Skip to content
AwareSprint

PCI DSS · Security awareness programme

PCI DSS: evidencing a security awareness programme

PCI DSS treats security awareness as an ongoing programme, not an event, and it names the threats that programme has to cover. Assessors look for the schedule, the content, and the personnel records together.

What it actually asks for

A formal awareness programme
The standard expects a documented programme, not occasional emails. It needs an owner, a scope and a defined cadence.
Reviewed at least once every twelve months
The programme itself is reviewed periodically and updated as threats change, with evidence of that review.
Training on hire and at least annually
The personnel cadence is set out plainly: on joining, then at least once every twelve months, with acknowledgement that it was completed.
Phishing and social engineering explicitly covered
The standard calls these out directly, alongside acceptable use of the technology people work with. Coverage has to be demonstrable in the content itself.

Where organisations come unstuck

The frequent finding is not absence of training but absence of a demonstrable link between the programme, the threats it names, and the individual records. Assessors sample personnel and expect the trail to hold for each one.

The evidence to keep

  • A record of completion for each person, with dates, that an assessor can sample
  • Content that visibly covers phishing and social engineering, mapped to the requirement
  • Evidence the programme was reviewed and updated within the last twelve months
  • Acknowledgement that personnel completed and understood the material
  • Participation data across everyone in scope, including who has not completed

How AwareSprint helps

AwareSprint runs short security challenges for your whole team and produces a completion register with dates, content versions and participation across the population. That is the record this clause asks you to produce. It does not make you compliant, and no platform can. It gives you the training evidence, so the rest of your programme is what your auditor spends time on.

Work email only. Nothing to install and no card required.

Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.

Registering your whole company?Use the company form

Other standards

FAQ

Questions

What teams ask about PCI DSS and awareness training.

Does PCI DSS require simulated phishing?

The standard mandates that awareness training covers phishing and social engineering. It does not mandate simulation as the delivery method, though many assessors regard practical exercises as stronger evidence than a slide deck.

Who is in scope for the training requirement?

Personnel with access to the cardholder data environment, and generally anyone whose role could affect its security. Your QSA will confirm scope against your environment.

Is annual training enough?

Annually is the stated minimum for personnel. Awareness is described as ongoing, so a programme that runs only once a year and does nothing between sittings can still attract comment.