PCI DSS security awareness training requirements
Last 30 days
Who this applies to
Any organization that stores, processes or transmits cardholder data, and the service providers supporting them.
The controls
Personnel receive security awareness training upon hire and at least once every 12 months.
Training must explicitly cover threats including phishing and related social engineering attacks. Mandatory since 31 March 2025.
Training must cover acceptable use of end-user technologies. Mandatory since 31 March 2025.
How often you have to train
On hire, then at least every 12 months. The clock runs per employee from their own training date, not on a calendar year.
What an assessor will ask to see
- Per-employee training records dated from their individual hire and training dates
- Content evidence showing phishing and social engineering are explicitly covered
- Content evidence covering acceptable use of end-user technologies
- Annual acknowledgement from each employee
The detail that fails most assessments
The per-employee annual clock is where most programs fail an assessment. A company-wide January training leaves anyone hired in March out of compliance by the following March, even though "everyone was trained this year" is technically true.
How Hook Security fits
Enrollment is driven from your directory, so each employee is trained from their own hire date rather than a company-wide calendar event. Phishing and social engineering are the core of the curriculum, not an add-on module.
Hook Security does not guarantee a passing assessment, and no platform can — compliance depends on your full control environment, your documentation and your assessor. Controls cited as published and last verified 2026-09-09. This is a reference, not legal advice.
The same records answer a cyber insurance questionnaire — see what underwriters ask for.
Show us your PCI DSS scope. We will tell you what we cover.
Thirty minutes, a live account, and an honest answer about the gaps.