PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 10.4.1 — Daily audit log review

Requirement 10.4.1 requires daily review of security events and of logs from all systems that store, process or transmit account data, all critical system components, and all servers performing security functions. Requirement 10.4.1.1 adds that automated mechanisms must be used to perform those reviews.Timing: Applies in PCI DSS v4.0.1. Requirement 10.4.1.1 (automated log review) is mandatory for all assessments since 31 March 2025.

Who it applies to

Entities operating in-scope systems that generate audit logs
Entities completing SAQ D-Merchant or SAQ D for Service Providers

What Requirement 10.4.1 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

All security events are reviewed at least once daily.
Logs of all system components that store, process or transmit account data are reviewed daily.
Logs of all critical system components are reviewed daily.
Logs of servers and components performing security functions — network security controls, IDS/IPS, authentication servers — are reviewed daily.
Automated mechanisms are used to perform the reviews (Requirement 10.4.1.1).

Evidence an assessor expects

SIEM or log platform configuration showing in-scope sources onboarded
Alerting rules and the triage workflow for exceptions
Records showing daily review actually occurred, including weekends and holidays
Evidence that the review is automated rather than a manual sample

Common mistakes

Collecting logs centrally but only reviewing them when something goes wrong.
Gaps in coverage where a critical system never shipped its logs to the platform.
A manual spot-check process that no longer satisfies the automated-review requirement.

Not sure whether Requirement 10.4.1 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.