Home Audit PCI DSS Compliance : Requirements, Assessment Process, and How to Prepare

PCI DSS Compliance : Requirements, Assessment Process, and How to Prepare

PCI DSS compliance requirements and assessment process for organizations

Written By

CBQA Global

Follow us:

PCI DSS compliance requires organizations to meet and validate the requirements of the Payment Card Industry Data Security Standard (PCI DSS) to protect payment account data. PCI DSS provides a baseline of technical and operational requirements for organizations that store, process, or transmit payment data. It also applies to entities that can impact the security of the cardholder data environment (CDE).

For companies, PCI DSS compliance goes beyond having security policies or technologies. Organizations must understand their scope, applicable requirements, control implementation evidence, and the assessment and validation methods required by the payment brand or acquirer.

What Are the PCI DSS Requirements?

PCI DSS v4.0.1 consists of 12 primary requirements that fall into six control objectives:

Req.Official TitleMain Focus
1Install and Maintain Network Security ControlsNetwork security controls (NSC) between trusted and untrusted networks, including CDE segmentation
2Apply Secure Configurations to All System ComponentsHardening, secure configurations, and removal of default credentials
3Protect Stored Account DataProtection of stored account data, cryptographic keys, and PAN masking
4Protect Cardholder Data with Strong Cryptography During TransmissionStrong encryption during transmission over open or public networks
5Protect All Systems and Networks from Malicious SoftwareAnti-malware and phishing protection
6Develop and Maintain Secure Systems and SoftwareVulnerability management, secure software, and payment-page script controls
7Restrict Access to System Components and Cardholder Data by Business Need to KnowLeast privilege and access control based on business need
8Identify Users and Authenticate Access to System ComponentsUnique IDs, password policies, and multi-factor authentication (MFA)
9Restrict Physical Access to Cardholder DataPhysical access control, media, and POI devices
10Log and Monitor All Access to System Components and Cardholder DataAudit logging, daily log review, and log retention
11Test Security of Systems and Networks RegularlyVulnerability scanning (ASV), penetration testing, and change detection
12Support Information Security with Organizational Policies and ProgramsSecurity policy, targeted risk analysis, third-party management, and incident response

PCI SSC published PCI DSS v4.0.1 in June 2024 as a limited revision of v4.0. The revision provides corrections and clarifications without adding or removing requirements.

Since March 31, 2025, all requirements that previously carried a future-dated status have become mandatory. These requirements include controls related to payment-page scripts and MFA for non-console access to the CDE.

How Does the PCI DSS Assessment Process Work?

A PCI DSS assessment evaluates whether security controls within the defined scope meet the applicable requirements. However, the payment brand and/or acquirer determines the validation method, not PCI SSC.

In general, organizations can approach the assessment process through the following stages:

StageFocus
1. ScopeDetermine the systems, data, processes, and environments within the CDE or those that can impact CDE security. Organizations must confirm their scoping at least annually (Req. 12.5.2).
2. RequirementDetermine the applicable requirements based on the scope and type of environment.
3. TestingEvaluate control implementation and supporting evidence against the official PCI DSS testing procedures.
4. ReportingDocument assessment results in a ROC prepared by a QSA or through an applicable SAQ for self-assessment.
5. ValidationComplete the AOC and ASV scan, where required, and submit the documentation to the party requesting validation.

For organizations that use an SAQ, the process starts with selecting the appropriate SAQ and confirming the eligibility criteria. Next, the organization confirms its scope, performs the self-assessment, and completes the SAQ and AOC. If required, the organization also performs an ASV scan. Finally, it submits the required documentation to the acquirer or relevant party.

Related article : What Is PCI DSS? Definition, Objectives, and Benefits for Companies

What Are the Official PCI DSS Validation Documents?

PCI SSC recognizes validation documentation that uses the official templates available on the PCI SSC website.

