Train your team on the vulnerabilities you actually have.
Your scan findings decide what your developers and analysts learn next. Verified completions are logged as audit evidence for the training controls in CMMC, NIST 800-53, SOC 2, HIPAA, PCI DSS and ISO 27001.
One loop from scan to trained team
The same CWE mapping that ties a finding to a compliance control also ties it to the training that prevents it from coming back.
- 01
Upload scan
Upload scanner output or run the free CLI. Findings are enriched with EPSS, CISA KEV and CVSS.
- 02
Map to controls
Findings that carry a CWE map to the controls they threaten across 13 frameworks.
- 03
Assign targeted training
The CWEs in your open findings decide which courses each person is recommended and assigned.
- 04
Export evidence
Completions are tracked and verified, then exported as a CSV your auditor can check.
From CWE to course
An illustrative example of our CWE-to-course mapping. The recommendation follows the weakness, and each one points to external providers and free resources.
SQL injection findings in your order service
SQL injection fundamentals
Assigned to: Backend developers
Cross-site scripting in user input handlers
Cross-site scripting and output encoding
Assigned to: Frontend developers
Hard-coded credentials in config files
Server-side request forgery in a URL fetcher
SSRF and server-side attacks
Assigned to: Backend and cloud engineers
Who it's for
Development teams
Secure coding training on the bug classes your own code produced, instead of a generic annual course. Supports PCI DSS 6.2.2 and SSDF role-based training.
SOC and vulnerability analysts
Learn to triage what your scanners actually report: exploitability, KEV status, and the attack techniques behind each weakness.
GRC and compliance leads
One record that shows the training was tied to real risk, ready to hand to an auditor or C3PAO next to your POAM.
A path for each role, not a single annual module
Beyond one-off course recommendations, the platform groups topics into guided paths and assigns the right path to the right person. The examples below are illustrative; the current set lives in the app and grows over time.
Secure Coding for Developers
Fix the bug classes your own code produces — injection, access control, secrets — in the languages your team ships.
Web Application Security
The OWASP Top 10 weaknesses end to end, from how each one works to how to prevent it.
SOC Analyst Fundamentals
Triage, detection and response: read what scanners report and what the logs say next to it.
Cloud Security Essentials
Misconfiguration, identity and exposure in the cloud, including the metadata and IAM mistakes behind real findings.
CMMC Awareness & Insider Threat
Security awareness and insider-threat topics for defense-industrial-base teams working toward CMMC Level 2.
Compliance for Engineers
How a finding becomes a control gap, a POAM item and a training requirement — so engineers and GRC speak one language.
Each path links to external providers and free resources (e.g. HTB Academy, PortSwigger Web Security Academy, OWASP, and MITRE CWE pages). CVERiskPilot records the assignment, completion and verification; it does not host the courses. Free versions of these paths are on the Learn page.
Knowledge checks that gate completion
Core topics such as injection, cross-site scripting, access control, authentication and insider threat awareness come with a short knowledge check: a few self-authored questions on the material. Where a knowledge check exists, completing the topic requires passing it, so that completion records a pass, not just a click. Topics without one are completed with a link or note as proof. These are our own quick quizzes, not a certification.
A team dashboard managers can act on
Managers see training coverage across the team at a glance: who is assigned, what is complete and verified, what is overdue, and where skills still lag the weaknesses in your open findings. It turns scattered completions into a plan you can report on.
Training controls your evidence supports
Training records support these requirements. Your assessor or auditor decides whether a control is met.
| Framework | Controls | Requirement | What the training record shows |
|---|---|---|---|
| CMMC Level 2 / NIST 800-171 | AT.L2-3.2.1, AT.L2-3.2.2, AT.L2-3.2.3 (3.2.1–3.2.3) | Security awareness, role-based training, and insider threat awareness | Who was assigned which course, for which findings, and when they completed it. Role-based training (3.2.2) counts role-targeted topics only, and insider threat awareness (3.2.3) counts only the dedicated insider threat awareness topic, built on the free CDSE course and CISA guidance. |
| NIST 800-53 | AT-2, AT-3 | Literacy training and awareness; role-based training | Role-based assignments for developers, analysts and administrators (the only topics counted for AT-3), with completion dates and verification status. |
| SOC 2 | CC1.4 | Commitment to attract, develop and retain competent individuals | A record that staff were trained on the weaknesses found in your own systems. |
| HIPAA Security Rule | §164.308(a)(5) | Security awareness and training program for the workforce | Dated training records tied to the vulnerabilities that put ePHI systems at risk. |
| PCI DSS 4.0 | 12.6, 6.2.2 | Security awareness program; software development personnel trained at least once every 12 months | Per-developer secure coding assignments and completions you can export for the 12-month window. |
| ISO 27001:2022 | A.6.3 | Information security awareness, education and training | Training matched to the risks your scans found, with completion history. |
Training in every package
No separate training subscription. Training is part of the compliance package you already pick by audit.
