PCI DSS v4.0.1 · Data security standard for payment cards

PCI DSS compliance starting with the human element

PCI DSS requires every organization that stores, processes or transmits cardholder data to run a formal security awareness program for all staff. We give you that program, the assessments and the audit evidence, mapped to the standard’s requirements and segmented by audience.

Request a demo

The human element is still the entry point

According to Verizon’s DBIR report, the human element is involved in around 6 in 10 breaches. That is why PCI DSS dedicates Requirement 12.6 to a formal security awareness program: all staff have to know the security policy and their role in protecting cardholder data, with training that is renewed every year.

What PCI DSS requires from you about people

The current version, PCI DSS v4.0.1, reinforces staff training. Three requirements land directly on your security awareness program.

Formal security awareness program (Requirement 12.6)

Requirement 12.6.1 requires implementing a formal security awareness program that makes all staff aware of the information security policy and their role in protecting payment account data. It stops being a best practice and becomes an auditable obligation.

Training at onboarding and every year (Requirement 12.6.3)

The standard requires training staff at the time of hire and at least once every twelve months, and collecting an acknowledgment from each person. Security awareness has to be sustained over time and renewed every year.

Phishing, social engineering and acceptable use (Requirements 12.6.3.1 and 12.6.3.2)

Since 31 March 2025, training must explicitly cover phishing and social engineering, as well as the acceptable use of end-user technologies. They are the vectors through which most attacks on card data come in.

A ready-made program, segmented by audience

You do not have to build it from scratch. The content mapped to PCI DSS comes ready and is assigned by audience in a couple of clicks, each level with its own language and focus.

More than 100 training modules mapped to PCI DSS, ready to assign Each with its exam and its reinforcement newsletters, from everyday cyber hygiene to the secure handling of cardholder data. ✓ Included in the base content package, not as paid add-on content

All staff

Everyday cyber hygiene, how to recognize phishing and social engineering and why every role influences the security of card data. Habits you can apply from day one, without standard jargon.

Roles that handle cardholder data

For those who operate, administer or access the cardholder data environment: acceptable use of technologies, secure handling of the data and the expected conduct when facing a fraud attempt.

Compliance mapped to PCI DSS

Each piece of content is linked to the standard requirements it covers. From the platform’s compliance management you verify the level of compliance based on the training assigned to each person.

And every piece leaves traceability: who completed what, what result they got and how they progressed. That is the evidence that turns “we train our people” into something verifiable.

More than 700 organizations sustain their program with SMARTFENSE

We have spent more than 10 years helping organizations in banking, retail, hospitality and critical infrastructure reduce human risk and leave auditable evidence that they do. The difference compared to a generic campaign is traceability: who was trained, what result they got, how they responded to a phishing or ransomware simulation and how they improved over time. That is the evidence a PCI DSS assessment will ask for.

Retail Payment processors Financial institutions Hospitality and travel E-commerce

Request a demo and build your program for PCI DSS

Leave us your details and we will show you how to cover Requirement 12.6 and the rest of the training obligations with content mapped to the standard, ready for your organization.