PCI DSS v4.0.1 · Global

Phishing training is now
a PCI DSS requirement.

PCI DSS v4.0.1 Requirement 12.6 requires a formal security awareness programme and training on hire and at least every 12 months, and since 31 March 2025 that training must cover phishing and social engineering, alongside automated anti-phishing mechanisms under Requirement 5.4.1.

Standard
PCI DSS v4.0.1 (June 2024); v4.0 was retired on 31 December 2024
Training
On hire and at least once every 12 months (12.6.3)
Phishing
Phishing and social engineering training, required since 31 March 2025 (12.6.3.1)
KeenSec evidence
Training completions and certificates, simulation results, report logs, policy acknowledgements

What Requirement 12.6 says

Five requirements your
assessor will test.

Requirements marked 31 March 2025 were best practice until that date and are now required.

RequirementWhat it saysRequired
12.6.1A formal security awareness programme makes all personnel aware of the security policy and their role in protecting cardholder data.Yes
12.6.2The programme is reviewed at least once every 12 months and updated for new threats and vulnerabilities.Since 31 March 2025
12.6.3Personnel are trained on hire and at least once every 12 months, and acknowledge the security policy.Yes
12.6.3.1Training covers threats including phishing and related attacks, and social engineering.Since 31 March 2025
5.4.1Processes and automated mechanisms detect and protect personnel against phishing attacks.Since 31 March 2025

Where card data meets people

Call centres, stores
and finance teams.

People who take payments or support customers are natural targets for phishing and phone-based social engineering.

Simulated example
Voice call14:03

“Payments support” · unknown number

Terminal verification

We are updating your payment terminal. Please confirm the admin code so we can finish remotely.

  • Unexpected call
  • Asks for a code
A sample vishing scenario for payment staff.

Expectation to record

The awareness record
your assessor can read.

TRAINING

Staff complete awareness training.

LMS completions, assessments and certificates.

SIMULATION RESULTS

Staff tested against social engineering.

Phishing, vishing and messaging outcomes per person.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

POLICY ACKNOWLEDGEMENTS

Staff accept your security policies.

Dated records per person and version.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. PCI DSS v4.0.1 Requirements and Testing ProceduresJune 2024 · PCI Security Standards Council document library

Questions buyers ask

Frequently asked questions.

Does PCI DSS require phishing simulation?

Not in the requirement text. The guidance for 12.6.3.1 says an effective programme should include examples of phishing emails and periodic testing to see how many personnel report such attacks. Simulations and the Phishing Reporter give you exactly that.

Which PCI DSS version applies?

Version 4.0.1, published in June 2024. Version 4.0 was retired on 31 December 2024. The Council consulted on the next revision in 2026, but no new version has been published.

Does KeenSec make us compliant with PCI DSS?

No tool makes you compliant on its own. KeenSec helps you run and evidence the awareness side of your programme; your QSA or assessor decides compliance.

Which PCI DSS requirements does KeenSec help with?

Mainly Requirement 12.6: the awareness programme, training on hire and every 12 months, and phishing and social engineering content. Requirement 5.4.1 covers technical anti-phishing mechanisms, which training does not replace; the Phishing Reporter helps staff report what gets through.

Let’s connect the dots

Train the people
who touch the payments.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo