Compliance

Awareness evidence for
the frameworks you answer to.

KeenSec helps you produce the evidence behind the people side of your security obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements, all tied to named employees and dates.

What KeenSec provides
Evidence of awareness activity, per person and per date
Records
Simulation results, report logs, training, certificates, acknowledgements
Who decides compliance
Your auditor or regulator
Coverage
Frameworks from the markets you operate in, plus global standards

By region

Pick the framework
your auditor asks about.

Each page explains where security awareness fits in that framework and which KeenSec records help you show it.

INDIA

DPDP Act 2023 and Rules 2025

Security safeguards and breach reporting from May 2027.

See the evidence
INDIA

CERT-In Directions and advisories

6-hour incident reporting, plus CERT-In’s 2025–2026 advice on phishing training and realistic simulations.

See the evidence
INDIA

SEBI CSCRF

Mandatory awareness programmes, Board training and periodic phishing tests for SEBI-regulated entities.

See the evidence
INDIA

RBI Cybersecurity Directions 2026

Mandatory awareness for new recruits and annual training for management and the Board, under RBI’s July 2026 Directions.

See the evidence
INDIA

IRDAI Cyber Security Guidelines 2026

Tracked awareness training, phishing handling and annual assurance audits for insurers and intermediaries.

See the evidence
SAUDI ARABIA

NCA ECC-2:2024

Control 1-10-3 of Saudi Arabia’s NCA Essential Cybersecurity Controls (ECC-2:2024) requires the awareness programme to cover secure handling of email, especially phishing emails, plus mobile devices and storage media, safe browsing and social media, and the newer NCNICC-1:2025 controls bring similar awareness duties to non-critical private companies..

See the evidence
SAUDI ARABIA

SAMA Cyber Security Framework

The SAMA Cyber Security Framework, section 3.1.6, requires a cyber security awareness programme for staff, third parties and customers, run periodically throughout the year, covering threats such as spear-phishing and whaling, and evaluated to measure its effectiveness..

See the evidence
UAE

UAE Information Assurance Standard v2.1

The UAE Information Assurance Standard v2.1, published by the UAE Cybersecurity Council in November 2025, requires federal entities and critical information infrastructure entities to maintain an awareness and training programme, evaluate its effectiveness and keep records of awareness campaigns..

See the evidence
SINGAPORE

MAS TRM Guidelines

The MAS Technology Risk Management Guidelines of 18 January 2021 expect a comprehensive IT security awareness training programme for all staff, delivered at least annually to staff, contractors and service providers, with technology-risk training for the board..

See the evidence
GLOBAL

PCI DSS v4.0.1

PCI DSS v4.0.1 Requirement 12.6 requires a formal security awareness programme and training on hire and at least every 12 months, and since 31 March 2025 that training must cover phishing and social engineering, alongside automated anti-phishing mechanisms under Requirement 5.4.1..

See the evidence
GLOBAL

ISO/IEC 27001:2022

ISO/IEC 27001:2022 includes an Annex A control on information security awareness, education and training, and since 31 October 2025 certification is to the 2022 edition only, because certificates to the 2013 edition expired or were withdrawn at the end of the transition..

See the evidence
EU

NIS2 Directive

NIS2 (Directive (EU) 2022/2555) requires members of management bodies to follow cybersecurity training, lists basic cyber hygiene practices and cybersecurity training among the risk-management measures entities in scope must take, and asks Member States to encourage regular training for employees..

See the evidence
EU

GDPR

GDPR requires appropriate technical and organisational security for personal data, including a process for regularly testing and evaluating how well those measures work, and gives the data protection officer the task of awareness-raising and training for staff involved in processing..

See the evidence
US

HIPAA

The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management..

See the evidence

One platform, one record

The evidence pack,
whatever the framework.

SIMULATION RESULTS

Who was tested, on which channel.

Email, SMS and RCS, voice, WhatsApp, Microsoft Teams and Slack, with outcomes per person and campaign.

REPORT LOGS

Who reported, and what the analysis found.

Every Phishing Reporter submission, with its automated verdict and timestamps.

TRAINING AND CERTIFICATES

Who learned what, and when.

LMS completions, assessment results and certificates for every learner.

POLICY ACKNOWLEDGEMENTS

Who signed which version.

Policy Manager keeps a dated record per person, policy and version.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Questions buyers ask

Frequently asked questions.

Does KeenSec make us compliant?

No tool makes you compliant on its own. KeenSec runs your awareness programme and produces the records, and your auditor or regulator decides whether your organisation meets the framework.

What evidence does KeenSec produce?

Simulation results, Phishing Reporter logs with automated analysis, LMS completions and certificates, policy acknowledgements, and the reminder and escalation trail behind them.

Which frameworks does KeenSec support?

These pages cover DPDP, CERT-In Directions, SEBI CSCRF, RBI, NCA ECC, SAMA CSF, UAE IA, MAS TRM, PCI DSS, ISO 27001, NIS2, GDPR and HIPAA. The same records can support other frameworks with awareness expectations.

Let’s connect the dots

From lure to lesson
to evidence.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo