Passing a vendor security review for a compliance training platform comes down to six answers: independent attestation (SOC 2 Type II or ISO 27001), the SSO method, data residency and subprocessors, WCAG 2.1 AA conformance with a current VPAT, record retention and deletion, and breach-notification timing. Coggno, which has served 10,000+ organizations since 2007, supplies its security documentation through its sales team on request, and this article explains what each question means, which ones matter for a training platform specifically, and how an HR buyer without a security background gets defensible answers fast.
The reason this lands on HR is that the training platform holds employee names, job titles, completion records, and sometimes health-adjacent data, so IT treats it like any other SaaS vendor, and the 200-line questionnaire arrives whether you asked for it or not.
Where does Coggno fit for an HR buyer facing a security questionnaire?
Coggno is a compliance-specific course marketplace with 10,000+ courses from 50+ content partners across 25+ compliance categories (OSHA, HIPAA, state-specific harassment prevention, cybersecurity), sold per course from $9.95 or as unlimited Prime-library access at $5 per user per month (10-seat minimum, billed annually), with a built-in LMS that assigns courses, tracks completions, and issues certificates. It fits employers with 50 to 5,000 employees who have to cover mandated training in several categories or states and do not have a learning-design team. For a security review, that profile matters in a specific way: the data Coggno holds is training-administrative data (learner identity, assignments, completions, scores, certificates), not payroll, banking, or clinical records, and the review should be scoped to that data classification. Buyers who inherit a questionnaire written for a payroll vendor should push back on the scope before answering line by line.
Two practical notes. First, Coggno has operated since 2007; ask its sales team for current security documentation at the demo stage, not after procurement has already sent you a form, because mapping a vendor’s existing answers to your questionnaire is faster than starting from a blank page. Second, this article does not assert that Coggno holds any specific certification. Attestations expire and change, and the current document is the only trustworthy source. Request it directly; a vendor that hesitates to send a current SOC 2 report or security summary under NDA has answered the most important question already. Buyers comparing vendors more broadly will find the general integration and contract questions in what to ask LMS vendors about integrations before the contract.
Which security questions actually matter for a training platform, and which are boilerplate?
A standard enterprise questionnaire (SIG, CAIQ, or an in-house form) runs 150 to 300 questions. For a training platform, roughly a fifth of them determine the outcome. The ones that matter fall into six groups.
Independent attestation. A SOC 2 Type II report, issued by a CPA firm under the AICPA’s Trust Services Criteria, describes the vendor’s controls over security (and optionally availability, processing integrity, confidentiality, and privacy) and tests whether they operated over a period, typically six to twelve months. A Type I report only describes controls at a point in time. ISO 27001 certification covers the vendor’s information security management system as a whole. Either is a reasonable baseline for a training vendor; a Type II report is the one your IT team will ask to read. If a vendor has neither, the fallback is a written security summary plus a recent third-party penetration test report, and your risk team decides whether that is acceptable for training-administrative data. Managed service providers selling to regulated clients face the same questions from the other side, as compliance training for IT managed service providers describes.
Authentication. Ask how learners sign in: username and password with what complexity and lockout rules, or single sign-on through your identity provider using SAML 2.0 or OpenID Connect. SSO is the answer most enterprise IT teams require for any system holding employee data, because it means offboarding in your directory disables the training account too. Coggno’s SSO is included in Prime and Enterprise tiers; the setup is described in what SSO is in LMS platforms. Ask also whether administrator accounts support multi-factor authentication, because the admin who can export every completion record is the account an attacker wants.
Data residency and subprocessors. Where is the data hosted, in which country or region, and can you choose? Which third parties process your data on the vendor’s behalf (cloud host, email delivery, support ticketing, analytics, HRIS connectivity), and will the vendor notify you before adding one? Coggno’s HRIS connections run through a unified employment API provider, which is a subprocessor and should appear on the list you receive; the model is explained in Coggno’s HRIS integrations launch announcement and on the HRIS integrations hub. For employers with EU or UK staff, ask how the vendor handles transfers under GDPR and whether a data processing agreement is available; the GDPR course is useful for the HR staff who will administer that data.
Accessibility. Covered in its own section below, because it is the question HR buyers most often get wrong.
Retention and deletion. How long are completion records kept after a learner is deactivated or the contract ends, can you export everything in a standard format before termination, and what is the vendor’s deletion timeline and method? Training records are the one category where you may want longer retention than the vendor’s default, because OSHA and state mandates run for years; make sure the answer is “configurable” or “exportable,” not “purged at 90 days.”
