# PCI DSS security awareness training: requirement 12.6 explained (2026)

> PCI DSS v4.0 requires a formal awareness programme for all personnel, training upon hire and at least once every 12 months, and since 31 March 2025 it must cover phishing and social engineering.

- Canonical: https://cyberpulse.it/en/pci-dss-security-awareness-training
- Dutch version: https://cyberpulse.it/pci-dss-security-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

If you process card payments, security awareness training is not a choice but a requirement under PCI DSS v4.0. Requirement 12.6.1 calls for a formal awareness programme for all personnel, requirement 12.6.3 requires training upon hire and at least once every 12 months after that, and since 31 March 2025 phishing and social engineering must be part of that training (requirement 12.6.3.1). PCI DSS is not a law but a contractual standard, and in practice that makes it just as binding. This article explains what the three requirements actually ask and how to comply demonstrably.

## What is PCI DSS and who does it apply to?

PCI DSS stands for Payment Card Industry Data Security Standard: the security standard of the card brands, maintained by the PCI Security Standards Council. It applies to organisations that accept or process card payments. Think of web shops, retail chains, hotels and restaurants: precisely the sectors where the till and the payment page are the heart of the revenue.

The key thing to understand: PCI DSS is **not a law**. There is no public supervisory authority checking compliance, as there is with the GDPR or the Dutch Cybersecurity Act (Cbw). Enforcement runs through the card brands and your acquirer: the party you signed your card acceptance contract with. Compliance with PCI DSS is part of that contract. Fail to comply and you carry a contractual and commercial risk towards your acquirer and the card brands, up to and including the question of whether you can keep accepting card payments at all.

That does not make the pressure smaller, if anything it makes it more concrete: where a statutory obligation runs via a regulator, this requirement sits directly inside the relationship with the party that makes your payments possible. How PCI DSS relates to the statutory frameworks is covered in the overview of [when security awareness training is mandatory](/en/security-awareness-training-mandatory): there PCI DSS sits in the row of contractual obligations, alongside certification requirements.

For training, three requirements from chapter 12 matter:

| Requirement | What it asks | Since |
|---|---|---|
| 12.6.1 | A formal security awareness programme for all personnel | v4.0 |
| 12.6.3 | Training upon hire and at least once every 12 months | v4.0 |
| 12.6.3.1 | Phishing and social engineering must be covered in the training | 31 March 2025 |

## Requirement 12.6.1: a formal awareness programme for all personnel

The foundation is requirement 12.6.1: there must be a **formal** security awareness programme for **all personnel**. Two words carry the weight here.

**Formal** means: documented and structured. A poster by the coffee machine or the occasional email from IT is not a programme. There has to be a described approach behind it: what you train, who you train, when and how.

**All personnel** means: everyone, not only the people who handle cardholder data day to day. The reasoning is practical: an attacker rarely picks the best-secured door. The colleague who "has nothing to do with payments" usually does have a mailbox, a password and access to the network. A programme that trains only the till staff or the finance team therefore meets neither the letter nor the spirit of the requirement.

For your records that means: capture the programme as a document and make sure you can show that coverage is complete, including new joiners, part-timers and the seasonal staff that are so common in retail and hospitality.

## Requirement 12.6.3: training upon hire and at least once every 12 months

Requirement 12.6.3 fixes the frequency: personnel are trained **upon hire** and **at least once every 12 months** after that.

The onboarding moment is the part that most often slips in practice. New employees start, get going, and the awareness training "can wait for the next round". That is exactly what 12.6.3 rules out: the training belongs at the start of the employment, not at the next annual campaign that happens to fall months later.

"At least once every 12 months" is also a floor, not a recommendation. Training more often is allowed, and sensible, because an annual session has faded by the time the next phishing email arrives. But for compliance the minimum is clear: every employee, every year, demonstrably.

In practice that means you need two processes: a fixed training step in your onboarding, and a recurring cycle that skips nobody. Both have to leave a trace in your records, because an assessor or acquirer wants to see per employee when the training was completed. If you have peaks of intake all at once (seasonal work in retail or hospitality, say) schedule the training as a standard part of the first working week; that scales better than catch-up rounds afterwards.

## Requirement 12.6.3.1: phishing and social engineering in the training

Requirement 12.6.3.1 sets out what has to be in the training as a minimum: **phishing and social engineering**. This requirement has been mandatory since **31 March 2025**: in PCI DSS v4.0 it was originally a future-dated requirement, but that date is now well past. Anyone who has not updated their programme since then has a gap.

The choice of these particular topics makes sense: phishing and social engineering do not target your systems but your people, which makes them exactly the territory where technology alone offers no protection. An awareness programme that does not deal with these attack types explicitly misses the subject where human risk is greatest.

