PCI DSS 12.6.3: Personnel receive security awareness training

PCI DSS v4.0.1 control 12.6.3: the requirement in full, the 4 testing procedures an assessor uses to verify it, and the related controls in section 12.6.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.6

Personnel receive security awareness training as follows:

  • Upon hire and at least once every 12 months.
  • Multiple methods of communication are used.
  • Personnel acknowledge at least once every 12 months that they have read and understood the information security policy and procedures.

Summary

Train everyone at hire and at least yearly, by more than one method, and have them acknowledge they have read your policy.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.6.3.a Examine security awareness program records to verify that personnel attend security awareness training upon hire and at least once every 12 months.
12.6.3.b Examine security awareness program materials to verify the program includes multiple methods of communicating awareness and educating personnel.
12.6.3.c Interview personnel to verify they have completed awareness training and are aware of their role in protecting cardholder data.
12.6.3.d Examine security awareness program materials and personnel acknowledgments to verify that personnel acknowledge at least once every 12 months that they have read and understand the information security policy and procedures.

Where 12.6.1 asks for a programme, this asks for delivery, and its three bullets fail independently. Upon hire and at least once every 12 months is two triggers, and new joiners trained at induction and never again meet only one. Multiple methods of communication is easy to miss entirely: one e-learning module is one method. And the acknowledgement is a separate artefact from the completion record: someone can finish a course without ever confirming they read your information security policy. Four procedures, one per element plus the records.

What to prepare

  • Completion records covering hire dates and annual cycles, against a roster of all personnel.
  • Evidence of at least two delivery methods.
  • The acknowledgements, dated within the last twelve months, separate from course completions.
  • The policy version each acknowledgement refers to.

How to implement it

1. Tie the hire trigger to onboarding, not to the annual cycle. Someone joining in February who first trains in the December cohort has gone ten months untrained, and the dates in the records show it.

2. Use a second method deliberately and record it. Posters, a team briefing, a periodic email or a screensaver campaign all count; what matters is that you can name two and show them.

3. Keep the acknowledgement as its own record. A tick inside a course platform is fragile and often not exportable; the requirement asks people to confirm they have read and understood the policy, and that should survive the platform.

4. Re-acknowledge when the policy changes materially. Not required by the wording, but an acknowledgement of a superseded policy answers a question nobody asked.

Where this commonly fails

  • Annual training with no induction training, or the reverse.
  • A single e-learning module presented as multiple methods.
  • Completion records offered as acknowledgements, which are a separate bullet.
  • Contractors trained by their employer, with nothing on your side evidencing it.

How PCIComplianceHub helps

Our Security awareness training records who completed which module and when, and issues a certificate per completion.

Scope note. It evidences delivery and completion. The upon-hire and annual cadence, and the acknowledgement that personnel have read your policy, are yours to run.

Signed in, you can retrieve your organisation's evidence for 12.6.3 as JSON: what the scanner has recorded, with the scope note above attached to it.

Others in section 12.6:

Control What it requires
12.6.1 A formal security awareness program is implemented to make all personnel aware of the entity’s…
12.6.2 The security awareness program…
12.6.3.1 Security awareness training includes awareness of threats and vulnerabilities that could impact…
12.6.3.2 Security awareness training includes awareness about the acceptable use of end-user…

12.6.2 · All controls · 12.6.3.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.