Industry standardGlobal
PCI DSS
PCI DSS v4.0.1
The Payment Card Industry Data Security Standard applies to every organisation that stores, processes or transmits cardholder data. Version 4.0 became the only active version in April 2024, and its future-dated requirements became mandatory on 31 March 2025. Validation is by self-assessment questionnaire or an on-site assessment by a Qualified Security Assessor, depending on transaction volume.
Who it reaches
- Merchants accepting card payments, at levels set by their acquirer based on transaction volume.
- Service providers that handle cardholder data or affect its security: payment processors, hosting providers, gateways.
- Software vendors of payment applications, under the related PCI Secure Software Standard.
What the audit checks
- 01Level 1 merchants and service providers: annual on-site assessment by a QSA producing a Report on Compliance and an Attestation of Compliance.
- 02Lower levels: annual self-assessment questionnaire matching the payment channel, plus quarterly external scans by an Approved Scanning Vendor.
- 03Twelve requirements in six groups, from network security to policy.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Scope the cardholder data environment | 2 to 4 |
| Gap assessment against the 12 requirements | 2 to 4 |
| Remediation and segmentation | 8 to 24 |
| Assessment, scans, attestation | 2 to 8 |
Evidence to have ready
- Cardholder data environment scope and network diagrams
- Data flow diagrams for card data
- Firewall and segmentation configurations and tests
- Encryption and key management records
- Vulnerability management and quarterly ASV scans
- Penetration test reports
- Access control and MFA evidence
- Logging and daily log review
- Targeted risk analyses required by v4.0
- Policies and security awareness training
Dates
- PCI DSS v4.0 future-dated requirements became mandatory
Questions people ask
- Do I need a QSA?
- Level 1 merchants and most service providers do. Smaller merchants self-assess with the questionnaire their acquirer specifies, but many choose a QSA review for assurance.
- Can I reduce scope?
- Yes, and it is the single biggest lever: tokenisation, hosted payment pages and network segmentation keep card data out of most of your environment, shrinking what the assessment covers.