PCI DSS · Security awareness programme
PCI DSS: evidencing a security awareness programme
PCI DSS treats security awareness as an ongoing programme, not an event, and it names the threats that programme has to cover. Assessors look for the schedule, the content, and the personnel records together.
What it actually asks for
- A formal awareness programme
- The standard expects a documented programme, not occasional emails. It needs an owner, a scope and a defined cadence.
- Reviewed at least once every twelve months
- The programme itself is reviewed periodically and updated as threats change, with evidence of that review.
- Training on hire and at least annually
- The personnel cadence is set out plainly: on joining, then at least once every twelve months, with acknowledgement that it was completed.
- Phishing and social engineering explicitly covered
- The standard calls these out directly, alongside acceptable use of the technology people work with. Coverage has to be demonstrable in the content itself.
Where organisations come unstuck
The frequent finding is not absence of training but absence of a demonstrable link between the programme, the threats it names, and the individual records. Assessors sample personnel and expect the trail to hold for each one.
The evidence to keep
- A record of completion for each person, with dates, that an assessor can sample
- Content that visibly covers phishing and social engineering, mapped to the requirement
- Evidence the programme was reviewed and updated within the last twelve months
- Acknowledgement that personnel completed and understood the material
- Participation data across everyone in scope, including who has not completed
How AwareSprint helps
AwareSprint runs short security challenges for your whole team and produces a completion register with dates, content versions and participation across the population. That is the record this clause asks you to produce. It does not make you compliant, and no platform can. It gives you the training evidence, so the rest of your programme is what your auditor spends time on.
That email address did not work. Check it and try again.
Work email only. Nothing to install and no card required.
Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.
Registering your whole company?Use the company form