PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

Segmentation — Network segmentation

Segmentation isolates the cardholder data environment from the rest of the network so that out-of-scope systems cannot reach it. PCI DSS does not require segmentation, but it is the usual way to keep scope small.

What it means in practice

Where segmentation is used to reduce scope, penetration testing must validate that the segmentation controls are effective — annually for merchants and at least every six months for service providers.
Segmentation that exists on a diagram but not in the ruleset is the most common finding in this area.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.