When PCI DSS 4.0.1 took effect on March 31, 2025, Requirement 12.6 stopped being the easiest line item in the entire standard. For years it asked almost nothing of security teams: run an annual training video, log a completion percentage, move on. Now it asks for a documented program, reviewed at least every 12 months, […] The post PCI DSS finally caught up to human risk appeared first on Fable Security .