Zum Hauptinhalt springen
Starter Kit · Register

Training Register

Updated on 2 min Reviewed by: Cenedril-Redaktion
Clause 7.3A.6.3 ISO 27001NIS2 Art. 21(2)(g)

The training register documents who completed which training, when — and when the next refresher is due. Without this register, you cannot demonstrate in an audit that your team holds the competencies your ISMS assumes.

ISO 27001 requires in A.6.3 (Awareness, Education and Training) that all personnel receive appropriate training and that completions are recorded. NIS2 demands in Art. 21(2)(g) “basic cyber hygiene practices and cybersecurity training”. The register is where you prove both.

What does it contain?

The CSV template maps one row per training attendance. The columns:

  • Person / Role — who attended and in which ISMS role
  • Training / Type — name of the training and whether it was internal or external
  • Due Date / Completion Date / Status — planned date, actual completion, current state
  • Evidence — reference to certificate, attendance confirmation or LMS entry
  • Next Refresh — when the next refresher is due

How to use it

Initial population: Enter all personnel in ISMS-relevant roles and document training already completed. Mark missing evidence as “Overdue” — this gives you an immediate action list.

Ongoing maintenance: After every training event, update Completion Date, Evidence and Next Refresh. Once a quarter, check whether refreshers are coming due and schedule them in time.

Audit preparation: Auditors typically select three to five roles and verify documented training evidence. A complete register with linked proof answers these questions in seconds.

Register Template

Training Register

PersonRoleTrainingTypeDue DateCompletion DateStatusEvidenceNext Refresh
Anna WeberInformation Security OfficerISO 27001 Lead ImplementerExternal certification2026-06-302025-11-12CompletedCert #LI-27001-448212028-11-12
Anna WeberInformation Security OfficerIncident response tabletopInternal drill2026-05-152026-03-20CompletedDrill report 2026-Q12027-03-20
Markus SchulzIT Operations LeadCIS Linux Benchmark workshopExternal training2026-07-31Planned
Markus SchulzIT Operations LeadBackup restore drillInternal drill2026-04-302026-04-02CompletedDrill report BCM-2026-012027-04-02
Sophie LangDeveloperOWASP Top 10 workshopInternal training2026-03-312026-03-28CompletedAttendance sheet 2026-03-282027-03-28
Sophie LangDeveloperSAST tool onboardingInternal training2026-05-31In progress
Julia HoffmannData Protection OfficerCIPP/E refresherExternal training2026-09-30Planned
Julia HoffmannData Protection OfficerDPIA workshopExternal training2026-06-302026-02-14CompletedCert DPIA-2026-1122028-02-14
Thomas KrügerHR LeadBackground screening refresherInternal training2026-08-31Planned
Elena FischerFinance LeadCEO fraud / BEC workshopExternal training2026-05-312026-04-03CompletedWorkshop confirmation BEC-262027-04-03
All Employees (42)All EmployeesSecurity Awareness 2026E-learning2026-06-30In progress (28/42 completed)LMS report 2026-04-132027-06-30
All Employees (42)All EmployeesPhishing simulation Q1Simulation2026-03-312026-03-25CompletedLMS report PS-2026-Q12026-09-30
All Employees (42)All EmployeesAcceptable Use Policy acknowledgementE-learning2026-04-30In progress (35/42)LMS report 2026-04-132027-04-30
New Hires (4)All EmployeesOnboarding security inductionClassroomWithin 2 weeks of start3 of 4 completedHR onboarding sheet

Sources

ISO 27001 Controls Covered

Clause 7.3 Awareness A.6.3 Information security awareness, education and training

Frequently asked questions

Which training events belong in the register?

Everything ISMS-relevant: internal awareness sessions, external certifications (e.g. ISO 27001 Lead Implementer), product training with a security angle, and role-specific courses (e.g. secure coding for developers). Auditors check whether every ISMS role has documented competence development.

How often should training be refreshed?

ISO 27001 does not prescribe a fixed interval. In practice, 12 months for general awareness and 24–36 months for external certifications work well. The register includes a Next Refresh column — enter the date there and use it as a reminder trigger.

Is a spreadsheet sufficient as training evidence?

For the audit, yes — as long as entries are complete (person, role, training, type, completion date, evidence). The CSV template covers exactly these columns. The key is to archive the actual proof (certificate, attendance confirmation) alongside the register entry.