PCI DSS 12.6 asks for a formal awareness program that includes phishing and social engineering, with at least an annual review. A 40-minute course once a year does not produce that evidence.
What the auditor wants to see
What the auditor wants to see is history: each campaign with channel, lure, scope and result, plus a training record per person. That is a byproduct of running the program, not a folder assembled three weeks before the audit.
The PCI DSS 12.6 term is the short definition. This note exists for the long-tail query "PCI DSS 12.6 security awareness training".
Native phishing simulation — email and QR — leaves a behavior record. Adaptive training leaves a completion record. The report button leaves a defensive-gesture record. Together they are a program. A policy PDF on the intranet is not.
ISO 27001 and the rest of the mapping
ISO/IEC 27001 control A.6.3 requires awareness and training relevant to each person’s role. Whalemate produces that evidence as an exportable training record. The organization is certified ISO/IEC 27001:2022 by A-LIGN; trust detail lives in the Trust Center.
The control mapping — ISO 27001, PCI, and the statutes the compliance brief declares — is on the compliance page. This note does not replace that brief or invent a local law article.
How it is operated, not how it is dressed up
A program that only exists in the audit month is not 12.6. A program that runs simulations, assigns training on failure and exports the record can be shown. Banking has its own industry brief; the Banco del Sol case is a customer narrative, not a PCI certificate.
Smishing and other vectors outside the native channel run as a professional service when the scope is authorized. They are not sold as a self-service feature to inflate a control.
A formal awareness program that includes phishing and social engineering, with at least an annual review. A 40-minute course once a year does not produce that evidence.
What does the auditor want to see?
History: each campaign with channel, lure, scope and result, plus a training record per person. That is a byproduct of running the program, not a folder assembled three weeks before the audit.
Does an annual course meet 12.6?
No. The requirement asks for a program and specific evidence of phishing and social engineering, not generic security content.
Where is the control mapping?
On the compliance page. ISO/IEC 27001 A.6.3 requires role-relevant awareness. The Trust Center declares Whalemate’s ISO/IEC 27001:2022 certification (A-LIGN).
Would you like to go deeper on this topic?
Open this article directly in Claude or ChatGPT —
ask questions, get a summary, or explore related ideas.