Compliance is Mandatory. Boredom is Optional.

One training library that satisfies the security awareness control across eight major frameworks — SOC 2, PCI DSS, ISO 27001, HIPAA, NISTCSF, HITRUST, CMMC, and CIS Controls.

Cross-Framework Coverage

01 / 08

01

SOC 2

2017 Trust Services Criteria

Satisfies directly

CC1.4 / CC2.2

Security awareness & communication

What the training reinforces

Day-to-day staff behavior is where these controls hold or fail. The curriculum reinforces access control (CC6), monitoring & incident response (CC7), change management (CC8), availability & backup (A1), and vendor risk (CC9).

02

PCI DSS

v4.0.1

Satisfies directly

Req 12.6

Formal security awareness program

What the training reinforces

Cardholder data is only as safe as the people who handle it. The curriculum reinforces malware defenses (5), secure coding & OWASP (6), least privilege (7), MFA & passwords (8), physical security (9), logging (10), data protection (3), and vendor management (12.8).

03

ISO 27001

:2022

Satisfies directly

Cl. 7.2–7.3 + A.6.3

Competence & awareness

What the training reinforces

Your ISMS leans on people doing the right thing by default. The training reinforces supplier security (A.5.19–5.22), access control (A.5.15–18), data protection, physical security (A.7), and logging (A.8.15).

04

HIPAA

Security Rule

Satisfies directly

§164.308(a)(5)

Security Awareness & Training

What the training reinforces

Protecting PHI starts with everyday staff judgment. The modules reinforce administrative, physical & technical safeguards, incident procedures, and device & media controls.

05

NIST CSF

2.0

Satisfies directly

PR.AT

Awareness & Training

What the training reinforces

Awareness touches every part of your security program, not just one corner. The training reaches all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

06

HITRUST CSF

e1 Assessment

Satisfies directly

Domain 13 / 02.e

Education, training & awareness

What the training reinforces

This is the bar the whole curriculum was built to. Past Domain 13, it reinforces endpoint & portable media protection (02–03), password management (10), access control (11), audit logging (12), third-party assurance (14), incident management (15), and data protection & privacy (19).

07

NIST 800-171 / CMMC

DoD / CUI contractors

Satisfies directly

3.2

Awareness & Training family

What the training reinforces

Handling CUI demands disciplined habits from everyone on the contract. The curriculum reinforces access control, audit & accountability, configuration management, incident response, and media protection — for DoD and CUI contractors.

08

CIS Controls

v8

Satisfies directly

Control 14

Security Awareness & Skills

What the training reinforces

Skilled, aware staff are what make the technical safeguards actually work. The training maps to Controls 3, 4, 5/6, 7, 8, 11, and 15.

One curriculum, built to HITRUST CSF e1 — carrying the awareness layer across all eight frameworks.

One training library, seven frameworks, zero glazed-over eyes.

Industry-specific security modules that satisfy the awareness control from SOC 2 CC1.4 to CIS Control 14 — and that your people actually finish.

Build the Bench. Prove the Competence.

Your Quarterly Assessment. Your Evidence.

Run recurring web app assessments in-house and generate auditor-ready reports on the spot.

SoulEyez satisfies SOC 2 CC4.1/CC7.1 and HITRUST Domain 07 — turning a line item you outsource into evidence you own.


Engagement-First Compliance

A 60-day path into the field for newcomers — and documented role-based development for the security staff you already have.

Certificates of completion give you the evidence ISO 27001 Cl. 7.2 and NIST 800-171 §3.2.2 ask for.

SoulEyez - Testing Is the Control. The Report Is the Proof.

Advanced Pentesting. Audit-Ready Output.

Every framework on this page asks the same two questions: are you looking for vulnerabilities on a defined cadence, and can you prove it? Most teams answer the first with one annual third-party engagement and the second with a scramble through old Slack threads.

SoulEyez collapses both into a single workflow. Run the scan, track the finding through remediation, generate the report — with the full engagement history sitting behind it as your evidence trail.

Satisfies directly
SOC 2 — CC7.1 vulnerability identification and monitoring; CC4.1 periodic control evaluation
HITRUST CSF — Domain 07, Vulnerability Management

Also reinforces
ISO 27001 A.8.8 · NIST CSF 2.0 ID.RA-01 and DE.CM · NIST 800-171 §3.11.2 and §3.12.1 · CIS Controls v8 #7 and #18 · PCI DSS Req 11 scanning and testing activity

Lightweight, open-source friendly, and built to drop into the pipeline you already have.