Get Demo
↑

PCI DSS Requirement 12: Policies, Risk Analysis, Awareness, TPSPs, and Incident Response

PCI DSS v4.0.1 Requirement 12 - security policy, TRA (12.3.1), scope confirmation, awareness (incl. phishing), TPSP management (12.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 12 in v4.0.1 is titled Support Information Security with Organizational Policies and Programs. It covers the information security policy, acceptable use, targeted risk analyses for flexible frequencies, crypto and technology reviews, scope inventory and annual confirmation, security awareness (including phishing and social engineering), personnel screening, third-party service provider (TPSP) governance, and a tested incident response plan.

Related: Requirement 10 · Requirement 11 · 12 requirements hub.

v4.0.1 note: PCI SSC clarified Applicability Notes on customer and third-party service provider (TPSP) relationships under Requirement 12. No requirements were added or deleted. Gotcha: a TPSP Attestation of Compliance (AOC) is not a substitute for the written agreement required by 12.8.2. Phishing awareness training (12.6.3.1) is separate from technical phishing controls in 5.4.1.

Requirement Structure

Clause
Focus
12.1
Comprehensive information security policy and executive ownership
12.2
Acceptable use of end-user technologies
12.3
Formal risk identification - especially 12.3.1 TRA for flexible frequencies
12.4
PCI DSS compliance management (service-provider sub-clauses)
12.5
Document and validate PCI DSS scope
12.6
Security awareness (ongoing; phishing and social engineering)
12.7
Personnel screening
12.8
Manage TPSP risk
12.9
TPSPs support customers (service-provider only)
12.10
Incident response for suspected or confirmed CDE incidents

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Is a TPSP's AOC enough for 12.8.2?

No. 12.8.2 requires written agreements that include acknowledgments of security responsibility. Evidence that a TPSP meets PCI DSS (for example an AOC) is not the same as that written agreement.

What is a targeted risk analysis (12.3.1)?

A documented analysis that justifies how frequently a flexible or periodic PCI DSS control must be performed - covering assets, threats, likelihood/impact factors, annual review, and updates when needed. It is not a full enterprise risk assessment substitute.

Does phishing awareness training satisfy 5.4.1?

No. 12.6.3.1 is security awareness training about phishing and social engineering. 5.4.1 is a separate technical/automated control to detect and protect personnel against phishing. Meeting one does not meet the other.

PCI DSS hub · IR plan template · Policy templates · 12 requirements hub · PCI DSS v4.0.1: What Changed

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!