Back to Blog
Industry

How to Train Every Employee on PCI Security — Even Your Deskless and Non-English-Speaking Staff

Lasso Learn TeamJuly 15, 202610 min read

If your business accepts card payments, PCI DSS Requirement 12.6 requires you to train every employee who could affect cardholder data security — full-time, part-time, temporary, and contractors — upon hire and at least annually. The hard part for restaurants, retail, hotels, salons, and similar operators is not the content of the training. It is getting that training to hourly, deskless, and non-English-speaking employees who do not have a work email or a computer, and then proving each one of them completed it when an assessor asks.

This guide covers who actually needs the training under 12.6, why deskless and multilingual workforces break traditional security-awareness tools, what the standard actually expects in v4.0, whether free PCI awareness training is enough, how the requirement applies to remote workers, and how to deliver and document the training without an L&D team or an LMS rollout.

PCI training requirements at a glance

If you only need the short version of what PCI employee training involves, this is it:

Who All personnel who could affect cardholder data security — full-time, part-time, temps, and contractors, whether on-site, remote, or hybrid
When Upon hire, and at least annually thereafter
What Security awareness training specific to your own cardholder data environment and policies — not just a generic threat overview
Proof Per-employee completion records — who took which training, on what date — producible for an assessor

Who actually needs PCI security training?

Requirement 12.6 is broader than most operators assume. It is not just the people running the register or processing payments in the back office. It covers all personnel whose actions could affect the security of cardholder data — directly or indirectly:

  • Front-of-house staff handling cards. Servers, cashiers, baristas, front-desk clerks, retail associates, stylists who run checkout.
  • Back-office staff. Bookkeepers, managers reviewing batches, anyone who can access stored receipts or reports that include card data.
  • Support and facilities roles. Cleaners, maintenance, IT contractors, and anyone with physical access to areas where POS terminals or payment devices live.
  • Temps and contractors. Seasonal workers, agency staff, contracted cleaners — anyone in the environment falls under the same training expectation.

The cadence is also non-negotiable: training is required upon hire and at least annually thereafter. A onboarding video on day one and silence after that does not meet 12.6.

Does PCI training apply to remote and hybrid workers?

Yes. The scope test in 12.6 is not where someone sits — it is whether their actions could affect the security of cardholder data. A bookkeeper reconciling batches from a home office, a remote manager who can pull reports containing card data, a virtual assistant handling phone orders, or a hybrid employee who takes the occasional payment over the phone are all in scope, exactly as if they worked behind the counter.

Remote workers actually raise the stakes in one specific way: they operate outside your physical controls. There is no manager nearby to notice a receipt left on a desk, no locked back office, no supervised terminal. Training is the control that travels with them — which is why the content for remote staff should cover the remote-specific risks (household members and card data, home Wi-Fi, phone payments taken outside the POS environment) and not just the in-store scenarios. And the documentation expectation is identical: a per-employee completion record for the remote bookkeeper, on the same dashboard as the front-of-house crew.

The delivery problem, conveniently, is the same one deskless staff have already forced you to solve. Training that works on any phone with a company code and PIN reaches the remote worker at their kitchen table exactly as easily as the line cook in the break room.

Why is PCI training so hard for businesses with hourly or deskless staff?

The standard is the same for a 12-table restaurant as it is for a Fortune 500. The reality of delivering it is not. For a typical hourly or deskless workforce, the obstacles stack up fast:

  • No work email. Most hourly employees never get a company email address. Security-awareness platforms built around email-based course assignments and reminders simply do not reach them.
  • No computer or desk. A server, a cashier, or a housekeeper does not sit at a workstation. Traditional desktop training assumes a chair and a login that does not exist.
  • High turnover. Hospitality and retail run double-digit monthly turnover. Onboarding training has to happen on day one, every time, without an IT ticket — and last year’s completion records still need to be intact for the annual refresh.
  • Mixed languages. A significant share of restaurant, hotel, and salon staff are more comfortable in Spanish, Vietnamese, Portuguese, Tagalog, or another language. English-only training does not actually train them, and on a PCI assessment that gap is visible.
  • No L&D team, no IT department. The owner-operator or the GM is the one rolling training out, between everything else they do.

