<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>GetCheckmark blog</title>
  <link>https://getcheckmark.com/blog/</link>
  <description>GetCheckmark — phishing simulation, compliance training, and individual security-awareness certification for regulated industries (SOC 2, ISO 27001, NIST, DORA, PCI DSS).</description>
  <language>en</language>
  <lastBuildDate>2026-04-15</lastBuildDate>
  <atom:link href="https://getcheckmark.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>What SOC 2 auditors are actually looking for in awareness evidence — 2026 update</title>
      <link>https://getcheckmark.com/blog/what-auditors-actually-look-for-2026.html</link>
      <guid isPermaLink="true">https://getcheckmark.com/blog/what-auditors-actually-look-for-2026.html</guid>
      <pubDate>2026-04-10</pubDate>
      <description>The annual update on what SOC 2 auditors prioritise in awareness-evidence reviews, based on the audits our customers ran in 2025.</description>
      <dc:creator>Cormac Walsh</dc:creator>
    </item>
    <item>
      <title>Certification versus attestation — what your auditor actually wants to see</title>
      <link>https://getcheckmark.com/blog/certification-versus-attestation.html</link>
      <guid isPermaLink="true">https://getcheckmark.com/blog/certification-versus-attestation.html</guid>
      <pubDate>2026-03-04</pubDate>
      <description>Many awareness platforms produce "certificates" that have no audit standing. Here's what produces evidence and what doesn't.</description>
      <dc:creator>Liam O'Connor</dc:creator>
    </item>
    <item>
      <title>DORA Article 13 Section 6 in practice — what awareness evidence regulators expect</title>
      <link>https://getcheckmark.com/blog/dora-article-13.html</link>
      <guid isPermaLink="true">https://getcheckmark.com/blog/dora-article-13.html</guid>
      <pubDate>2026-02-08</pubDate>
      <description>Our reading of DORA's training and awareness expectations, based on the first cohort of inspections our customers have undergone.</description>
      <dc:creator>Cormac Walsh</dc:creator>
    </item>
    <item>
      <title>ISO 27001:2022 transition — A.6.3 and A.6.5 in the new control set</title>
      <link>https://getcheckmark.com/blog/iso-27001-transition.html</link>
      <guid isPermaLink="true">https://getcheckmark.com/blog/iso-27001-transition.html</guid>
      <pubDate>2026-01-12</pubDate>
      <description>The 2022 revision reorganised the Annex A controls; awareness-related controls sit in different places under the new structure.</description>
      <dc:creator>Aoife Murphy</dc:creator>
    </item>
    <item>
      <title>PCI DSS v4.0 Requirement 12.6 — awareness expectations evolved</title>
      <link>https://getcheckmark.com/blog/pcidss-v4-awareness.html</link>
      <guid isPermaLink="true">https://getcheckmark.com/blog/pcidss-v4-awareness.html</guid>
      <pubDate>2025-12-05</pubDate>
      <description>PCI DSS v4.0 expanded the security awareness requirement; what the changes mean for customers in payments.</description>
      <dc:creator>Sinéad Ryan</dc:creator>
    </item>
</channel>
</rss>
