PCI DSS 12.6.1: A formal security awareness program is implemented to make all personnel aware of the entity’s
PCI DSS v4.0.1 control 12.6.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.6.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.6
A formal security awareness program is implemented to make all personnel aware of the entity’s information security policy and procedures, and their role in protecting the cardholder data.
Summary
Run a real security awareness programme so that everyone, not just technical staff, knows your security policy and what their own part in protecting card data is.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.6.1 | Examine the security awareness program to verify it provides awareness to all personnel about the entity’s information security policy and procedures, and personnel’s role in protecting the cardholder data. |
The shortest control in this set and one of the most commonly under-evidenced, because the single procedure is easy to read as "have some training". It is not: the programme must cover all personnel, must convey your own information security policy and procedures rather than generic security content, and must tell each person their role. An off-the-shelf phishing course covers none of those three on its own. Frequency and content updates are handled by 12.6.2 and 12.6.3, so those are assessed alongside this one in practice.
What to prepare
- The awareness programme material itself, showing it references your own policies rather than only generic security topics.
- A roster of all personnel, with completion records against it, including contractors and part-time staff.
- Evidence of what each role is told about its own part in protecting cardholder data.
- Records of acknowledgement, where your programme uses them.
How to implement it
1. Define "all personnel" before you measure completion. It includes contractors, temporary staff, and anyone with access to your systems or premises who could affect the security of card data. Completion measured against the payroll will look like 100% and still miss the people most likely to be targeted.
2. Point the training at your policy, not at security in general. The procedure verifies awareness of the entity’s information security policy and procedures. Material that never mentions your own incident reporting route, your own acceptable use rules, or your own payment channel is not evidence for this control however good it is.
3. Say what each role actually does. A customer service agent who takes phone orders, a developer who touches the payment page and a warehouse packer have different parts to play. Tailoring the "your role" section is the difference between awareness and attendance.
4. Keep the completion record as the evidence, not the platform. Training platforms are changed and cancelled. Export completion records into your own compliance evidence at the time, so the evidence survives the vendor.
Where this commonly fails
- Contractors and seasonal staff omitted from the roster, so coverage is not "all personnel" no matter what the completion rate says.
- A generic phishing course used as the whole programme, which never conveys the entity’s own policies.
- New joiners trained at induction and never again, which fails 12.6.3 even where this control passes.
- Completion records held only inside a training vendor, and lost when the contract ends.
How PCIComplianceHub helps
Our Security awareness training delivers awareness modules and records completion per person, which is the evidence this control asks you to produce.
Scope note. It provides the programme and the records. Covering all personnel, and conveying your own policies rather than only generic material, is yours to ensure.
Signed in, you can retrieve your organisation's evidence for 12.6.1 as JSON: what the scanner has recorded, with the scope note above attached to it.
Related controls
Others in section 12.6:
| Control | What it requires |
|---|---|
| 12.6.2 | The security awareness program… |
| 12.6.3 | Personnel receive security awareness training… |
| 12.6.3.1 | Security awareness training includes awareness of threats and vulnerabilities that could impact… |
| 12.6.3.2 | Security awareness training includes awareness about the acceptable use of end-user… |
← 12.5.3 · All controls · 12.6.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.