SOC 2 expects you to train every person on their security responsibilities and to keep evidence that they did it. HACKIN'GAMES delivers that training as fourteen hands-on games — phishing, social engineering, cloud misconfiguration, AI prompt injection and more — and produces the per-employee completion records and exportable transcript your auditor reviews as evidence for the Trust Services Criteria.
No credit card to start. This is SOC 2 security awareness training plus completion evidence — not a GRC platform, and not a full SOC 2 program on its own.
Yes — in practice. SOC 2 is not a checklist of literal controls; it's an attestation against the AICPA Trust Services Criteria. The criterion most directly tied to security awareness is Common Criteria CC2.2: the entity internally communicates information, including security objectives and responsibilities, necessary to support the functioning of internal control. Telling people what they are responsible for — and confirming they received it — is exactly what an awareness program does. Closely related is CC1.4 (commitment to attracting, developing and retaining competent individuals), which auditors read to include keeping personnel competent on security topics.
Because the criteria are outcome-based, SOC 2 auditors translate CC2.2 and CC1.4 into a concrete expectation: documented security-awareness training for all personnel, with evidence that each person completed it — typically at onboarding and at least annually. During the audit, the assessor doesn't just ask whether training exists; they sample employees and review the actual completion records as evidence that the control operated.
So the practical question isn't "is training required" — it's "can you prove every person was trained, on the right topics, on a recurring basis." That proof is what most teams scramble for at audit time, and it's what HACKIN'GAMES is built to produce.
We cover the two halves an auditor checks for the awareness control: real training that reaches every person, and durable evidence each person completed it.
HACKIN'GAMES gives you the deliverables the assessor samples against CC2.2 / CC1.4:
Honest scope: this satisfies the security-awareness-training piece of SOC 2 and produces the completion evidence for it. It does not by itself make your organization SOC 2 compliant — a SOC 2 report covers many other controls — and your auditor makes the final determination on whether the evidence meets the criteria.
Every module is a hands-on game with four difficulty tiers, not a slideshow or a quiz — so employees practice the decision instead of memorizing a slide. Coverage spans the threats your SOC 2 auditor and your attackers both care about:
Phishing & BEC · social engineering · cloud security & misconfiguration · application security (SQLi / XSS) · AI / LLM prompt-injection security — plus incident response, password security, cryptography and more across the full library.
Effectively, yes. SOC 2 is an attestation against the AICPA Trust Services Criteria rather than a list of named controls, but the criteria CC2.2 (internally communicating security objectives and responsibilities) and CC1.4 (commitment to competence) lead auditors to expect documented security-awareness training for all personnel, with evidence each person completed it — usually at onboarding and at least annually.
Your auditor samples employees and reviews completion records as evidence the control operated. HACKIN'GAMES gives you per-employee, per-module completion records with dates in your admin dashboard, plus a one-click exportable "Security Awareness Training Record" transcript per person. You hand that to the auditor as the evidence for CC2.2 / CC1.4. The auditor still makes the final determination on whether it satisfies the criteria.
SOC 2 doesn't prescribe a format — it cares that personnel are trained on their security responsibilities and that you can evidence completion. Hands-on games satisfy that just as a slideshow would, and tend to drive much higher real completion. What an auditor reviews is the topic coverage and the per-person completion records, both of which HACKIN'GAMES provides.
The criteria don't state a fixed cadence, but auditors typically expect training at onboarding for new hires and a refresh at least annually for everyone, since a SOC 2 Type II report covers an operating period. You can re-run modules each cycle in HACKIN'GAMES and the completion dates roll up so you can show the recurring evidence.
No — and we won't claim it does. HACKIN'GAMES satisfies the security-awareness-training control (CC2.2 / CC1.4) and produces the completion evidence for it. A SOC 2 report covers many other controls across security, availability and more, and HACKIN'GAMES is not a GRC platform. Your auditor or assessor makes the final determination on your overall report.