DocumentFunction
ROCReport on Compliance. A QSA prepares this detailed assessment report using the official ROC Reporting Template.
SAQSelf-Assessment Questionnaire. Eligible entities use an SAQ to perform a self-assessment. Several SAQ types are available, including A, A-EP, B, B-IP, C, C-VT, D, P2PE, and SPoC, depending on the payment environment.
AOCAttestation of Compliance. The organization uses this official form to attest to assessment results based on a ROC or SAQ.
ASV ReportAttestation of Scan Compliance. An Approved Scanning Vendor (ASV) qualified by PCI SSC provides the results of an external vulnerability scan.

Therefore, certificates or “compliance certificates” that do not use official PCI SSC templates do not qualify as valid PCI DSS validation evidence. See PCI SSC FAQ 1220 for further clarification.

How Can Companies Prepare for PCI DSS Compliance?

A common mistake is to start with a checklist before determining what actually falls within the scope. Instead, organizations should first understand their payment environment and identify the systems, data, processes, and controls that require attention.

A practical approach aligned with PCI SSC guidance is:

SCOPE → CONTROL → EVIDENCE → VALIDATE

StageFocus
ScopeIdentify relevant systems, data, processes, applications, networks, and third parties. Use network diagrams, data-flow diagrams, and system inventories to define the environment.
ControlMap each applicable requirement to the existing technical and operational controls. Then, identify any gaps.
EvidencePrepare evidence that demonstrates how controls operate. Examples include configurations, log review records, vulnerability scan results, approved policies, and training records.
ValidateDetermine the appropriate assessment method, such as an SAQ or ROC, based on the applicable compliance program. Then, complete the required official documentation, including the AOC and ASV scan where applicable.

For example, an e-commerce company may use an external payment gateway without storing card data in its internal database. Even so, the company still needs to understand its payment architecture and accurately determine its scope.

The organization should also review its integration method, such as redirect, iframe, or direct post. In addition, it should establish clear responsibilities with the payment provider. PCI SSC provides specific criteria for e-commerce merchants and third-party payment pages, including eligibility for SAQ A and SAQ A-EP.

The SCOPE → CONTROL → EVIDENCE → VALIDATE framework represents a practical approach, not an official PCI SSC framework. Meanwhile, PCI SSC explains scoping and segmentation principles in its official Guidance for PCI DSS Scoping and Segmentation document.

PCI DSS Compliance vs. “Certification”

The term “PCI DSS certification” often appears in business and online searches. However, organizations should distinguish certification from compliance and validation.

PCI SSC does not issue compliance certificates to entities. Instead, organizations use official validation documents such as ROC, SAQ, and AOC, depending on the applicable validation method.

PCI-DSS compliance means meeting the applicable requirements. Meanwhile, validation documents the assessment results through official PCI SSC forms.

Therefore, organizations should not rely on the term “certification” as evidence of compliance because PCI SSC does not recognize it as an official validation method.

Conclusion

PCI DSS compliance requires more than completing a security checklist. First, organizations need to define their scope accurately. Next, they need to identify the applicable requirements and ensure that the relevant controls operate effectively.

Organizations should also prepare evidence that supports control implementation. Finally, they need to select the appropriate assessment and validation method based on the applicable compliance program.

As a result, structured preparation and reference to official PCI SSC documentation can help organizations understand their compliance position and identify potential gaps before the assessment begins.

Need Support in Preparing for PCI DSS Compliance?

Preparing for PCI DSS compliance requires a clear understanding of scope, applicable requirements, security controls, and supporting evidence.

If your organization needs to determine its scope, evaluate control readiness, or prepare for assessment and validation, CBQA Global can help discuss your requirements based on your business and technology environment.

With Certification, Audit, Training, Verification, and Validation services, CBQA Global supports organizations in strengthening assurance, compliance readiness, and risk management.

Contact CBQA Global:

Email: info@cbqaglobal.com
Marketing Email: marketing.cbqaglobal@gmail.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200

CBQA Global. We Inspire in Trust.
Certification | Audit | Training | Sustainability

More CBQA Global News

Ready to Strengthen Compliance, Trust, and Business Resilience?

Get expert support for your ISO certification and compliance needs through structured services in Certification, Audit, Training, Verification, Validation, Sustainability, and Professional Training to strengthen governance, reduce risk, and improve performance.

Apply for This Opportunity

Name
Drag & Drop Files, Choose Files to Upload