Data Privacy & Protection

PCI DSS Security Awareness Training Requirements: What Employers Handling Cardholder Data Must Document

PCI DSS Requirement 12.6 requires every entity that stores, processes, or transmits cardholder data to run a formal security awareness program, train personnel at hire and at least once every 12 months, cover phishing and social engineering and acceptable use of end-user technology, and collect an acknowledgment from each person at least once every 12 months that they have read and understood the security policy. Requirement 9.5.1.3 adds a separate training duty for anyone who works near a payment terminal: how to spot tampering or substitution and how to verify that a person claiming to be a repair technician is real.

For a merchant, this is a contractual obligation enforced by the card brands and acquiring banks rather than a federal law, but the evidence a Qualified Security Assessor asks for looks exactly like an OSHA or HIPAA training record, and in Nevada it is also a statutory duty. A free compliance gap analysis that maps each role touching cardholder data to the modules PCI expects is the quickest way to see whether your records would survive an assessment.

Who Has to Comply With PCI DSS Training Requirements?

The Payment Card Industry Data Security Standard applies to any organization that accepts, stores, processes, or transmits payment card data, from a single-location café to a national retailer, plus the service providers that touch that data on their behalf. The current version is PCI DSS v4.0.1, published by the PCI Security Standards Council in June 2024. Version 3.2.1 was retired on March 31, 2024, and the future-dated requirements that had been best practice under v4.0 became mandatory on March 31, 2025, including the two training sub-requirements on phishing and acceptable use.

PCI DSS is not a statute. It binds merchants through their agreements with acquiring banks and the card brands, and the consequences of non-compliance are contractual: fines passed through by the acquirer, higher transaction fees, forensic investigation costs after a breach, and in serious cases loss of the ability to accept cards. Two states have written it into law. Nevada’s NRS 603A.215 requires any data collector doing business in the state that accepts a payment card to comply with the current version of PCI DSS, and Minnesota’s Plastic Card Security Act imposes liability on businesses that retain sensitive authentication data after a transaction. For those merchants a training gap is a legal-compliance gap, not just a contract problem.

Scope matters for training rosters. PCI defines “personnel” broadly to include full-time and part-time employees, temporary staff, contractors, and consultants who are resident on the entity’s site or otherwise have access to the cardholder data environment. A seasonal cashier who works six weekends a year and a contractor who maintains the point-of-sale network are both in scope. The PCI DSS v4.0 employee training requirements article covers what changed between versions; this one is about building and documenting the program that Requirement 12.6 now demands.

What Does Requirement 12.6 Actually Say?

Requirement 12.6 has four operative sub-requirements. 12.6.1 requires a formal security awareness program that makes all personnel aware of the entity’s information security policy and procedures and their role in protecting cardholder data. A program means something documented, owned, and repeatable, not an email from IT. 12.6.2 requires the program to be reviewed at least once every 12 months and updated as needed to address new threats and vulnerabilities that may affect the security of the cardholder data environment. An assessor will ask for evidence of that review, which means a dated document showing who looked at the content, what changed, and why.

12.6.3 is the training requirement itself. Personnel must receive security awareness training upon hire and at least once every 12 months, through more than one method of communication, and must acknowledge at least once every 12 months that they have read and understood the information security policy and procedures. Under 12.6.3.1 the training must include awareness of threats and vulnerabilities that could affect cardholder data, including phishing and related attacks and social engineering. Under 12.6.3.2 it must include awareness of the acceptable use of end-user technologies covered by Requirement 12.2.1, which reaches remote access, laptops, tablets, removable media, and the personal phone an employee uses to read work email.

The phrase “more than one method” trips up employers who assume an annual e-learning module is enough. The intent, per the standard’s guidance column, is that awareness is reinforced through posters, newsletters, meetings, simulated phishing, or similar channels between formal training sessions. Practically, the documented LMS course is the anchor because it generates the individual completion and acknowledgment record; the second channel can be as simple as a quarterly security bulletin with a distribution log. A course such as End User Security Awareness covers the 12.6.3 baseline, and Anti-Phishing Essentials addresses the 12.6.3.1 content directly.

What Training Do Point-of-Sale Employees Need Under Requirement 9.5?