The honest answer is that off-the-shelf desktop security-awareness tools were designed for office workforces. They are not built for the operators who carry the bulk of card-present commerce. Reaching those teams takes a delivery model built for workers without inboxes — our guide to mobile training with no email required covers how QR and PIN access works in practice.

What does PCI Requirement 12.6 actually expect?

PCI DSS v4.0 sharpened what the training has to look like. The bar is no longer just “everyone watched a generic video once.” The standard expects:

  • Security awareness for all personnel. Upon hire and at least annually, covering the threats and policies relevant to their role.
  • Content specific to YOUR cardholder data environment. v4.0 expects training tailored to the company’s own cardholder data environment and policies — how you handle card data, the specific procedures your staff are expected to follow. A generic off-the-shelf module on its own is not enough.
  • Acknowledgement and comprehension. Personnel are expected to acknowledge they have read and understood the security policy and procedures. Knowledge checks that prove comprehension are stronger than a signature on a sheet.
  • Documentation. Per-employee records — who took which training, on what date — that can be produced for an assessor.

Lasso Learn is not a QSA and does not certify PCI compliance. PCI compliance is broader than training, and your assessor or acquirer makes the compliance determination. What we do is the delivery, customization, multilingual narration, and tracking that helps an operator actually meet the 12.6 training mandate.

Is free PCI awareness training enough?

Free PCI compliance training for employees does exist — card brands, acquirers, and a handful of security vendors publish generic awareness videos and slide modules at no cost. The honest answer is that they are better than nothing, and they cover the basics competently: what cardholder data is, why skimmers and phishing matter, why you never write a card number on a sticky note. If your alternative is no training at all, use one today.

But measured against what 12.6 actually expects, free generic modules come up short in three specific ways:

  • They are not specific to your environment. PCI DSS v4.0 expects security awareness training tailored to your own cardholder data environment and your own policies — how your staff handle cards at your terminals under your procedures. A generic video about a hypothetical retailer, by definition, cannot cover any of that. An assessor reviewing your evidence file can see the gap.
  • They do not reach hourly staff without email. Free modules are almost always delivered as a link — emailed to each employee or posted on a portal. For a workforce where most people have no company email and no desk, the link never arrives, and the most exposed employees are exactly the ones who never take the training.
  • They leave the documentation to you. A free video produces no per-employee record. You end up assembling your own spreadsheet of who watched what and when, chasing signatures, and hoping the file is intact when the assessment comes. This is the same proof-not-content problem that runs through all compliance training: the content is the cheap part; the per-person evidence is what you are actually being asked to produce.

A reasonable pattern for a small operator: use a free module as a stopgap on day one, and treat it as exactly that — a stopgap. What closes the 12.6 gap is training built from your own policies, delivered in a way that reaches your whole roster, with completion records generated automatically. Our guide to employee training tracking for small businesses covers what that documentation layer should do across every compliance topic, not just PCI.

How do you train and DOCUMENT it for an assessment?

The two pieces an assessor wants to see are that the training happened and what it covered — for every person in scope. A done-for-you mobile model produces both as a side effect of how it is rolled out:

  • Per-employee completion records. Every completion is tied to an individual employee, with a timestamp and the version of the course completed.
  • Knowledge checks. Short comprehension questions after each section produce a real record that the employee understood the content — not just that they pressed play.
  • Certificates of completion. A per-employee, per-course certificate is generated automatically. These are internal certificates of completion for your training; they are not PCI certifications.
  • Audit-ready export. A single export gives an assessor the roster, the dates, the courses, and the comprehension results — instead of a stack of signed sheets pulled from a drawer.
  • QR / PIN login for deskless workers. A QR badge or a company code plus personal PIN gets a hostess, a line cook, or a housekeeper into the training on their own phone or a shared break-room tablet, with completions still attributed to the individual.
  • Mixed-language delivery. The same module narrated in Spanish, Vietnamese, Portuguese, or another language so every employee actually learns the material in the language they understand best — and the dashboard still rolls up across all of them.