Concretely, your programme has to cover demonstrably how employees recognise phishing and social engineering and what to do when they see something suspicious. Check your current curriculum against that: is phishing in there as an explicit topic, or is it implicitly buried in a general module? For evidence purposes you want the first.

If you work with off-the-shelf content or an external platform, check whether that content has been updated on this point since the 31 March 2025 deadline. The requirement applies to your programme, regardless of who supplies the training: responsibility for compliance sits with the organisation that accepts the card payments.

## What does this mean for your programme in practice?

Together, the three requirements translate into a programme with three fixed building blocks:

**1. An onboarding moment.** Every new employee completes the awareness training as part of the start of employment. Make it a standard step in your onboarding checklist, just like the laptop and the email account.

**2. An annual repeat, or better, a continuous rhythm.** The annual requirement is the minimum. A continuous programme of short, regular learning moments makes that annual floor trivial to meet and keeps knowledge fresh. You never again have to organise a big catch-up campaign because the yearly deadline is approaching.

**3. Phishing and social engineering as an explicit component.** Alongside explaining how to recognise them, phishing simulations are a logical way to deliver this: employees practise with realistic examples, and you get measurable results showing the subject is covered and actually rehearsed.

Think wider than PCI DSS alone while you are at it. Cardholder data is almost always personal data too, so the expectations around [GDPR and security awareness](/en/gdpr-security-awareness-training) come into play. And if you are working towards ISO 27001 certification, one well-recorded programme also covers the awareness requirements of [ISO 27001 Annex A 6.3](/en/iso-27001-awareness-training). One programme, several frameworks covered: that is the efficient route.

## How to make it demonstrable

With PCI DSS, what ultimately counts is what you can show an assessor or your acquirer. A programme that runs but is documented nowhere simply does not exist for the purposes of an assessment. Work through this checklist:

- [ ] The awareness programme is **on paper**: audience, content, frequency and owner (12.6.1).
- [ ] The programme covers **all personnel**, including part-timers and seasonal staff (12.6.1).
- [ ] Every **new employee** completes the training upon hire, and that moment is recorded (12.6.3).
- [ ] The **annual repeat** is scheduled and participation is recorded per employee (12.6.3).
- [ ] **Phishing and social engineering** are explicitly in the curriculum (12.6.3.1).
- [ ] For each employee there is a **record** of participation, date and result that you can produce at any moment.

That per-employee record is exactly what CyberPulse is built for: the platform captures training participation, quiz results, certificates and phishing results per employee, and combines weekly micro-learning with phishing simulations: covering the requirements of 12.6.3 and 12.6.3.1 in one continuous programme. [Start a free trial](/trial) and see what evidence you can already produce after a few weeks.

## Frequently asked questions

### Is PCI DSS security awareness training a legal requirement?

No. PCI DSS is not a law but a contractual standard set by the card brands; enforcement runs through the card brands and your acquirer. That does not make the requirement optional in practice: compliance is part of your card acceptance contract, and failing to comply is a contractual and commercial risk. Separately, statutory frameworks such as the GDPR may of course apply to your organisation regardless of PCI DSS.
### How often does PCI DSS require you to train personnel?

Requirement 12.6.3 requires training at two moments: upon hire and at least once every 12 months after that. The annual frequency is a floor: training more often is allowed and helps retention. What matters is that both moments are recorded per employee, so that at an assessment you can show who took part and when.
### Does phishing have to be part of the training?

Yes. Requirement 12.6.3.1 states that security awareness training must cover phishing and social engineering. This requirement has been mandatory since 31 March 2025. So check that phishing and social engineering appear explicitly in your curriculum; a programme that does not demonstrably cover these topics no longer meets PCI DSS v4.0.
### Who has to complete the PCI DSS awareness training?

All personnel. Requirement 12.6.1 calls for a formal security awareness programme covering the entire workforce, not only the employees who work directly with cardholder data. In retail and hospitality that includes part-timers and seasonal staff. Make sure your records show full coverage, including employees who join part-way through the year.
### What do you risk if you do not meet requirement 12.6?

PCI DSS is enforced through the card brands and your acquirer, not through a public supervisory authority. Non-compliance is therefore mainly a contractual and commercial risk in the relationship with the party that makes your card payments possible. Any financial consequences run along that contractual route and differ case by case; there are no fixed amounts published by the standard itself.
### Are phishing simulations mandatory under PCI DSS?

The standard requires phishing and social engineering to be covered in the training (requirement 12.6.3.1); phishing simulations as such are not prescribed in so many words. They are, however, a logical and measurable way to deliver it: employees practise with realistic examples and you build evidence at the same time that the topic is actively trained: exactly what an assessor or acquirer wants to see.

## Sources

- [PCI Security Standards Council, document library (PCI DSS v4.0)](https://www.pcisecuritystandards.org/document_library/)
- [EUR-Lex, Regulation (EU) 2016/679 (GDPR)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
