GRC · Workforce Training Obligations
Training Requirements Checker
Select the frameworks a client is subject to and see the workforce security-training obligations each one imposes — what's explicitly mandated, what's derived, who it applies to, and where it comes from. Built to catch the gaps (like CJIS AI-use training) before an auditor does.
Select all
Clear
Reset checkboxes
↓ Export coverage
⎙ Print / Save as PDF
Explicit topic
Derived / expected
Role-based
Scope & caveats. This tool covers workforce security-awareness / role-based training obligations only — not the full control set of any framework. "Explicit" means the topic is named in the standard; "Derived / expected" means it flows from a general training clause or assessor/regulator guidance rather than an enumerated list. Frequency and applicability thresholds change (e.g. Reg S-P smaller-entity date, CJIS v6.0 rollout to Oct 2027). Verify against the current authoritative text for each client's exact obligations and dates before relying on this for an assessment. Your framework selections and coverage checkboxes are saved in this browser (localStorage) and restored on reload; Export coverage writes a CSV of the selected frameworks, topics, and covered/not-covered status; Print / Save as PDF produces a clean light-background document (choose "Save as PDF" as the printer destination) for handouts and assessment attachments. Data current as of the July 2026 build.