It requires at least an annual review and evidence that the program specifically covers phishing and social engineering, not just generic security content.
PCI DSS 12.6
PCI DSS v4.0 requirement on awareness programs that must include phishing.
Definition
Phishing simulation — A controlled lure to measure actual behavior, not the declared one.
QRishing — Phishing via QR code: the lure asks you to scan, not to click a link.
Ransomware (simulated) — A simulated attachment that would encrypt files, to measure the act of opening it without checking.
Report rate — Percentage of simulated (or real) threats that staff report using the phishing button.
Questions about PCI DSS 12.6
What is PCI DSS 12.6?
How does Whalemate use it?
Articles, guides and analysis on human risk management,
awareness and security culture
Guides and analysis for CISOs, IT and compliance teams in LATAM who need to explain the human factor — and decide what to do about it.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.
Read moreWant to see HRM in your organization?
Book a demo and we'll look at the program with data from your industry.