PCI DSS v4.0.1 · Global
Phishing training is now
a PCI DSS requirement.
PCI DSS v4.0.1 Requirement 12.6 requires a formal security awareness programme and training on hire and at least every 12 months, and since 31 March 2025 that training must cover phishing and social engineering, alongside automated anti-phishing mechanisms under Requirement 5.4.1.
- Standard
- PCI DSS v4.0.1 (June 2024); v4.0 was retired on 31 December 2024
- Training
- On hire and at least once every 12 months (12.6.3)
- Phishing
- Phishing and social engineering training, required since 31 March 2025 (12.6.3.1)
- KeenSec evidence
- Training completions and certificates, simulation results, report logs, policy acknowledgements
What Requirement 12.6 says
Five requirements your
assessor will test.
Requirements marked 31 March 2025 were best practice until that date and are now required.
| Requirement | What it says | Required |
|---|---|---|
| 12.6.1 | A formal security awareness programme makes all personnel aware of the security policy and their role in protecting cardholder data. | Yes |
| 12.6.2 | The programme is reviewed at least once every 12 months and updated for new threats and vulnerabilities. | Since 31 March 2025 |
| 12.6.3 | Personnel are trained on hire and at least once every 12 months, and acknowledge the security policy. | Yes |
| 12.6.3.1 | Training covers threats including phishing and related attacks, and social engineering. | Since 31 March 2025 |
| 5.4.1 | Processes and automated mechanisms detect and protect personnel against phishing attacks. | Since 31 March 2025 |
Where card data meets people
Call centres, stores
and finance teams.
People who take payments or support customers are natural targets for phishing and phone-based social engineering.
“Payments support” · unknown number
Terminal verification
We are updating your payment terminal. Please confirm the admin code so we can finish remotely.
- Unexpected call
- Asks for a code
Expectation to record
The awareness record
your assessor can read.
Staff complete awareness training.
LMS completions, assessments and certificates.
Staff tested against social engineering.
Phishing, vishing and messaging outcomes per person.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
Staff accept your security policies.
Dated records per person and version.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- PCI DSS v4.0.1 Requirements and Testing ProceduresJune 2024 · PCI Security Standards Council document library
Questions buyers ask
Frequently asked questions.
Does PCI DSS require phishing simulation?
Not in the requirement text. The guidance for 12.6.3.1 says an effective programme should include examples of phishing emails and periodic testing to see how many personnel report such attacks. Simulations and the Phishing Reporter give you exactly that.
Which PCI DSS version applies?
Version 4.0.1, published in June 2024. Version 4.0 was retired on 31 December 2024. The Council consulted on the next revision in 2026, but no new version has been published.
Does KeenSec make us compliant with PCI DSS?
No tool makes you compliant on its own. KeenSec helps you run and evidence the awareness side of your programme; your QSA or assessor decides compliance.
Which PCI DSS requirements does KeenSec help with?
Mainly Requirement 12.6: the awareness programme, training on hire and every 12 months, and phishing and social engineering content. Requirement 5.4.1 covers technical anti-phishing mechanisms, which training does not replace; the Phishing Reporter helps staff report what gets through.
Let’s connect the dots
Train the people
who touch the payments.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo