PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS compliance checklist for v4.0.1

PCI DSS compliance follows the same order every time: confirm how you accept payments, define scope, establish whether you may self-assess, select the correct SAQ or engage a QSA, implement and evidence each applicable requirement, then validate with your acquirer. Everything else is detail hanging off those six steps.

1. Map how you accept payments

Scope follows account data. Before anything else, list every channel and every system that touches it.

List every payment channel: e-commerce, MOTO, card-present terminals, virtual terminal, recurring billing.
Draw the data flow for each channel, from cardholder to acquirer, including any third party in the path.
Identify every system that stores, processes or transmits account data, plus systems connected to or able to affect those.
Confirm no sensitive authentication data is retained after authorisation anywhere, including logs and support tickets.

2. Confirm you may self-assess

Level 1 merchants and Level 1 service providers require a QSA-led Report on Compliance.
A Report on Compliance mandated by your acquirer or a payment brand removes the SAQ option.
Designated entities subject to PCI DSS Appendix A3 cannot use a short-form SAQ.
A confirmed account-data breach in the last 12 months usually triggers acquirer escalation.

3. Select the correct SAQ

Each payment channel must independently meet the eligibility criteria of the SAQ used for it.
Every short-form SAQ requires that no account data is stored electronically, including legacy data.
Where channels cannot each satisfy a short form, SAQ D for Merchants covers the remainder.
Service providers only have SAQ D for Service Providers, and only where eligible to self-assess.

4. Work the requirements and collect evidence

For each applicable requirement, evidence is what the assessment turns on — not intent.

Policies and procedures that are documented, current, in use and known to affected staff.
Configuration evidence: hardening standards, rulesets, MFA coverage, access model and role mapping.
Operational evidence: patch records, quarterly ASV scans, penetration test reports, log review records, POI inspection logs.
Programme evidence: TPSP register and agreements, targeted risk analyses, security awareness training, incident response plan and its annual test.

5. Close gaps before you attest

Track each gap with an owner, a remediation date and the evidence that will close it.
Where a requirement cannot be met as written, decide between a compensating control worksheet and the customised approach — both need documentation.
Rescan or retest after remediation; a failed ASV scan with a remediation plan is not a passing scan.

6. Validate and keep it running

Complete the SAQ and Attestation of Compliance, or have a QSA validate and sign them.
Submit to your acquirer or payment brand as they direct — they are the compliance-accepting entity.
Confirm scope at least annually, and every six months if you are a service provider.
PCI DSS is a continuous state: quarterly scans, daily log review and annual testing continue between assessments.

Turn the reading into an answer

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.