Back to blog

Blog

PCI DSS 12.6 Requires Vishing Coverage

Vishing and smishing are voice and SMS phishing. Under PCI DSS 12.6, measuring only email or course completion leaves a compliance gap.

PCI DSS 12.6 Requires Vishing Coverage

Vishing and smishing are not semantic variations of phishing. They are distinct channels that now require a different response. For CISOs, IT, and compliance teams in LATAM, the key point is that PCI DSS already requires coverage of phishing, related attacks, and social engineering in awareness programs, and it also requires acceptable use training for end-user technologies such as mobile devices, while regional risk is rising precisely through SMS, WhatsApp, and voice. If the program still centers on email or on course completion, it leaves an operational gap in both compliance and real exposure of the CDE, Coggno, Segurilatam, Kaspersky.

What appears when the sources are put together

The sources either describe the terms separately, explain PCI, or show regional pressure in LATAM. What emerges when they are read together is a concrete operational gap: the formal requirement is already in PCI DSS and the real pressure has already shifted to mobile and voice, but many programs still measure only email or course attendance.

Subject type Primary channel Target action Program or control requirement Evidence of measurement or scope LATAM relevance fuente
Vishing subtype of phishing / social engineering voice, phone calls, or voice messages induce the victim to reveal sensitive information or start a trust-based conversation not specified phishing by voice communication, calls or voice messages to obtain credentials, cards, or banking data not specified
Smishing subtype of phishing / social engineering SMS or text messages get the victim to click a link, download files or apps, or start a conversation not specified CISA defines it as phishing by text message, IBM and Experian link it to information theft or malware Segurilatam reports 286 million mobile fraud attempts via SMS and WhatsApp in 2023, and 74% of organizations in LATAM victims of smishing
PCI DSS 12.6 compliance requirement not specified ensure staff know the policy, procedures, and their role in protecting cardholder data formal awareness program implemented applies to PCI entities in LATAM, the source does not regionalize PCI SSC
PCI DSS 12.6.3.1 compliance sub-requirement not specified awareness of threats and vulnerabilities that could affect cardholder data, including phishing, related attacks, and social engineering minimum content required starting March 31, 2025 applies to PCI organizations in LATAM, the source does not regionalize Coggno
PCI DSS 12.6.3.2 compliance sub-requirement end-user technologies, including mobile devices, remote access, and removable media acceptable use of end-user technologies minimum content required starting March 31, 2025 relevant because smishing is shifting to mobile devices Coggno
LATAM exposure context regional risk series fake messages, mobile, SMS, and WhatsApp fraud, phishing, and smishing at scale not specified Kaspersky recorded 1.291 billion phishing blocks in Latin America between 2023 and 2024, an 85% increase, and Segurilatam reported 286 million mobile fraud attempts and 74% of organizations as smishing victims explicit
Whalemate HRM approach operating model / platform multichannel, not limited to email simulate, train, measure, intervene, and report human risk the risk score consolidates signals from simulations, courses, reports, and behavior, and is used to prioritize interventions, not for discipline Whalemate is aimed at IT, CISO, and compliance teams in Latin America Whalemate HRM, Whalemate

What exactly does it mean that vishing and smishing are variants of phishing?

The overlap across sources is broad: vishing and smishing are phishing subtypes differentiated by channel. CISA defines vishing as phishing by voice communication and smishing as phishing by text messages, CISA PDF. NIST reinforces that phishing is no longer limited to email and can appear as fraudulent text messages or fraudulent phone calls.

Experian summarizes phishing, smishing, and vishing as differing in how the attacker contacts the victim, email, text, or phone, Experian. SentinelOne and Dexpose use the same channel-based classification, distinguishing phishing, smishing, and vishing by email, SMS, and voice calls. Whalemate's reading is that this distinction is not just useful for an internal glossary: it enables separate metrics by channel, because the behavior to detect and correct is not identical in voice, SMS, or email.

Why does the channel difference change operational risk?