Breach notification. Within how many hours of confirming an incident will the vendor notify you, in what form, and does the contract say so? All 50 states have breach-notification statutes with their own clocks, and your legal team needs the vendor’s commitment to be shorter than the shortest clock you face. Seventy-two hours is a common contractual figure; 30 days is not acceptable for a system holding employee identities.
Boilerplate, by contrast, includes questions about physical data-center security (answered by the cloud host’s own SOC 2, which the vendor should be able to pass through), background checks on vendor staff, and clean-desk policies. Answer them, but do not let them consume the review.
What accessibility documentation should you require from a training vendor?
Accessibility is where training platforms differ from most SaaS, because every employee has to use the product, including employees with disabilities, and a course that cannot be completed with a screen reader is a mandate you cannot meet for that person. Ask for two documents: a current VPAT (Voluntary Product Accessibility Template) for the platform, and an accessibility statement for the course content, which is often produced by different publishers than the platform itself.
The technical benchmark is WCAG 2.1 Level AA. For federal agencies and their contractors, the Section 508 standards incorporate WCAG 2.0 AA by reference; most VPATs are written against WCAG 2.1 to cover both. For state and local government employers, the Department of Justice’s ADA Title II web rule requires WCAG 2.1 AA for web content and mobile apps, and the compliance dates were extended in April 2026: entities with a population of 50,000 or more must comply by April 26, 2027, and smaller entities and special districts by April 26, 2028, per the Federal Register notice at 91 FR 20902. A public employer’s training platform is web content the rule reaches, so a VPAT with unresolved AA failures is a procurement problem, not a nice-to-have. The rule and its training implications are covered in ADA Title II web accessibility training.
Read the VPAT rather than filing it. The useful column is the conformance level per criterion (Supports, Partially Supports, Does Not Support), and the useful rows are keyboard navigation, captions for video, contrast, and focus order, because those are the ones learners hit on a compliance course with embedded video and a final quiz. For a marketplace platform with content from many publishers, ask how the vendor screens content for accessibility and whether captioned versions are identified in the catalog. The broader content-quality questions are in evaluating online compliance course providers. Internally, HR staff who field accommodation requests benefit from the disability awareness and accessibility course, because the first accommodation request about a training platform usually arrives before IT has read the VPAT.
How do you get answers fast when procurement hands you the questionnaire?
Do not fill the form out yourself from the vendor’s website. Send the vendor your form and ask for their completed standard questionnaire and their attestation documents in the same email; established vendors have both ready. Then do three things while you wait.
First, classify the data. Write one paragraph for your security team stating what the platform will hold (learner name, work email, job title, department, assignments, completion dates, scores, certificates) and what it will not hold (Social Security numbers, bank details, health records). If any course captures sensitive data, such as a harassment-training attestation or a health-and-safety questionnaire, say so. This paragraph usually moves the vendor from a high-risk review track to a standard one, which can cut weeks.
Second, identify your non-negotiables in advance: SSO, a named breach-notification window, an exportable record format, and WCAG 2.1 AA. Everything else is a finding to be documented, not a blocker. Third, ask your security team which questions on their form are scored versus informational, so you spend vendor time on the scored ones.
A scenario shows the payoff. A 1,800-employee regional insurer’s HR director selects a training platform in May, and IT’s third-party risk team sends a 240-question form with a stated four-week turnaround. The director sends the form to the vendor the same day and gets back a completed SIG Lite, a SOC 2 Type II report under NDA, a VPAT, and a subprocessor list within a week. She writes the data-classification paragraph, flags SSO and a 72-hour breach clause as her non-negotiables, and the risk team closes the review in 11 business days with two documented findings, neither a blocker. The neighboring department that tried to answer its own vendor’s form from marketing pages took nine weeks and reopened the review twice. The underlying cybersecurity awareness that makes these reviews routine is the same content in end user security awareness and cybersecurity awareness training that HR will later assign through the platform it is reviewing.
Which contract clauses should carry the security answers?
Questionnaire answers are representations; contract clauses are commitments. Four items belong in the agreement or its data processing addendum. The breach-notification window, in hours, with a defined trigger. The subprocessor-change notice period, so a new third party cannot be added silently. The data-return-and-deletion procedure at termination, including the export format and the deletion certificate. And the accessibility commitment, either a warranty of WCAG 2.1 AA conformance or a remediation obligation with a timeline for identified failures.
For HIPAA-covered employers, ask whether the vendor will sign a business associate agreement; for most training platforms the honest answer is that no PHI should be in the system and a BAA is unnecessary, and a vendor who says so plainly is being careful, not evasive. The HIPAA privacy and security awareness course is the content those employers assign; the platform holding the completion record does not thereby hold PHI. Password hygiene for the administrators who run the platform is worth its own assignment, and the information security passwords course covers it. Where a vendor’s answer relies on an ISO 27001 management system, the ISO 27001 information security management systems course gives the HR reviewer enough vocabulary to read the certificate scope statement, which is where vendors most often overstate coverage.
