PCI-DSS v4.0.1 is the only active standard since January 2025. All 51 future-dated requirements — including payment page script monitoring (Req 6.4.3), change-detection on payment pages (Req 11.6.1), and MFA for all CDE access — became mandatory March 31, 2025. If you're running your 2026 assessment against outdated training, your QSA will flag it. We deliver live, documented training that satisfies Requirement 12.6 and gives you the attendance records your auditor actually needs.
Personal — $150 → Executive — $390 → Business — $900 flat → Free PCI-DSS scoping assessment →PCI DSS v4.0.1 applies to every entity that stores, processes, or transmits cardholder data — merchants and service providers at every level. Merchant level determines your validation type, not your training obligation. Requirement 12.6 applies to anyone who touches the Cardholder Data Environment.
Requirement 12.6 requires documented security awareness training for all personnel with access to the CDE. Below is the full requirement map your QSA will reference during your v4.0.1 assessment.
The Cardholder Data Environment (CDE) is the people, processes, and technology that store, process, or transmit cardholder data — and any system that connects to those systems.
Two documents your QSA will ask for:
No spam. One-click unsubscribe. From hello@secureveryone.com.
Check your inbox — and your spam folder.
Personal — $150 → Executive — $390 → Business — $900 flat →Our 4-module live coaching curriculum takes you from SAQ type determination through to evidence package completion. Delivered by PCI-DSS-aware instructors who understand what QSAs actually check for. Individual attendance records for every participant.
All four modules covered in sequence — scoping, technical controls, incident response, evidence collection. Individual attendance records per module. SAQ gap report included.
Book the full 4-module track →Every tier includes documented training evidence for your QSA assessment file. Module selection maps to your SAQ type.