In vishing, CISA describes a conversation dynamic designed to build trust and get the victim to disclose sensitive information, including by inducing the person to call a specified number. Cisco adds that those calls or voice messages seek credentials, card numbers, or banking data. Adaptive Security adds that attackers also seek MFA codes or transfers.

In smishing, the dominant pattern is different. CISA ties it to messages that lead the user to click, download files or applications, or start a conversation, CISA PDF. IBM, Egress, and NCB highlight the mobile component, links, and automatic opening of browser, email, or call features, IBM, Egress, NCB. Whalemate's reading is that a single phishing indicator is not enough if vishing aims to sustain a conversation and smishing aims to trigger an immediate action on the device.

What does PCI DSS 12.6 require, and why isn't a single course enough?

The SAQ D Merchant document for PCI DSS v4.0 states that a formal security awareness program must be implemented so that all personnel know the security policy and procedures and their role in protecting cardholder data, PCI SSC. Whalemate's material, aligned with that requirement, emphasizes that PCI DSS 12.6 requires an awareness program, not an isolated course, Whalemate.

Secondary ISO 27001 summaries point in the same direction of continuous process. Control Institute and High Table note that people under the organization's control must be aware of the policy, their contribution to the system, and the implications of noncompliance, Control Institute, High Table. Guardey, High Table, Cyberzoni, and Advisera add that control 6.3 requires a formal program, broad coverage, regular updates, and evidence of effectiveness, Guardey, High Table Annex A 6.3, Cyberzoni, Advisera. Whalemate's reading is that compliance is already pushing toward continuity and evidence, not toward annual training disconnected from real behavior.

What do PCI DSS 12.6.3.1 and 12.6.3.2 add to the problem?

Coggno explains that under 12.6.3.1 the training must include awareness of threats and vulnerabilities that could affect cardholder data, including phishing, related attacks, and social engineering, Coggno. The same source says that 12.6.3.2 requires coverage of acceptable use of end-user technologies such as remote access, mobile devices, and removable media, also starting March 31, 2025, Coggno.

That intersection changes how vishing and smishing should be read by PCI teams. If smishing happens through SMS, messaging, and mobile, and if vishing uses calls, voicemail, VoIP, and even AI-driven impersonation, then the expected scope of the program cannot stay limited to email phishing. Whalemate's reading is that 12.6.3.1 and 12.6.3.2 together require mapping human risk and technology use by channel, not just proving attendance in a training session.

Where is the tension between NIST's broad guidance and real-world execution?

NIST says two relevant things. First, phishing is not limited to email and also appears as smishing and vishing. Second, teams need to stay vigilant across all communication areas, NIST. That wording expands the awareness perimeter.

Whalemate, in its reading of NIST SP 800-50r1, shifts the focus from the presentation to practical exercise. It argues that the enterprise-wide program should include phishing, spear phishing, vishing, and smishing, and that the operational focus is not the talk but whether the user detects the attempt or clicks, Whalemate blog. The tension is not doctrinal, it is about execution: NIST expands the channels, but if the organization does not test observable behavior by channel, it is left with educational intent and no evidence of response.

Where is the tension between PCI DSS and the reality of LATAM?

PCI DSS, according to Coggno, already requires phishing, related attacks, social engineering, and acceptable use of mobile devices in the minimum content of the program, Coggno. At the same time, Segurilatam reports 286 million mobile fraud attempts via SMS and WhatsApp in 2023 and says that 74% of organizations in Latin America were victims of smishing in the last year, Segurilatam. Kaspersky adds 1.291 billion phishing attack blocks in Latin America between 2023 and 2024, an 85% increase, Kaspersky.

The tension is direct. The requirement already covers the risk and the channel, but regional incident volume shows that practice is still failing precisely in mobile and messaging. Whalemate's reading is that a program centered on email can both comply worse and protect worse at the same time, because it leaves out the channel where regional volume has already become visible.

Why isn't measuring only course completion enough?

Whalemate argues that HRM is not a security awareness course, but an approach that models context, simulates, trains, measures, intervenes, and reports, Whalemate HRM. That contrast matters because SecureCodingHub's material on PCI DSS 12.6.1 recommends recognition patterns, reporting procedures, and explicit current examples, including QR-code phishing, AI voice impersonation, and pretexting in Teams and Slack.

