Skip to content
Skip to content
PCI DSS Req 12.6-Aligned Training & Phishing Simulation

Security Awareness TrainingThat Actually Works

Assign PCI DSS-aligned training, run phishing simulations, track completion and certificates, and automate annual recertification — all in one platform that satisfies Req 12.6 without a separate LMS subscription.

87
Training API Endpoints
Deepest training module in GRC
11
Languages
Multi-language course content
Req 12.6
PCI DSS Aligned
Fully requirement-mapped
100%
Tracked Completion
Per user, per course, per cert

For Training Managers

Everything you need to run a compliant security awareness programme — without a separate LMS.

Course Library & Learning Paths

Curated PCI DSS security awareness courses covering cardholder data handling, social engineering, phishing, physical security, and incident response. Organise into custom learning paths by role or department.

  • Role-based learning paths
  • Modular course builder
  • Drag-and-drop path design
  • 11-language content

Assignment & Department Management

Assign training to individuals, departments, or entire organisations. Track who has been assigned, who has started, who has completed, and who is overdue — from one dashboard.

  • Bulk assignment by department
  • Role-based auto-assignment
  • Due date management
  • Overdue escalation

Phishing Simulation Campaigns

Run realistic phishing simulations aligned to PCI DSS Req 12.6. Choose from 50+ scenario templates, customise landing pages, and automatically enrol click-throughs in targeted remediation training.

  • 50+ phishing templates
  • Custom email/landing page
  • Auto-enrol click-throughs
  • Campaign scheduling

Certificate Management & Issuance

Automatically issue certificates upon course completion. Custom certificate templates with your organisation's branding. QSA-exportable completion records for audit evidence.

  • Auto-issuance on completion
  • Custom certificate templates
  • QSA audit export
  • Certificate validity periods

Recertification & Expiry Automation

Define recertification rules per course or learning path. Automatic reminders at 30/14/7 days before expiry. Expired certificates automatically trigger re-enrolment workflows.

  • Recertification rule engine
  • Auto-expiry reminders
  • Re-enrolment automation
  • Certificate expiry calendar

Training Analytics & Reporting

Completion rates, time-to-complete, phishing click rates, susceptibility trends, and quiz score distributions — all in a manager dashboard. Weekly summary emails to managers.

  • Completion rate dashboards
  • Phishing trend analysis
  • Quiz performance metrics
  • Manager weekly digest

Automated Reminders & Escalation

Daily reminder cron sends personalised emails to employees with outstanding training. Managers receive weekly summaries of overdue completions. Escalation rules notify department heads.

  • Daily per-user reminders
  • Weekly manager summary
  • Escalation to dept heads
  • Custom reminder templates

Multi-Language Support

Course content, UI, and certificates available in 11 languages. Employees see content in their preferred language automatically. Translations managed centrally by training admins.

  • 11 language course content
  • Auto-language detection
  • Centralised translation management
  • RTL language support
Phishing Simulation

Measure. Train. Improve. Prove It.

GRCTrack's phishing simulation engine sends realistic test emails, measures who clicked, auto-enrolls them in targeted micro-training, and tracks susceptibility reduction over time.

The improvement data is directly exportable for your QSA — satisfying PCI DSS Requirement 12.6 with measurable, documented evidence of security awareness improvement.

See Phishing Module Live
Phishing Campaign Results — Over Time
Campaign 1 (Baseline)
Click Rate34%
Report Rate12%
Campaign 2 (After Training)
Click Rate18%
Report Rate31%
Campaign 3 (90 days)
Click Rate8%
Report Rate52%
Click rate down 74% · Report rate up 333% across 3 campaigns

For Employees

A clean, simple My Training portal that employees actually want to use.

My Training Portal

Employees see their assigned courses, progress, due dates, and certificates in a clean personal portal.

Interactive Quiz Engine

Multi-choice quizzes with randomised question pools. Immediate feedback and explanations on each answer.

Certificate Downloads

Download completion certificates directly from the portal. Share with your manager or QSA.

Progress Tracking

See exactly where you are in each course and learning path. Resume from where you left off.

Satisfies PCI DSS Requirement 12.6

GRCTrack generates audit-ready evidence of your security awareness programme — completion records, certificate exports, phishing improvement metrics, and recertification history — all in the format your QSA expects.

Req 12.6.1 — Security awareness programme
Req 12.6.2 — Awareness training on hiring + annually
Req 12.6.3 — Phishing testing
Req 12.6.3.1 — Awareness of phishing threats
Req 12.6.3.2 — Behavioural change measurement
Simple, Transparent Pricing

Training Plans for Every Team Size

All plans include phishing simulation, certificate management, and PCI DSS Req 12.6 compliance evidence. No per-seat surprises.

Starter

For small merchants and teams up to 25 users

£99/month

Billed annually — £1,188/yr

  • Up to 25 users
  • 20+ security awareness courses
  • Phishing simulation (5 campaigns/mo)
  • Certificate generation
  • PCI DSS Req 12.6 evidence export
  • Email reminders
  • 3 languages
Start Free Trial
Most Popular

Professional

For growing organisations up to 250 users

£299/month

Billed annually — £3,588/yr

  • Up to 250 users
  • 60+ expert-built courses
  • Unlimited phishing campaigns
  • Custom certificate branding
  • AD/LDAP integration (Azure AD, Okta)
  • Department & role management
  • Learning path builder
  • Recertification automation
  • Manager analytics dashboard
  • 11 languages
Start Free Trial

Enterprise

For large organisations and QSA firms

£599/month

Billed annually — £7,188/yr

  • Unlimited users
  • All Professional features
  • White-label training portal
  • Multi-tenant client management
  • Custom course builder
  • API access for LMS integration
  • CISO Command Centre integration
  • SLA-backed support
  • Dedicated onboarding manager
  • Custom contract terms
Talk to Sales

All plans include a 30-day money-back guarantee. Prices exclude VAT. Need a custom quote?

Course Catalogue

60+ Courses Across Every Compliance Domain

Role-based learning paths covering PCI DSS, security awareness, GDPR, phishing defence, and more.

Built on Trust

Certified. Verified. Auditable.

GRCTrack maintains independent security and quality certifications so you can trust the platform that manages your compliance programme.

ISO 27001:2022
Certified
ISO 9001:2015
Certified
Cyber Essentials
Certified
Cyber Essentials+
Independently Verified
GDPR
UK & EU Compliant
SOC 2 Type II
In Progress

Launch Your Req 12.6-Compliant Training Programme Today

Start your free trial. No LMS required. No extra subscription. Just training that works.