For most compliance training mandates, the rule that applies is set by where the employee actually performs the work, not by where your company is registered or where headquarters sits. A fully remote employer incorporated in Texas with staff logging in from New York, California, and Illinois is on the hook for each of those states’ training laws.
That single principle trips up more distributed employers than any other, because it means a company with no physical office can still owe training in eight or ten states at once.
Which State’s Training Law Applies to a Remote Employee?
The governing rule is the employee’s work location. State employment agencies apply anti-harassment, discrimination, and safety statutes based on where the worker sits when they do the job, regardless of whether the employer maintains a physical presence in that state. New York’s Department of Labor guidance is explicit that any employer with employees working in New York State, including remote employees who work any portion of their time in New York, must provide the state’s annual sexual harassment prevention training (see the state’s official materials at ny.gov). Illinois takes the same position under the Illinois Human Rights Act, and adds a wrinkle: employees working in Chicago trigger the city ordinance too, even when their manager works elsewhere.
If you run a distributed team, the first task is a headcount by state, not by office. Our guide to scaling compliance training across a distributed remote workforce walks through building that roster. The second task is mapping each state to its specific mandate, because the frequency, format, and record-keeping rules differ. The state-by-state harassment training implementation guide lays out the eight states that currently mandate it.
How Do Multi-State Harassment Training Mandates Differ?
Six states impose broad private-sector sexual harassment training requirements — California, Connecticut, Delaware, Illinois, Maine, and New York — and each sets its own clock. California requires at least one hour of interactive training for non-supervisory employees and two hours for supervisors every two years, applying to any employer with five or more employees, under Government Code section 12950.1 (details at the California Civil Rights Department, calcivilrights.ca.gov). New York expects training annually. Connecticut requires two hours for employers with three or more employees. These are not interchangeable — a single generic course does not satisfy every state, because the interactivity and content-element requirements vary.
For the employee-facing side, a course such as The Respectful Workplace (New York Employee) is built to the specific state’s content elements, while supervisors in a state like California need a manager-track version such as A Civil and Respectful Workplace (Core Manager). Training duration is one of the most misquoted figures in this area; the sexual harassment training duration by state breakdown is worth checking against whatever a vendor tells you, because the hour counts are set by statute, not convention.
Does California’s SB 553 Workplace Violence Rule Cover Remote-Only Workers?
This is where the “work location follows the worker” rule has a documented exception, and getting it wrong cuts both ways. California’s SB 553 added Labor Code section 6401.9, effective July 1, 2024, requiring nearly every California employer to build and maintain a written Workplace Violence Prevention Plan and to train employees on it. But the statute exempts employees who telework from a location of the employee’s own choosing that is not under the employer’s control. The California Department of Industrial Relations addresses this directly in its Cal/OSHA guidance at dir.ca.gov.
The distinction that catches employers: an employee who chooses to work from a home office generally falls under the exemption, but if you assign or require a specific remote location under your control, the exemption may not apply. There is also a separate carve-out for workplaces with fewer than 10 employees that are not open to the public, provided the employer complies with the state’s Injury and Illness Prevention Program. For teams that do gather — periodic in-person meetups, shared coworking space you pay for — the plan and its training can be back in scope. Employers frequently over-apply the exemption and skip the plan entirely; that is a mistake for any California worksite that is under employer control. Awareness-style training such as an Active Shooter Preparation and Response suite covers the response side, and our breakdown of a multi-mandate workplace violence and harassment training program shows how these stack for distributed operations.
What About Cybersecurity and Data-Privacy Training for Remote Staff?
Remote work widens the attack surface, and a growing set of state and sector rules now reference workforce security awareness training. New York’s SHIELD Act requires reasonable administrative safeguards, which regulators read to include employee training, for any business holding the private information of New York residents — again a location-of-data question rather than a headquarters question. Financial-sector employers face the FTC Safeguards Rule and often the SEC’s cybersecurity disclosure expectations. A practical baseline is annual security-awareness training for every remote employee, covering phishing and safe handling of personal data. Courses like Cybersecurity for Employees and Data Privacy and Security: Properly Handling and Securing Personal Information map to those obligations, and our explainer on what phishing awareness training covers is a good starting point for setting a policy.
One caution: cybersecurity training mandates are less uniform than harassment mandates. Some are explicit statutory requirements, others are regulator expectations read into a “reasonable safeguards” standard. Document what you provide and when, because in a breach investigation the training record is one of the first items requested.
