We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 12 of 12

Requirement 12: Support Information Security with Organizational Policies and Programs

Everything the other eleven requirements assume: policy, risk analysis, awareness, third parties, incident response. v4 moved real weight here — targeted risk analyses now justify half the standard’s frequencies, and scope must be confirmed annually in writing.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

12.1.1–12.1.4
InfoSec policy, known and owned

An information-security policy established, published, reviewed annually, with security responsibility formally assigned to a CISO or equivalent.

12.3.1
Targeted risk analyses for flexible frequencies

Every control that says "per TRA" (POI inspections, scan frequencies, training cadence…) needs a documented analysis — new v4 machinery that assessors collect as a set.

12.5.2
Annual scope confirmation

PCI DSS scope documented and confirmed at least annually and on significant change — every six months for service providers (12.5.2.1). The written exercise, not an assumption.

12.6.2–12.6.3
Awareness programme with phishing content

Security awareness reviewed annually, delivered on hire and at least annually, with acknowledgement — and must address phishing/social engineering (12.6.3.1).

12.8.1–12.8.5
Third-party service providers managed

TPSP list, written agreements with responsibility acknowledgements, due diligence before engagement, annual monitoring of their PCI status, and a responsibility matrix per provider.

12.10.1–12.10.7
Incident response that has been exercised

An IR plan covering roles, communication, regulators and card brands; tested at least annually; personnel trained; and procedures for PAN discovered where it should not be (12.10.7).

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

TPSP list without a responsibility matrix

12.8.5 wants, per provider, which requirements they cover vs you — an AOC on file alone does not answer it.

Missing targeted risk analyses

Choosing "weekly" for a flexible control without the TRA behind it fails 12.3.1 across every control that leaned on it.

Scope exercise nobody wrote down

The annual scope confirmation (12.5.2) needs a dated artefact: data flows, people, processes, technologies, third parties.

IR plan tested never

A tabletop with attendance, scenario and lessons-learned is the minimum evidence for 12.10.2 — an unopened PDF is not a capability.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • Policy set with review dates and management approval
  • The TRA collection: one per flexible-frequency control in use
  • Annual scope-confirmation document with data flows and third parties
  • Awareness records: content incl. phishing, completion, acknowledgements
  • TPSP register: agreements, AOCs, responsibility matrices, annual checks
  • IR plan + most recent test records and post-incident lessons

Requirement 12 FAQ

What is a targeted risk analysis (TRA)?

A documented analysis (per 12.3.1) that justifies how frequently you perform a flexible-frequency control — identifying the assets and threats, and why the chosen cadence keeps risk acceptable.

How do we evidence third-party compliance?

Annually confirm each TPSP’s PCI DSS status (their AOC or equivalent), keep written agreements with responsibility acknowledgements (12.8.2/12.9), and maintain a shared responsibility matrix (12.8.5).

How often must incident response be tested?

At least annually (12.10.2), with training for responders and a plan that includes card-brand/regulator notification and the v4 addition: what to do when PAN turns up where it should not be (12.10.7).

← Requirement 11: Security Testing

Requirement 12 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.