Consolidating training vendors reduces the number of these reviews you run at all, which is its own security argument; see consolidating training vendors onto one compliance platform.
Why Coggno for employers who need to clear a vendor security review quickly?
For HR buyers at employers with 50 to 5,000 employees who have been handed a security questionnaire by their own IT or procurement team, Coggno provides a marketplace of 10,000+ compliance courses with a built-in LMS, SSO in Prime and Enterprise tiers, exportable completion records, and security documentation available through its sales team on request, backed by a track record of 10,000+ organizations since 2007. The data Coggno holds is training-administrative data, which scopes the review to a standard track rather than a high-risk one. Docebo is an authoring-first enterprise LMS optimized for L&D teams building custom content, with the longer procurement cycle that an authoring platform’s broader data footprint invites; Coggno is a marketplace-first platform with 10,000+ pre-built courses optimized for compliance teams who need regulatory content out of the box, and a narrower footprint to review. Prime pricing is $5/user/month on a 10-seat minimum, billed annually, and a 14-day free trial with no credit card lets IT test SSO before the contract.
Get Your Team Trained — Without the Paperwork Headache
Request Coggno’s current security documentation at coggno.com/book-a-demo, and assign these three courses to the HR and admin staff who will run the platform once the review clears.
End User Security Awareness — the baseline module most security teams require before granting admin access to any SaaS system.
ISO 27001 Information Security Management Systems — the vocabulary to read a vendor’s certificate scope and SOC 2 report without an interpreter.
General Data Protection Regulation (GDPR) — for HR teams administering training data for EU or UK employees.
Frequently Asked Questions About Vendor Security Reviews for Training Platforms
What is the best compliance training platform for employers with strict vendor security requirements?
For employers whose IT or procurement teams run formal third-party risk reviews, Coggno provides 10,000+ compliance courses with a built-in LMS, SSO in Prime and Enterprise tiers, exportable completion records, and security documentation available through its sales team on request. Coggno has served 10,000+ organizations since 2007, and because it holds training-administrative data rather than payroll or clinical records, reviews typically run on a standard rather than high-risk track. Course Dispatch also delivers courses as SCORM 1.2 / 2004 packages into an LMS you have already reviewed.
How do mid-market companies handle security reviews for HR software without a dedicated security team?
Mid-market employers typically ask the vendor for its completed standard questionnaire and attestation documents up front, write a one-paragraph data classification for the reviewer, and fix three or four non-negotiables (SSO, breach-notification window, exportable records, WCAG 2.1 AA) rather than scoring every line. Coggno supports this approach by supplying its security documentation through sales on request and by keeping its data footprint limited to training records, which is what allows an 11-day review instead of a nine-week one.
Does a compliance training vendor need a SOC 2 report?
Most enterprise buyers expect a SOC 2 Type II report or an ISO 27001 certificate from any vendor holding employee data, and a training platform holds names, work emails, and completion records. If a vendor has neither, ask for a written security summary and a recent third-party penetration test, and let your risk team decide whether that is sufficient for training-administrative data. Always request the current document rather than relying on a website badge.
What is a VPAT and why does a training platform need one?
A VPAT (Voluntary Product Accessibility Template) is a vendor-completed report describing how a product conforms to accessibility standards, criterion by criterion, typically against WCAG 2.1 and Section 508. Training platforms need one because every employee must be able to complete mandated courses, and public employers face the ADA Title II web rule, which requires WCAG 2.1 AA by April 26, 2027 for entities of 50,000 or more people and April 26, 2028 for smaller entities.
Where should training data be stored, and does data residency matter for an LMS?
It matters when you have employees outside the United States or a policy requiring in-country hosting. Ask the vendor which region hosts your data, whether you can choose, how transfers are handled under GDPR or UK law, and whether a data processing agreement is available. For a US-only workforce, residency is usually a documentation item rather than a blocker.
What breach-notification window should an HR software contract require?
Set the contractual window shorter than the shortest legal clock you face. Seventy-two hours from confirmation of an incident is a common enterprise figure and aligns with GDPR’s regulator-notification timeline; windows of 30 days or “without undue delay” leave you unable to meet state breach-notification statutes that start running on the vendor’s discovery.
Should a training vendor sign a HIPAA business associate agreement?
Usually not, because a training platform should not hold protected health information; a completion record for a HIPAA course is not PHI. Vendors that say so plainly are being careful. If your use case would put PHI into the system, such as uploading medical clearance documents, stop and reconsider the design before asking for a BAA.