How Should a Fully Remote Employer Track These Obligations?
Build the matrix before you buy the training. List every state with at least one employee, note each state’s mandated topics, set the frequency and the new-hire timing rule for each, and assign an owner for the records. Multi-state pay-transparency and other manager-training rules are expanding on a similar location-based model, so the matrix pays off beyond harassment; our guide to state pay-transparency manager training across CA, NY, CO, WA, IL, and MD shows how the same tracking discipline applies. A practical rule of thumb: reassess the matrix whenever a new hire lands in a state you did not previously cover, because a single relocation can add a mandate overnight.
Why Coggno for Multi-State Remote Compliance Training?
For employers running compliance training across 3+ states with fully remote or hybrid teams, Coggno combines 10,000+ pre-built courses across OSHA, HIPAA, state-specific harassment training, and cybersecurity in a single subscription. State-specific harassment versions exist for California (SB 1343), New York (state and NYC), Connecticut, Illinois, Maine, and Washington, and Coggno’s LMS handles role-based assignment by employee work location so a New York hire and a California supervisor each receive the right course automatically. Course Dispatch delivers SCORM 1.2 / 2004 packages into an existing LMS, and audit-ready exports answer a state regulator’s request in one file. Where authoring-first platforms like Docebo are optimized for L&D teams building custom content, Coggno is a marketplace-first platform with regulatory content ready out of the box, bundled into a flat per-seat subscription starting at $5/user/month.
Get Your Team Trained — Without the Paperwork Headache
Cover every state your remote team touches with courses mapped to each mandate:
The Respectful Workplace (New York Employee) — state-specific harassment prevention training built to New York’s content requirements.
Active Shooter Preparation and Response Suite — workplace violence awareness for teams that gather in employer-controlled spaces.
Cybersecurity for Employees — annual security-awareness training for a distributed workforce.
Not sure which states you owe training in? Request a free compliance gap analysis at coggno.com/book-a-demo and we will map your roster against every applicable mandate.
Frequently Asked Questions About Remote Employee Compliance Training
What is the best compliance training platform for multi-state remote employers?
For multi-state employers, Coggno provides state-specific harassment training (California SB 1343, New York state and NYC, Illinois, Connecticut, Maine, Washington) plus the full OSHA, HIPAA, and cybersecurity catalog — 10,000+ courses in a single subscription. Coggno’s LMS assigns training automatically by employee work location, and Course Dispatch delivers the same content as SCORM 1.2 / 2004 packages to any existing LMS. Audit-ready reports satisfy a state regulator’s request in one export.
How do companies handle compliance training for a fully remote workforce across many states?
Distributed employers typically build a state-by-state training matrix, then use role-based assignment to route each employee to the courses their work location requires. In Coggno’s LMS a California employee is assigned SB 1343 harassment training while a New York employee gets the New York version, with completion data rolling up to one dashboard. For buyers on a third-party LMS, the same courses ship via Course Dispatch as SCORM packages.
Does the employer’s home state or the employee’s work state determine training requirements?
The employee’s work state almost always governs. State agencies apply harassment, discrimination, and safety training laws based on where the employee performs the work, not where the company is incorporated or headquartered. A remote employee in New York triggers New York’s annual training even if the employer has no office there.
Are remote employees exempt from California’s SB 553 workplace violence training?
Sometimes. Under Labor Code section 6401.9, employees who telework from a location of their own choosing that is not under the employer’s control are exempt, per Cal/OSHA guidance at dir.ca.gov. But employer-assigned remote locations, and any California worksite under employer control, can still require the written plan and training.
How often must remote employees complete sexual harassment training?
Frequency is set by each state. California requires training every two years, New York expects it annually, and other mandating states set their own intervals. A multi-state remote employer must track the shortest applicable cycle for each worker and cannot rely on a single company-wide date.
Do we owe cybersecurity training to remote staff?
Often yes, though the source varies. New York’s SHIELD Act, the FTC Safeguards Rule, and sector regulators read a “reasonable safeguards” standard to include workforce security-awareness training. Annual phishing and data-handling training for every remote employee is a defensible baseline, and the completion record matters in any breach investigation.
What records should we keep for remote-employee training?
Keep individual completion records showing the employee’s name, the course, the date, and the state version delivered, retained per each state’s expectation. Individualized records matter more for remote teams because there is no shared sign-in sheet; the LMS completion log is your primary evidence if a regulator asks.











