One training library that satisfies the security awareness control across eight major frameworks — SOC 2, PCI DSS, ISO 27001, HIPAA, NISTCSF, HITRUST, CMMC, and CIS Controls.
Compliance is Mandatory. Boredom is Optional.
Cross-Framework Coverage
01 / 08
SOC 2
2017 Trust Services Criteria
Compliance Training — satisfies directly
CC1.4 / CC2.2
Security awareness & communication
SoulEyez — satisfies directly
CC7.1 / CC4.1
Vulnerability identification & periodic control evaluation
What the training reinforces
Day-to-day staff behavior is where these controls hold or fail. The curriculum reinforces access control (CC6), monitoring & incident response (CC7), change management (CC8), availability & backup (A1), and vendor risk (CC9).
PCI DSS
v4.0.1
Compliance Training — satisfies directly
Req 12.6
Formal security awareness program
SoulEyez — satisfies directly
Req 11
Regular scanning & testing of systems and networks
What the training reinforces
Cardholder data is only as safe as the people who handle it. The curriculum reinforces malware defenses (5), secure coding & OWASP (6), least privilege (7), MFA & passwords (8), physical security (9), logging (10), data protection (3), and vendor management (12.8).
ISO 27001
:2022
Compliance Training — satisfies directly
Cl. 7.2–7.3 + A.6.3
Competence & awareness
SoulEyez — satisfies directly
A.8.8
Management of technical vulnerabilities
What the training reinforces
Your ISMS leans on people doing the right thing by default. The training reinforces supplier security (A.5.19–5.22), access control (A.5.15–18), data protection, physical security (A.7), and logging (A.8.15).
HIPAA
Security Rule
Compliance Training — satisfies directly
§164.308(a)(5)
Security Awareness & Training
SoulEyez — supports
§164.308(a)(1)(ii)(A) & (a)(8)
Risk analysis & periodic technical evaluation
The Security Rule names no explicit scanning requirement — these are the nearest analogues, and scanning is evidence toward them rather than the control itself.
What the training reinforces
Protecting PHI starts with everyday staff judgment. The modules reinforce administrative, physical & technical safeguards, incident procedures, and device & media controls.
NIST CSF
2.0
Compliance Training — satisfies directly
PR.AT
Awareness & Training
SoulEyez — satisfies directly
ID.RA-01 / DE.CM
Vulnerability identification & continuous monitoring
What the training reinforces
Awareness touches every part of your security program, not just one corner. The training reaches all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
HITRUST CSF
e1 Assessment
Compliance Training — satisfies directly
Domain 13 / 02.e
Education, training & awareness
SoulEyez — satisfies directly
Domain 07
Vulnerability management
What the training reinforces
This is the bar the whole curriculum was built to. Past Domain 13, it reinforces endpoint & portable media protection (02–03), password management (10), access control (11), audit logging (12), third-party assurance (14), incident management (15), and data protection & privacy (19).
NIST 800-171 / CMMC
DoD / CUI contractors
Compliance Training — satisfies directly
3.2
Awareness & Training family
SoulEyez — satisfies directly
3.11.2 / 3.12.1
Vulnerability scanning & periodic control assessment
What the training reinforces
Handling CUI demands disciplined habits from everyone on the contract. The curriculum reinforces access control, audit & accountability, configuration management, incident response, and media protection — for DoD and CUI contractors.
CIS Controls
v8
Compliance Training — satisfies directly
Control 14
Security Awareness & Skills
SoulEyez — satisfies directly
Controls 7 & 18
Continuous vulnerability management & penetration testing
What the training reinforces
Skilled, aware staff are what make the technical safeguards actually work. The training maps to Controls 3, 4, 5/6, 7, 8, 11, and 15.
Every framework here asks the same two things of you: that your people know better, and that you are looking for holes on a cadence. The training library covers the first, SoulEyez covers the second, and both leave an evidence trail. Neither is certification on its own — each framework asks for more than these two controls.
SoulEyez - Testing Is the Control. The Report Is the Proof.
Advanced Pentesting. Audit-Ready Output.
Every framework on this page asks the same two questions: are you looking for vulnerabilities on a defined cadence, and can you prove it? Most teams answer the first with one annual third-party engagement and the second with a scramble through old Slack threads.
SoulEyez collapses both into a single workflow. Run the scan, track the finding through remediation, generate the report — with the full engagement history sitting behind it as your evidence trail.
Satisfies directly
SOC 2 — CC7.1 vulnerability identification and monitoring; CC4.1 periodic control evaluation
HITRUST CSF — Domain 07, Vulnerability Management
Also reinforces
ISO 27001 A.8.8 · NIST CSF 2.0 ID.RA-01 and DE.CM · NIST 800-171 §3.11.2 and §3.12.1 · CIS Controls v8 #7 and #18 · PCI DSS Req 11 scanning and testing activity
Lightweight, open-source friendly, and built to drop into the pipeline you already have.

