Blog
Articles on PCI DSS
What we publish on PCI DSS for CISOs, IT and compliance teams in LATAM.
Articles on PCI DSS 12.6, the v4.0 requirement that an awareness program specifically cover phishing and social engineering, reviewed at least annually. We cover what evidence a QSA assessor asks for, how generic security content differs from content that directly answers the requirement, and the questions that come up during certification for companies processing card data in LATAM.

PCI DSS, audit
Apr 2, 2026By Federico Hombre
PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.
Read moreWant to see this in your organization?
Book a demo. We will look at how to measure human risk in your team and what to change first.
Book a demo