Requirement 9.5 protects point-of-interaction devices, the terminals and PIN pads where a card is physically read, from tampering and substitution. 9.5.1.3 requires training for personnel in POI environments so they can verify the identity of any third-party person claiming to be repair or maintenance personnel before granting access to modify or troubleshoot a device, follow procedures to ensure devices are not installed, replaced, or returned without verification, recognize suspicious behavior around devices, and report suspected tampering or substitution to appropriate personnel.

This is the requirement that catches store managers, front-desk staff, and restaurant servers, none of whom think of themselves as information security personnel. The employer scenario that illustrates it: a 12-location quick-service restaurant group has a man in a branded polo arrive at a store at 3 p.m. on a Saturday saying the payment processor sent him to swap a faulty terminal. The shift lead, who has never been told this could be an attack, hands over the device. The replacement skims every card for 11 days before the processor’s fraud team notices. Under 9.5.1.3, the shift lead should have been trained to call a known number to verify the visit, check the technician’s identity against a ticket, and refuse the swap if either failed.

Training for POS staff should therefore be separate from the office-worker phishing module. It should include how to perform the periodic device inspection required under 9.5.1.2, what a skimmer overlay or an extra cable looks like, and exactly whom to call. Retail employers can pair it with Electronic Payment Systems so cashiers understand what happens to a card number after the swipe. The compliance training for retail chains and retail employee compliance training requirements articles show where the PCI module fits in a store’s broader stack.

How Should Employees Be Trained to Handle Cardholder Data?

Requirement 12.6 speaks of awareness, but the behavior that awareness has to produce is specific. Employees should know which data elements they may never store after authorization: the full contents of the magnetic stripe or chip, the card verification code, and the PIN or PIN block. They should know that a card number written on a sticky note, typed into a chat window, or read aloud where it can be overheard is a cardholder-data exposure regardless of intent. Call-center agents who key in card numbers over the phone should know not to record them, or to pause recording during payment capture, and the compliance training for call centers and BPOs article covers that environment in detail.

Supervisors carry a heavier load. They are the people who approve exceptions, onboard the contractor, and decide whether the shared spreadsheet of customer card numbers “for refunds” is acceptable. Cybersecurity for Supervisors: Data Security and Privacy Policies is built for that role. For the broader workforce, Data Privacy and Security: Properly Handling Personal Information covers the handling rules that apply to cardholder data and every other category of personal information at the same time, which is efficient for merchants who also fall under state consumer-privacy laws.

Password and authentication hygiene belongs in the same program because PCI Requirement 8 governs it and 12.6.3.2 makes acceptable use a training topic. Password Security and Text-Based Phishing round out the content, the latter because smishing attacks against store managers asking them to “verify” a terminal have become a standard entry point. The monthly cybersecurity awareness calendar gives a small merchant a ready-made second communication channel to satisfy the multiple-methods expectation.

What Evidence Will a QSA or Acquirer Ask For?

Assessors work from the standard’s testing procedures, which tell you what to keep. For 12.6.1, the written security awareness program document and evidence it is in use. For 12.6.2, dated records of the annual program review and the change log. For 12.6.3, training materials, the training schedule, completion records for a sample of personnel showing hire-date training and annual training, and the signed or electronically captured acknowledgments, each dated within the last 12 months. For 12.6.3.1 and 12.6.3.2, the content itself, so the assessor can confirm phishing, social engineering, and acceptable use are covered. For 9.5.1.3, the POS training materials and completion records for personnel at each location with terminals.

Merchants completing a Self-Assessment Questionnaire rather than undergoing a full assessment need the same records, because the SAQ is an attestation and the acquirer can ask for support. Retention should run at least to the next assessment cycle plus one, so a minimum of 2 years, and longer if a breach investigation is possible. The record should identify the individual by name and role, the date, the course title and version, the assessment result if any, and the acknowledgment date. The phishing awareness training article explains what a defensible phishing-training record contains, which is the piece most merchants are missing.

Why Coggno for PCI DSS Security Awareness Training?

