Curriculum traceability

PCI DSS v4.0

This matrix shows how each curriculum area maps to PCI DSS v4.0requirements — the clause or control it supports, how it's taught, and the evidence the learner and organisation receive. It's a sample, illustrative mapping; your live records (completions, assessment scores, version history) form the per-organisation evidence pack.

What this supports — and what it doesn't

These programs support preparation for PCI DSS v4.0 certification: they deliver the awareness and competence training the standard requires (notably Clause 7.2 Competence, 7.3 Awareness, and Annex A 6.3) and produce the documented completion and assessment records auditors look for. They do notby themselves certify your organisation or any individual, and they don't guarantee certification — your organisation still implements the management system and is audited by an accredited certification body. Training is the supporting evidence, not the certificate.

PCI-DSS Awareness

Curriculum areaPCI clauses / controlsMethodEvidence produced
PCI Basics: Cardholder Data & the Standard
Req 12.6Req 3.2
Lesson + knowledge-checkPer-learner completion (version-stamped) + quiz score
Handling Cardholder Data Safely
Req 3Req 4Req 9
Lesson + knowledge-checkPer-learner completion (version-stamped) + quiz score
Protecting Payment Systems & Devices
Req 9.5Req 5Req 2
Lesson + knowledge-checkPer-learner completion (version-stamped) + quiz score
Incidents, Compliance & Your Obligations
Req 12.10Req 12
Lesson + knowledge-checkPer-learner completion (version-stamped) + quiz score

Hover a clause code for its title. Clause references follow PCI DSS v4.0. For a per-organisation, audit-ready evidence pack, get in touch.