Compliance
Awareness evidence for
the frameworks you answer to.
KeenSec helps you produce the evidence behind the people side of your security obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements, all tied to named employees and dates.
- What KeenSec provides
- Evidence of awareness activity, per person and per date
- Records
- Simulation results, report logs, training, certificates, acknowledgements
- Who decides compliance
- Your auditor or regulator
- Coverage
- Frameworks from the markets you operate in, plus global standards
By region
Pick the framework
your auditor asks about.
Each page explains where security awareness fits in that framework and which KeenSec records help you show it.
DPDP Act 2023 and Rules 2025
Security safeguards and breach reporting from May 2027.
See the evidence INDIACERT-In Directions and advisories
6-hour incident reporting, plus CERT-In’s 2025–2026 advice on phishing training and realistic simulations.
See the evidence INDIASEBI CSCRF
Mandatory awareness programmes, Board training and periodic phishing tests for SEBI-regulated entities.
See the evidence INDIARBI Cybersecurity Directions 2026
Mandatory awareness for new recruits and annual training for management and the Board, under RBI’s July 2026 Directions.
See the evidence INDIAIRDAI Cyber Security Guidelines 2026
Tracked awareness training, phishing handling and annual assurance audits for insurers and intermediaries.
See the evidence SAUDI ARABIANCA ECC-2:2024
Control 1-10-3 of Saudi Arabia’s NCA Essential Cybersecurity Controls (ECC-2:2024) requires the awareness programme to cover secure handling of email, especially phishing emails, plus mobile devices and storage media, safe browsing and social media, and the newer NCNICC-1:2025 controls bring similar awareness duties to non-critical private companies..
See the evidence SAUDI ARABIASAMA Cyber Security Framework
The SAMA Cyber Security Framework, section 3.1.6, requires a cyber security awareness programme for staff, third parties and customers, run periodically throughout the year, covering threats such as spear-phishing and whaling, and evaluated to measure its effectiveness..
See the evidence UAEUAE Information Assurance Standard v2.1
The UAE Information Assurance Standard v2.1, published by the UAE Cybersecurity Council in November 2025, requires federal entities and critical information infrastructure entities to maintain an awareness and training programme, evaluate its effectiveness and keep records of awareness campaigns..
See the evidence SINGAPOREMAS TRM Guidelines
The MAS Technology Risk Management Guidelines of 18 January 2021 expect a comprehensive IT security awareness training programme for all staff, delivered at least annually to staff, contractors and service providers, with technology-risk training for the board..
See the evidence GLOBALPCI DSS v4.0.1
PCI DSS v4.0.1 Requirement 12.6 requires a formal security awareness programme and training on hire and at least every 12 months, and since 31 March 2025 that training must cover phishing and social engineering, alongside automated anti-phishing mechanisms under Requirement 5.4.1..
See the evidence GLOBALISO/IEC 27001:2022
ISO/IEC 27001:2022 includes an Annex A control on information security awareness, education and training, and since 31 October 2025 certification is to the 2022 edition only, because certificates to the 2013 edition expired or were withdrawn at the end of the transition..
See the evidence EUNIS2 Directive
NIS2 (Directive (EU) 2022/2555) requires members of management bodies to follow cybersecurity training, lists basic cyber hygiene practices and cybersecurity training among the risk-management measures entities in scope must take, and asks Member States to encourage regular training for employees..
See the evidence EUGDPR
GDPR requires appropriate technical and organisational security for personal data, including a process for regularly testing and evaluating how well those measures work, and gives the data protection officer the task of awareness-raising and training for staff involved in processing..
See the evidence USHIPAA
The HIPAA Security Rule, at 45 CFR 164.308(a)(5), requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management..
See the evidenceOne platform, one record
The evidence pack,
whatever the framework.
Who was tested, on which channel.
Email, SMS and RCS, voice, WhatsApp, Microsoft Teams and Slack, with outcomes per person and campaign.
Who reported, and what the analysis found.
Every Phishing Reporter submission, with its automated verdict and timestamps.
Who learned what, and when.
LMS completions, assessment results and certificates for every learner.
Who signed which version.
Policy Manager keeps a dated record per person, policy and version.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Questions buyers ask
Frequently asked questions.
Does KeenSec make us compliant?
No tool makes you compliant on its own. KeenSec runs your awareness programme and produces the records, and your auditor or regulator decides whether your organisation meets the framework.
What evidence does KeenSec produce?
Simulation results, Phishing Reporter logs with automated analysis, LMS completions and certificates, policy acknowledgements, and the reminder and escalation trail behind them.
Which frameworks does KeenSec support?
These pages cover DPDP, CERT-In Directions, SEBI CSCRF, RBI, NCA ECC, SAMA CSF, UAE IA, MAS TRM, PCI DSS, ISO 27001, NIS2, GDPR and HIPAA. The same records can support other frameworks with awareness expectations.
Let’s connect the dots
From lure to lesson
to evidence.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo