not make your organization ISO 27001 certified by itself, and HACKIN'GAMES is not a GRC or ISMS platform — your certification body makes the final determination.

What your team will train on

Each module is a hands-on game with four difficulty tiers, not a slideshow quiz. The skills map to the threats your auditors and your attackers both care about. A few of the core modules:

Phishing & BEC · Social engineering · Cloud security · Application security · AI / LLM security — plus incident response, password security, cryptography and more, for 14 games in total.

ISO 27001 security awareness training — frequently asked questions

Does ISO 27001 require security awareness training?

Yes. It is an explicit requirement of the standard. In ISO/IEC 27001:2022 it is Annex A control 6.3, "Information security awareness, education and training" (this was A.7.2.2 in the 2013 version). Clauses 7.2 (Competence) and 7.3 (Awareness) reinforce it, requiring personnel to be competent and aware of the information security policy and their role in the ISMS. HACKIN'GAMES provides that training and the completion records to evidence it.

How do I prove training completion to my auditor?

Your team admin dashboard logs per-employee, per-module completion with dates, and you can export a "Security Awareness Training Record" transcript for any team member in one click. You attach that to your ISMS evidence pack alongside your awareness program documentation. We give you the records — your certification auditor reviews them and makes the final determination.

Does gamified training count for ISO 27001?

ISO 27001 does not prescribe a format. Annex A 6.3 asks for appropriate, role-relevant awareness education and training with regular updates — it does not require slideshows. Hands-on, gamified training that people actually complete, backed by completion records, is a legitimate way to deliver and evidence the control. As always, your auditor assesses whether your specific program meets the requirement.

How often is ISO 27001 awareness training required?

The standard calls for awareness to be ongoing with regular updates rather than naming a fixed interval. Most organizations run awareness training at least annually plus onboarding for new hires, and refresh content when threats or policies change. HACKIN'GAMES timestamps every completion, so you can demonstrate a recurring cadence rather than a single point-in-time event.

Does HACKIN'GAMES make us ISO 27001 certified?

No. Certification covers your entire Information Security Management System across many controls and clauses. HACKIN'GAMES satisfies the awareness-training side of one control — Annex A 6.3 — and produces the completion evidence for it. It is not a GRC or ISMS platform and does not replace your certification audit. Your certification body makes the final determination.

Set up your team — free to start Browse all 14 games ▸
HACKIN'GAMES · security awareness training · SOC 2 training · HIPAA training · glossary · all games · ISO 27001 security awareness training & Annex A 6.3 completion evidence. · built by Looms.