PCI DSS requires every organization that stores, processes or transmits cardholder data to run a formal security awareness program for all staff. We give you that program, the assessments and the audit evidence, mapped to the standard’s requirements and segmented by audience.
Request a demoAccording to Verizon’s DBIR report, the human element is involved in around 6 in 10 breaches. That is why PCI DSS dedicates Requirement 12.6 to a formal security awareness program: all staff have to know the security policy and their role in protecting cardholder data, with training that is renewed every year.
The current version, PCI DSS v4.0.1, reinforces staff training. Three requirements land directly on your security awareness program.
Requirement 12.6.1 requires implementing a formal security awareness program that makes all staff aware of the information security policy and their role in protecting payment account data. It stops being a best practice and becomes an auditable obligation.
The standard requires training staff at the time of hire and at least once every twelve months, and collecting an acknowledgment from each person. Security awareness has to be sustained over time and renewed every year.
Since 31 March 2025, training must explicitly cover phishing and social engineering, as well as the acceptable use of end-user technologies. They are the vectors through which most attacks on card data come in.
You do not have to build it from scratch. The content mapped to PCI DSS comes ready and is assigned by audience in a couple of clicks, each level with its own language and focus.
Everyday cyber hygiene, how to recognize phishing and social engineering and why every role influences the security of card data. Habits you can apply from day one, without standard jargon.
For those who operate, administer or access the cardholder data environment: acceptable use of technologies, secure handling of the data and the expected conduct when facing a fraud attempt.
Each piece of content is linked to the standard requirements it covers. From the platform’s compliance management you verify the level of compliance based on the training assigned to each person.
And every piece leaves traceability: who completed what, what result they got and how they progressed. That is the evidence that turns “we train our people” into something verifiable.
We have spent more than 10 years helping organizations in banking, retail, hospitality and critical infrastructure reduce human risk and leave auditable evidence that they do. The difference compared to a generic campaign is traceability: who was trained, what result they got, how they responded to a phishing or ransomware simulation and how they improved over time. That is the evidence a PCI DSS assessment will ask for.
Leave us your details and we will show you how to cover Requirement 12.6 and the rest of the training obligations with content mapped to the standard, ready for your organization.