Compliance Training

PCI DSS Security Awareness

Card data leaks through ordinary moments — a terminal that reboots mid-sale, a number written on a sticky note "just until the system is back", a caller who sounds exactly like processor support. This course is built for everyone who touches a payment: front counter, phone orders, billing, dispatch, management and the people who support them. It teaches the pause that keeps card data inside the approved path.

4 Video Modules20 CheckpointsRandomised Final Exam
60 Min
Course Duration
80%
Pass Score
20
Question Bank

Who This Course Is For

PCI DSS Requirement 12.6 expects security awareness training for personnel who can affect the security of cardholder data. In practice that is a much wider group than the people who think of themselves as "handling payments".

Front counter and point-of-sale staff
Phone, mail and card-not-present order takers
Billing, accounts receivable and refunds teams
Dispatch and customer service who take card details
Managers and owners who approve exceptions
IT, help desk and anyone supporting payment devices
Cleaning, maintenance and anyone near terminals
New hires and annual refresher audiences

What the Course Covers

Four modules, roughly fifteen minutes each, with five knowledge checkpoints inside every video and a three-question quiz at the end of each one.

1

Payment Data and Shared Responsibility

The Payment Journey; Account Data: Know the Difference; The Cardholder Data Environment; Your Role in Payment Security; Training Evidence Is Not PCI Validation.

The Payment JourneyAccount Data: Know the DifferenceThe Cardholder Data EnvironmentYour Role in Payment SecurityTraining Evidence Is Not PCI Validation
15 min5 checkpoints3 quiz questions
2

Secure Handling in Daily Operations

Use Approved Payment Channels; Prevent Unapproved Copies; Mask, Retain and Dispose; Inspect Payment Terminals; Phone, Remote and Card-Not-Present Work.

Use Approved Payment ChannelsPrevent Unapproved CopiesMask, Retain and DisposeInspect Payment TerminalsPhone, Remote and Card-Not-Present Work
15 min5 checkpoints3 quiz questions
3

Phishing, Authentication and Access

Payment-Focused Social Engineering; Unique Accounts and MFA; Least Privilege and Role Changes; Third-Party and Support Access; Secure Payment Workstations.

Payment-Focused Social EngineeringUnique Accounts and MFALeast Privilege and Role ChangesThird-Party and Support AccessSecure Payment Workstations
15 min5 checkpoints3 quiz questions
4

Incident Recognition and Response

Recognize Reportable Events; First Authorized Actions; Preserve Evidence and Role Boundaries; Build a Useful Incident Report; Capstone: Tampering and Fake Support.

Recognize Reportable EventsFirst Authorized ActionsPreserve Evidence and Role BoundariesBuild a Useful Incident ReportCapstone: Tampering and Fake Support
15 min5 checkpoints3 quiz questions

A Final Exam That Cannot Be Memorised

The final assessment draws 10 questions at random from a 20-question bank, and shuffles the answer options on every attempt. Two employees sitting the exam side by side do not get the same paper, and retaking it does not mean replaying the same answers in the same order. You need 80% to pass, and you can retake it as many times as you need.

10 questions drawn from 20
Answer options shuffled each attempt
80% required to pass

What This Certificate Does and Does Not Cover

PCI DSS security-awareness completion record only. This certificate does not certify an organization, system, merchant, service provider, or individual as PCI DSS compliant. Employer-specific policies, reporting contacts, system procedures, role-based training, and documented annual acknowledgement remain required.

Simple, Transparent Pricing

Train everyone who touches a payment, not just the front counter

Individual

One employee, one certificate

$59
$119
  • 4 video modules
  • 20 in-video knowledge checkpoints
  • Quiz after each module
  • Randomised final exam (10 of 20 questions)
  • Downloadable certificate
  • Lifetime access
  • 80% passing score required
Most Popular

Team of 5

Small offices and owner-operators

$239($47.8/seat)
$595
Save 19%
  • 4 video modules
  • 20 in-video knowledge checkpoints
  • Quiz after each module
  • Randomised final exam (10 of 20 questions)
  • Downloadable certificate
  • Lifetime access
  • 80% passing score required
  • Admin dashboard
  • Progress tracking
Best Value

Team of 10

Multi-department teams

$429($42.9/seat)
$1190
Save 27%
  • 4 video modules
  • 20 in-video knowledge checkpoints
  • Quiz after each module
  • Randomised final exam (10 of 20 questions)
  • Downloadable certificate
  • Lifetime access
  • 80% passing score required
  • Admin dashboard
  • Progress tracking
  • Bulk enrollment
  • Compliance reports

Enterprise

Fleets and large employers

Contact Us

Save when you train for more than one requirement

Most teams need more than one certification. Add a second course and 10% comes off your whole order — a third takes off 15%.

  • Cybersecurity Awareness / Phishing & Social Engineering

    Phishing, Social Engineering & Safe Work · $49.00

    Both courses $97.20 — you save $10.80

  • HIPAA for the General Healthcare Workforce

    Privacy, Security & Breach Response · $59.00

    Both courses $106.20 — you save $11.80

The rules this course is built on

We teach to the published text. Read it yourself — every link below goes to the issuing agency or legislature, not to a summary.

Issuing authority: PCI Security Standards Council (industry standard body, not a government regulator), with US federal guidance from NIST and CISA

Provided so you can verify what we teach against the source. This is reference material, not legal advice, and reading it does not by itself discharge an employer obligation.

Common Questions

Does this make our business PCI DSS compliant?

No, and be careful with any training vendor that says otherwise. PCI DSS compliance is an organisational outcome established through a Self-Assessment Questionnaire or a QSA assessment covering your systems, network, vendors and policies. This course produces one specific piece of evidence: that your personnel received security awareness training, which is what Requirement 12.6 asks for. It is one line item in a much larger validation effort.

Does it satisfy PCI DSS Requirement 12.6?

It is built to support it. Requirement 12.6 expects a formal security awareness programme with training at hire and at least annually, covering threats relevant to cardholder data. This course delivers that training and gives you a dated, per-person completion record to file as evidence. Your assessor will also expect to see your own programme documentation, your policy acknowledgements and role-specific training where it applies.

How long does it take?

About 60 minutes of video across four modules, plus quizzes and the final assessment. You can stop and resume; progress is saved to your account.

How often should this training be repeated?

PCI DSS expects security awareness training at hire and at least once every twelve months, plus additional training when threats or processes change. The certificate shows a one-year validity date to match that cadence.

Does it cover terminal tampering and fake support calls?

Yes. Module 2 covers inspecting payment terminals for skimmers and substitutions, and Module 4 closes on a capstone that combines a tampering indicator with a caller impersonating support — the two patterns that most often show up together in real card-present fraud.

What happens if I fail the final exam?

You can retake it. Each attempt draws a fresh set of questions from the bank, so a retake is a genuine re-test rather than a second run at the same paper.

Can I buy seats for my team?

Yes. Five-seat and ten-seat bundles are available above, and larger volumes can be arranged through the enterprise contact form.

Get your people trained

Instant access. Completion record on passing. Lifetime access to the material.

Start Training - $59

Already purchased? Go to the course