If the content has to reflect current techniques and if the risk is expressed in user behavior, course completion is an incomplete signal. It does not show whether the person recognized a suspicious SMS, cut off a pretext call, reported an attempt, or shared a one-time code. Whalemate's reading is that a standalone learning metric does not prove operational resilience against vishing and smishing.

What should be measured by channel for vishing and smishing?

The material leads to four minimum groups of measurement: exposure, detection, reporting, and response. This comes from combining the channel-based characterization from CISA, NIST, Proofpoint, and Adaptive Security with PCI DSS content requirements and the continuous measurement approach of HRM, CISA News, Proofpoint Social Engineering, Adaptive Security, Whalemate HRM.

In smishing, exposure refers to users and roles that operate more through mobile or messaging. Detection focuses on recognizing fraud signals in SMS, WhatsApp, or apps. Reporting measures whether the attempt reaches internal security channels. Response records whether there was a click, download, callback, credential handoff, or sharing of codes. In vishing, the logic changes: what matters is whether the user keeps the conversation going or ends it, whether identity is validated through another channel, and whether the incident is escalated in time, Proofpoint Vishing, Canadian Centre for Cyber Security.

Why do mobile and voice create a specific gap in the CDE?

SecureCodingHub says phishing and social engineering were responsible for a significant share of CDE compromises recorded in the 2024 to 2025 window, although it does not provide a specific percentage, SecureCodingHub. Adaptive Security and Acronis show that vishing can target credentials, MFA, transfers, or installation of remote access tools, Adaptive Security, Acronis. That broadens impact from data theft to initial access and movement across systems.

In smishing, the mobile vector often sits outside classic corporate email controls. IBM and Egress highlight links, malware, and urgent requests on mobile devices, IBM, Egress. Whalemate's reading is that if staff who touch card environment processes also use mobile devices to authenticate, approve workflows, or respond to messages, then the awareness gap by channel can turn into a direct CDE gap.

What does HRM add to that gap?

Whalemate describes HRM as an approach that models context, simulates, trains, measures, intervenes, and reports, Whalemate HRM. It also says its public modules include advanced simulations, adaptive training, human risk analytics, and an awareness agent. For this problem, that makes it possible to move from generic awareness to an operational cycle for vishing and smishing.

The benefit is not only simulating more channels. It is connecting signals. Whalemate says the risk score consolidates data from simulations, courses, reports, and behavior, and is used to prioritize interventions, not for discipline, Whalemate HRM. Whalemate's reading is that, applied to vishing and smishing, that score can show who is more exposed or responds worse on mobile and voice, so the team can intervene with adaptive training or compensating controls instead of using the data as punishment.

What decision does this enable for CISOs, IT, and compliance in LATAM?

The decision is not semantic, it is about program design. If vishing and smishing are phishing by voice and SMS, if PCI DSS 12.6 requires a formal program, if 12.6.3.1 requires coverage of phishing, related attacks, and social engineering, and if 12.6.3.2 requires acceptable use of mobile devices, then the program must be measured by channel and not only by email or course completion, PCI SSC, Coggno.

For a CISO in LATAM, that means defining exposure, detection, reporting, and response metrics for SMS, voice, and messaging, in addition to email. For IT, it means adding simulations and reporting paths that account for mobile devices, calls, and blended campaigns, something Proofpoint says is common when smishing is used in tandem with voice calls, Proofpoint Vishing. For compliance, it means asking for evidence of effectiveness by channel, not just attendance evidence. An HRM approach makes that transition operational with multichannel simulations, adaptive training, and a risk score to prioritize interventions without turning the score into a disciplinary tool, Whalemate, Whalemate HRM.

What to read next?

See the full topic guide

Would you like to go deeper on this topic?

Open this article directly in Claude or ChatGPT — ask questions, get a summary, or explore related ideas.

Open with ClaudeOpen with ChatGPT