Cybersecurity
Security awareness training for small businesses: what you are actually required to have
Last updated 2026-09-29
Short answer: a small business is legally required to train staff on security awareness only if a specific rule covers it. Tax preparers and other financial businesses fall under the FTC Safeguards Rule at any size, healthcare providers and their business associates under the HIPAA Security Rule, and anyone taking card payments under PCI DSS, which is the only one of the three that sets a yearly cadence. None of them requires phishing simulations. What all of them need is a record of who was trained, when, and on what.
That matters because the big security awareness platforms are built for hundreds of seats, and a seven- or twenty-person company shopping for one tends to find quote forms, minimums and features it will never use. Start from what you are required to show, then buy the smallest thing that shows it.
Which rule applies to you
| If you are | Rule | What it requires | How often |
|---|---|---|---|
| Tax preparers, lenders, and other financial businesses | FTC Safeguards Rule, 16 CFR 314.4(e) | Security awareness training for staff, updated as risks change | No fixed interval in the rule; IRS guidance recommends regular refreshers |
| Healthcare providers and their business associates | HIPAA Security Rule, 45 CFR 164.308(a)(5) | A security awareness and training program for all workforce members, including management | No fixed interval; "periodic security updates" is an addressable item |
| Businesses that take card payments | PCI DSS v4.0, Requirement 12.6 | Security awareness training covering phishing and social engineering | On hire and at least once every 12 months |
Tax preparers: size does not get you out of training
The FTC rule lists tax preparation firms as financial institutions, and section 314.4(e) requires “security awareness training that is updated as necessary to reflect risks identified by the risk assessment.” The small-firm exemption in 314.6, for firms holding information on fewer than 5,000 consumers, removes four provisions: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan and the annual report. Training is not one of them. IRS Publication 5708 adds that tax professionals need a written information security plan “regardless of size,” and Publication 4557 tells them to “provide security awareness training and schedule regular refreshers.” A first hire, remote or not, should be trained before they are given access to client data.
Healthcare and business associates
The HIPAA Security Rule requires covered entities and business associates to “implement a security awareness and training program for all members of its workforce (including management).” The detailed items under it, such as security reminders and password management, are addressable, which means you decide how to meet them and document why. The rule does not set a frequency.
Card payments: the one with a yearly clock
PCI DSS v4.0 requirement 12.6.3 says personnel receive security awareness training “upon hire and at least once every 12 months,” and 12.6.3.1 requires it to cover phishing and social engineering. For the smallest merchants, the PCI Council’s own guidance says a simple program can be as modest as a flyer in the back office or a periodic email, as long as it exists and is maintained.
Phishing simulations, frequency and format
No rule on this page requires simulated phishing tests; PCI requires phishing to be covered in the training, which is a different thing. Simulations are a reasonable addition once people have been taught what to look for, and some cyber insurers ask about them, so read your own policy. On format, the FTC and HIPAA rules do not prescribe live or online delivery. The constant is evidence: a dated record per person that shows the training happened and what it covered.
Free, cheap, and when to pay
CISA publishes no-cost resources for small and medium businesses, including material on phishing, passwords, multi-factor authentication and updates. For a business no rule covers, that may be enough. Paying makes sense when you need to prove completion to someone else: an insurer at renewal, a customer’s security questionnaire, or a PCI or Safeguards review.
Our courses are priced per seat with no minimum: cybersecurity awareness at $49, PCI DSS security awareness at $59, HIPAA for the general workforce at $59, and GLBA Safeguards Rule awareness at $79. Each trainee gets a dated certificate with an ID anyone can verify, and team buyers can export the roster for an auditor. The price per seat falls as headcount rises; see team pricing.
Common questions
Is security awareness training legally required for a small business?
Only if a rule covers you. The main ones are the FTC Safeguards Rule for financial businesses including tax preparers, the HIPAA Security Rule for healthcare providers and their business associates, and PCI DSS for businesses that take card payments. Outside those, the pressure usually comes from cyber insurers and customer security questionnaires rather than a law.
Our tax practice has fewer than 5,000 clients. Are we exempt?
Not from training. The FTC exemption for firms holding information on fewer than 5,000 consumers removes four provisions: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual report. Staff security awareness training, 314.4(e), is not on that list. The IRS also says tax preparers need a written information security plan regardless of size.
Do we have to run phishing simulations?
None of these rules requires simulated phishing tests. PCI DSS requires the training itself to cover phishing and social engineering. Simulations can be useful, and some insurers ask about them, so check your own policy wording.
Does training have to be annual?
Under PCI DSS, yes: on hire and at least every 12 months. The FTC rule says only that training must be updated as necessary to reflect risks, and the HIPAA Security Rule sets no interval. Annual training is still the common practice, and the IRS sample security plan uses it.
Is there a free option?
Yes. CISA publishes no-cost security resources for small and medium businesses, including material on phishing, passwords, multi-factor authentication and software updates. What free material usually does not give you is a dated completion record per person, which is what an insurer, auditor or customer asks to see.
Will an auditor accept live training instead of a platform?
The FTC and HIPAA rules do not specify a delivery method, and PCI DSS asks for multiple methods of communication. What every one of them needs is evidence: who was trained, when, and on what. Whether a particular assessor accepts a given format is their call, so ask before you rely on it.
Not legal advice. Rules as published on eCFR and by the IRS and PCI Security Standards Council, checked September 2026.
Related training
Security awareness training with a record you can show
Every certificate we issue can be checked at certifiedtrainingusa.com/verify. Training a team? Seat bundles and invoicing.