- Starter (free)
- Training recommendations from your findings
- Audit Readiness and above
- Learning paths, knowledge checks and a team training dashboard, plus assignments, completion tracking and verification, and auditor evidence export (CSV)
- Federal Assessment
- CMMC AT.L2 training evidence (3.2.1–3.2.3) via the awareness path, alongside your POAM
- Partner
- Run findings-driven training paths across client organizations
Compliance packages
Pick the audit you're preparing for
Every package maps your findings to controls and recommends training from them. Audit Readiness and above add assignments, completion tracking and an evidence export.
Starter
Individual practitioners evaluating on real data
See which controls your scan findings threaten, and what your team should learn next.
- 50 AI triage calls / month
- 3 scan uploads / month
- Unlimited local CLI scans
- POAM export (CSV, JSON, XLSX)
- Training recommendations from your findings
- Community support
Audit Readiness
Small GRC and security teams preparing for a commercial audit
Walk into your SOC 2, HIPAA or PCI DSS audit with a POAM already built and training evidence tied to real findings.
- 1,000 AI triage calls / month
- Up to 5 users
- Unlimited scan uploads
- Findings mapped through their CWE to your framework controls
- POAM export (CSV, JSON, XLSX)
- Learning paths, knowledge checks and a team training dashboard
- Training assignments, completion tracking and auditor evidence export
- AI chat on your workspace data
- Jira and ServiceNow ticket push
- Email support
Federal Assessment
Defense contractors and federal suppliers handling CUI
Get to a defensible CMMC Level 2 or FedRAMP-style POAM before your assessment.
- Everything in Audit Readiness
- CMMC Level 2 self-assessment workflow and SPRS estimate
- FedRAMP-style POAM generation
- CMMC AT.L2 training evidence (3.2.1–3.2.3) via the awareness path
- Case approval workflow for risk decisions
- SSO, set up with our team
- Built by a 100% Veteran Owned company
Partner
MSSPs, vCISOs and assessment firms
Deliver compliance-mapped vulnerability reports and findings-driven training across your client base.
- Manage multiple client organizations
- Recurring commission on referred customers
- Client-ready POAMs and compliance impact reports
- Run findings-driven training paths across client organizations
- Partner onboarding with our team
All packages include unlimited local CLI scans. Run without an API key, the CLI reports the core 6 frameworks; add an API key from any package to see all 13.
Provider-neutral by design
CVERiskPilot does not host courses. Recommendations link to external training providers and free resources (e.g. HTB Academy, PortSwigger Web Security Academy, OWASP, and MITRE CWE pages), so your team learns where the best material for each weakness already lives. The CWE-to-course mapping is ours; providers do not review or endorse it. Some provider courses need the provider's own subscription, and anything the provider issues for finishing a course comes from the provider, not from CVERiskPilot. Free practitioner paths are on our Learn page.
Frequently asked questions
- What is findings-driven security training?
- Training chosen by your own vulnerability data. CVERiskPilot reads the weaknesses (CWEs) in your open scan findings and recommends courses that cover them, so a team with SQL injection findings learns about SQL injection rather than sitting through a generic annual module.
- Where do the courses come from?
- Recommended courses link to external training providers and free resources (e.g. HTB Academy, PortSwigger Web Security Academy, OWASP, MITRE CWE pages). People take the course on the provider's site; CVERiskPilot records the recommendation, the assignment and the completion.
- Which plans include training?
- Every plan, Starter included, gets training recommendations from its findings. Audit Readiness ($149/month, 14-day trial) and above add assignments, completion tracking and verification, and the evidence export for auditors.
- Does training evidence satisfy CMMC AT.L2-3.2.2 or SOC 2 CC1.4 on its own?
- No tool can promise that; your assessor or auditor decides whether a practice is met. The export gives them dated, per-person records tied to the risks you found, which supports role-based training requirements such as CMMC AT.L2-3.2.2, NIST 800-53 AT-3 and PCI DSS 6.2.2; only role-targeted topics count toward those. Insider threat awareness (AT.L2-3.2.3) is supported only by verified completions of the insider threat awareness topic, which links to the free CDSE Insider Threat Awareness course and CISA guidance and ends in a knowledge check.
- What is in the evidence export?
- For each training control in the framework you pick, a CSV of who completed which topic, the CWEs that prompted it, completion and verification dates, who verified it, and any proof link or note the learner attached.
- How are completions verified?
- The learner marks an assignment complete with a link or note as proof, such as a provider completion page; where the topic has a knowledge check, completing it requires passing that check first. A reviewer on your team then verifies it, and the export shows both the completion and the verification.
- Are the training providers affiliated with CVERiskPilot?
- No. Providers are named for reference and do not endorse CVERiskPilot, and the CWE-to-course mapping is our own. If we ever add affiliate links, they will be marked as such next to the link, with a disclosure.
Let your findings set the training plan
Start with a scan. Recommendations are free on Starter; the 14-day Audit Readiness trial adds assignments and the evidence export. Preparing for a CMMC Level 2 assessment? Scope it with us.
100% Veteran Owned · Controlled alpha
