Skip to main content
Trusted by Hundreds of MSPs

PCI DSS security awareness training requirements

PCI DSS v4.0 — Requirement 12.6. What the controls say, how often you have to train, what an assessor will ask to see, and the detail that fails most assessments.

app.hooksecurity.co/dashboard
Security Overview

Last 30 days

↓ 73% risk reduction
1,247
Phishing Tests
+12%
94.2%
Pass Rate
+8%
3,892
Trained Users
+156
Recent Activity
Phishing simulation completed
Marketing Team
2m ago
Training module finished
john.doe@company.com
15m ago
Suspicious click detected
sarah.smith@company.com
1h ago

Who this applies to

Any organization that stores, processes or transmits cardholder data, and the service providers supporting them.

The controls

12.6.3Security awareness training

Personnel receive security awareness training upon hire and at least once every 12 months.

12.6.3.1Phishing and social engineering

Training must explicitly cover threats including phishing and related social engineering attacks. Mandatory since 31 March 2025.

12.6.3.2Acceptable use of end-user technologies

Training must cover acceptable use of end-user technologies. Mandatory since 31 March 2025.

How often you have to train

On hire, then at least every 12 months. The clock runs per employee from their own training date, not on a calendar year.

What an assessor will ask to see

  • Per-employee training records dated from their individual hire and training dates
  • Content evidence showing phishing and social engineering are explicitly covered
  • Content evidence covering acceptable use of end-user technologies
  • Annual acknowledgement from each employee

The detail that fails most assessments

The per-employee annual clock is where most programs fail an assessment. A company-wide January training leaves anyone hired in March out of compliance by the following March, even though "everyone was trained this year" is technically true.

How Hook Security fits

Enrollment is driven from your directory, so each employee is trained from their own hire date rather than a company-wide calendar event. Phishing and social engineering are the core of the curriculum, not an add-on module.

Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.

The same records answer a cyber insurance questionnaire — see what underwriters ask for.

Show us your PCI DSS scope. We will tell you what we cover.

Thirty minutes, a live account, and an honest answer about the gaps.