The language piece deserves its own emphasis: an employee who did not understand the training was not really trained, whatever the completion log says. Our guide to multilingual compliance training — one course, every language covers how the single-course, many-languages model works.

How is this different from off-the-shelf security awareness software?

Off-the-shelf security-awareness libraries — including phishing-simulation tools — are built for office workforces with email and desktops. They do useful things in that environment. For a hospitality or retail operator with hourly, deskless, multilingual staff, they leave the most exposed part of the workforce untrained. The two models can complement each other, but they are not the same thing:

Off-the-shelf desktop security awareness Custom done-for-you mobile training
Content source Generic library, threat catalog Built from YOUR security policies and procedures
Who it reaches Email-and-desktop employees Hourly, deskless, multilingual staff
Login model Work email and password QR badge or company code + personal PIN
Languages Usually English (extras as add-ons) Native-language narration on the same content
Specific to your environment Generic, optional customization Built specifically for your CHD environment
Documentation for 12.6 Email-tied completion logs Per-employee records, certificates, export
Phishing simulation Often included Not in scope — different category of tool

An office with desktop staff often runs an awareness library and custom training for its frontline. The two cover different populations. The point is not to replace one with the other — it is to stop assuming the desktop tool reaches the part of the workforce most often exposed to card data.

How fast can it be ready?

Done-for-you means the work the operator does is short. You send your security policy and procedures — what you already have for PCI — plus any short phone videos of how staff are expected to handle cards, terminals, or receipts. The partner builds the course:

  • Days to a first module. A core PCI security awareness module built from your policy, narrated, with comprehension checks, lands as a draft in days.
  • Weeks for the full rollout. Role-specific modules (front-of-house, back-office, contractors), the multilingual versions, and the assignment-and-tracking setup come together over weeks, not months.
  • No L&D team. No LMS implementation. The course and the tracking come together. You do not separately license an LMS, buy a library, and stitch them together.
  • Annual refresh handled. When the year rolls around, the refresher re-assigns automatically and the dashboard shows who is current and who is overdue — for the same set of people you were already tracking.

Frequently Asked Questions

Does this make us PCI compliant?

No. PCI compliance is broader than training and Lasso Learn is not a QSA. Your assessor or acquirer makes the compliance determination. What we do is help you meet the training portion — Requirement 12.6 — by delivering customized training to every employee, including deskless and non-English-speaking staff, and producing the per-employee documentation an assessment expects.

Do you issue a PCI certification?

No. The certificate generated at the end of each course is an internal certificate of completion for your training program — useful for your documentation and for your assessor’s evidence file. It is not an official PCI certification, and we do not represent it as one.

Can the training be in Spanish, Vietnamese, or other languages?

Yes. The same module can be delivered with native-language narration so every employee learns the material in the language they understand best. The dashboard still rolls up across all languages, so you have one consolidated record for the entire workforce.

How often does each employee need this training?

Per Requirement 12.6, security awareness training is required upon hire and at least annually thereafter, for all personnel whose actions could affect cardholder data security. The platform handles the assign-on-hire and annual-refresher cadence automatically and shows you who is current at any moment.

Is free PCI compliance training enough for my employees?

Free PCI awareness modules cover the generic basics and are better than nothing, but PCI DSS v4.0 expects training specific to your own cardholder data environment, delivered to everyone in scope, with per-employee documentation. Free generic modules meet none of those three tests on their own — they work as a day-one stopgap, not as your 12.6 evidence.

Do remote and hybrid employees need PCI training?

Yes. Scope under 12.6 is based on whether someone’s actions could affect cardholder data security, not where they work. A remote bookkeeper, a hybrid manager pulling payment reports, or anyone taking phone payments from home is in scope and needs the same on-hire and annual training — with the same completion records — as on-site staff. Mobile PCI DSS eLearning reaches them on their own device the same way it reaches deskless staff on the floor.

Share:LinkedInTwitter

Related posts

See it in action

Schedule a demo and we'll walk through how Lasso Learn fits your team.

Schedule a Demo