PCI DSS v4.0: security awareness, training & the human layer
If your organisation stores, processes or transmits cardholder data — as a merchant, payment service provider, acquirer or bank — PCI DSS v4.0 applies, and your QSA assessment or self-assessment questionnaire will test the human layer explicitly. Unlike frameworks that leave awareness to interpretation, PCI DSS spells out the programme, the cadence and the records in Requirement 12.6. This page explains exactly what the standard requires of your people, and how AfriPhish produces the evidence an assessor will ask to see.
What PCI DSS v4.0 requires on awareness and human risk
Requirement 12.6.1 — a formal security awareness programme. A formal programme must be implemented to make all personnel aware of the entity's information security policy and procedures, and of their role in protecting cardholder data. "Formal" means owned, documented and scheduled — an ad-hoc email when something goes wrong does not qualify.
Requirement 12.6.2 — the programme is reviewed and kept current. The awareness programme must be reviewed at least once every 12 months and updated as needed to address new threats and vulnerabilities that may impact the security of the cardholder data environment. Since phishing and social engineering evolve monthly, an assessor will look for dated evidence that your content actually changed — new scenarios, new modules — not just that a review meeting occurred.
Requirement 12.6.3 — training upon hire, at least annually, with acknowledgement. Personnel must receive security awareness training upon hire and at least once every 12 months, through more than one method of communication, and must acknowledge at least annually that they have read and understood the information security policy and procedures. The sub-requirements make the content explicit: training must cover current threats that could impact cardholder data security — including phishing and related attacks and social engineering — as well as the acceptable use of end-user technologies.
Requirement 12.10.4 — incident-response training. The personnel expected to respond to suspected or confirmed incidents must be appropriately and periodically trained on their responsibilities. Response plans fail quietly when the people named in them have never rehearsed their role.
Requirement 5.4.1 — the anti-phishing pairing. v4.0 also requires processes and automated mechanisms to detect and protect personnel against phishing attacks. That is a technical control — mail filtering, link protection — and AfriPhish does not replace it. But the standard's own guidance treats technology and awareness as complementary: filters catch what they can, and 12.6.3's phishing training addresses the messages that get through. Simulations are how you verify that second layer actually works.
The requirements AfriPhish helps you evidence
| PCI DSS v4.0 requirement | AfriPhish module | Evidence produced |
|---|---|---|
| 12.6.1 — formal awareness programme | Scheduled campaigns and training series | A documented, dated programme history per population |
| 12.6.2 — programme reviewed and updated for new threats | Continuously updated phishing scenarios and course library | Dated content changes showing the programme evolved |
| 12.6.3 — training upon hire and at least annually | Automated assignment on joining plus recurring campaigns | Per-user completion records with hire-date alignment |
| 12.6.3 — annual policy acknowledgement | Policy management with e-signature attestation | Versioned, timestamped acknowledgement registers |
| 12.6.3 — phishing and social-engineering content | Simulations across realistic scenario families + training | Click, credential-submission and report rates per campaign |
| 12.10.4 — incident-response personnel trained | Dedicated IT/SecOps training track | Track-level completion and score records for responders |
Because training, simulations and attestations share one data model, cadence compliance is visible at a glance: every person, their hire date, their last training date and their last acknowledgement sit in a single exportable view.
What assessors typically ask for
QSA assessments and SAQ evidence-gathering on Requirement 12.6 are predictable. Expect requests for:
- The awareness programme documentation — what is delivered, to whom, on what schedule, and who owns it (12.6.1).
- Annual review evidence — proof the programme was reviewed within the last 12 months and updated for current threats, with dated changes (12.6.2).
- Training records sampled against hire dates — new starters matched to their onboarding training, and the full population matched to the annual cycle (12.6.3).
- Acknowledgement registers — each person's annual confirmation that they have read and understood the security policy, tied to the version in force.
- Phishing and social-engineering content — the actual material demonstrating those threats are covered, plus simulation results showing effectiveness.
- Incident-response training records — evidence the named responders were trained on their roles, periodically (12.10.4).
All of the above export directly from AfriPhish, scoped to your assessment period.
See where your organisation stands
Before your next assessment window, gap-check the human layer. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your programme against the cadence and evidence Requirement 12.6 actually demands, and highlights what a QSA would flag.
Preparing for an assessment with a QSA or internal security team? Book a demo and we will show you the exact reports that answer a 12.6 evidence request.