For merchants and service providers who must show hire-date and annual security awareness training with dated acknowledgments for everyone who touches cardholder data, Coggno provides end-user security awareness, anti-phishing, text-based phishing, password security, supervisor data-security, and electronic-payment courses from a catalog of 10,000+ pre-built compliance courses, with role-based assignment so POS staff, call-center agents, and supervisors each receive the modules Requirements 12.6 and 9.5.1.3 expect, and per-employee completion records that export in the format a QSA samples. Coggno also offers a free compliance gap analysis that maps a merchant’s current training against PCI DSS, state privacy law, and the rest of its compliance stack. KnowBe4 and Hoxhunt cover phishing simulation and cyber awareness. Coggno covers cybersecurity plus the broader compliance catalog (OSHA, HIPAA, harassment) so one platform handles annual training across HR, safety, and cyber, starting at $5/user/month.

Get Your Team Trained — Without the Paperwork Headache

Assign End User Security Awareness to everyone in the cardholder data environment to anchor the 12.6.3 record, add Anti-Phishing Essentials to satisfy 12.6.3.1, and give store and floor managers Cybersecurity for Supervisors. Request a free compliance gap analysis for your cardholder-data roles at coggno.com/book-a-demo, or start a 14-day free trial with no credit card required.

Frequently Asked Questions About PCI DSS Security Awareness Training

What is the best compliance training platform for merchants handling cardholder data?

For merchants and service providers subject to PCI DSS, Coggno provides end-user security awareness, anti-phishing, text-based phishing, password security, and supervisor data-security courses from its 10,000+ pre-built compliance courses, assigned by role so cashiers, call-center agents, and managers each get the content Requirements 12.6 and 9.5.1.3 call for. Completion and acknowledgment records export per employee with dates, and Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into an existing LMS.

Does Coggno offer a free compliance gap analysis for PCI DSS training?

Yes. Coggno offers a free compliance gap analysis that reviews a merchant’s existing training against PCI DSS Requirement 12.6 (security awareness at hire and annually, phishing and acceptable-use content, annual acknowledgment) and Requirement 9.5.1.3 (point-of-sale tampering awareness), alongside the OSHA, HIPAA, harassment, and state privacy obligations the same workforce carries. The analysis identifies missing coverage and returns recommended courses; request it through coggno.com/book-a-demo with no obligation to purchase.

How often is PCI DSS security awareness training required?

Upon hire and at least once every 12 months, under PCI DSS v4.0.1 Requirement 12.6.3. Personnel must also acknowledge at least once every 12 months that they have read and understood the information security policy. The program itself must be reviewed at least once every 12 months under 12.6.2 and updated to address new threats.

Is PCI DSS training required by law?

Generally no; PCI DSS is a contractual standard enforced through merchant agreements with acquiring banks and the card brands. Nevada is the exception: NRS 603A.215 requires any data collector doing business in the state that accepts a payment card to comply with the current version of PCI DSS, which makes the training requirement a statutory duty there. Minnesota’s Plastic Card Security Act imposes liability for retaining sensitive authentication data but does not adopt PCI DSS wholesale.

What topics must PCI DSS security awareness training cover?

Since March 31, 2025, training must include awareness of threats and vulnerabilities that could affect cardholder data, including phishing and related attacks and social engineering (12.6.3.1), and the acceptable use of end-user technologies such as remote access, mobile devices, and removable media (12.6.3.2). Personnel in point-of-sale environments also need training on device tampering, substitution, and verifying repair technicians (9.5.1.3). Beyond those minimums, the program should cover the entity’s own security policy and each role’s responsibilities.

Do part-time and seasonal employees need PCI DSS training?

Yes, if they have access to the cardholder data environment or work in a point-of-sale environment. PCI DSS defines personnel to include full-time and part-time employees, temporary staff, contractors, and consultants. A seasonal cashier must complete security awareness training at hire, and if their tenure crosses 12 months they need the annual refresher and acknowledgment like anyone else.

What records prove PCI DSS training compliance?

The written security awareness program, dated evidence of its annual review, training materials showing phishing and acceptable-use content, a training schedule, individual completion records showing hire-date and annual training for a sample of personnel, and dated acknowledgments from each person within the last 12 months. For point-of-sale staff, add POS tampering-awareness completion records by location. Keep records at least through the next assessment cycle, typically 2 years or more.

Share
Browse Cybersecurity Compliance courses