PCI DSS compliance requires organizations to meet and validate the requirements of the Payment Card Industry Data Security Standard (PCI DSS) to protect payment account data. PCI DSS provides a baseline of technical and operational requirements for organizations that store, process, or transmit payment data. It also applies to entities that can impact the security of the cardholder data environment (CDE).
For companies, PCI DSS compliance goes beyond having security policies or technologies. Organizations must understand their scope, applicable requirements, control implementation evidence, and the assessment and validation methods required by the payment brand or acquirer.
What Are the PCI DSS Requirements?
PCI DSS v4.0.1 consists of 12 primary requirements that fall into six control objectives:
| Req. | Official Title | Main Focus |
|---|---|---|
| 1 | Install and Maintain Network Security Controls | Network security controls (NSC) between trusted and untrusted networks, including CDE segmentation |
| 2 | Apply Secure Configurations to All System Components | Hardening, secure configurations, and removal of default credentials |
| 3 | Protect Stored Account Data | Protection of stored account data, cryptographic keys, and PAN masking |
| 4 | Protect Cardholder Data with Strong Cryptography During Transmission | Strong encryption during transmission over open or public networks |
| 5 | Protect All Systems and Networks from Malicious Software | Anti-malware and phishing protection |
| 6 | Develop and Maintain Secure Systems and Software | Vulnerability management, secure software, and payment-page script controls |
| 7 | Restrict Access to System Components and Cardholder Data by Business Need to Know | Least privilege and access control based on business need |
| 8 | Identify Users and Authenticate Access to System Components | Unique IDs, password policies, and multi-factor authentication (MFA) |
| 9 | Restrict Physical Access to Cardholder Data | Physical access control, media, and POI devices |
| 10 | Log and Monitor All Access to System Components and Cardholder Data | Audit logging, daily log review, and log retention |
| 11 | Test Security of Systems and Networks Regularly | Vulnerability scanning (ASV), penetration testing, and change detection |
| 12 | Support Information Security with Organizational Policies and Programs | Security policy, targeted risk analysis, third-party management, and incident response |
PCI SSC published PCI DSS v4.0.1 in June 2024 as a limited revision of v4.0. The revision provides corrections and clarifications without adding or removing requirements.
Since March 31, 2025, all requirements that previously carried a future-dated status have become mandatory. These requirements include controls related to payment-page scripts and MFA for non-console access to the CDE.
How Does the PCI DSS Assessment Process Work?
A PCI DSS assessment evaluates whether security controls within the defined scope meet the applicable requirements. However, the payment brand and/or acquirer determines the validation method, not PCI SSC.
In general, organizations can approach the assessment process through the following stages:
| Stage | Focus |
|---|---|
| 1. Scope | Determine the systems, data, processes, and environments within the CDE or those that can impact CDE security. Organizations must confirm their scoping at least annually (Req. 12.5.2). |
| 2. Requirement | Determine the applicable requirements based on the scope and type of environment. |
| 3. Testing | Evaluate control implementation and supporting evidence against the official PCI DSS testing procedures. |
| 4. Reporting | Document assessment results in a ROC prepared by a QSA or through an applicable SAQ for self-assessment. |
| 5. Validation | Complete the AOC and ASV scan, where required, and submit the documentation to the party requesting validation. |
For organizations that use an SAQ, the process starts with selecting the appropriate SAQ and confirming the eligibility criteria. Next, the organization confirms its scope, performs the self-assessment, and completes the SAQ and AOC. If required, the organization also performs an ASV scan. Finally, it submits the required documentation to the acquirer or relevant party.
Related article : What Is PCI DSS? Definition, Objectives, and Benefits for Companies
What Are the Official PCI DSS Validation Documents?
PCI SSC recognizes validation documentation that uses the official templates available on the PCI SSC website.
| Document | Function |
|---|---|
| ROC | Report on Compliance. A QSA prepares this detailed assessment report using the official ROC Reporting Template. |
| SAQ | Self-Assessment Questionnaire. Eligible entities use an SAQ to perform a self-assessment. Several SAQ types are available, including A, A-EP, B, B-IP, C, C-VT, D, P2PE, and SPoC, depending on the payment environment. |
| AOC | Attestation of Compliance. The organization uses this official form to attest to assessment results based on a ROC or SAQ. |
| ASV Report | Attestation of Scan Compliance. An Approved Scanning Vendor (ASV) qualified by PCI SSC provides the results of an external vulnerability scan. |
Therefore, certificates or “compliance certificates” that do not use official PCI SSC templates do not qualify as valid PCI DSS validation evidence. See PCI SSC FAQ 1220 for further clarification.
How Can Companies Prepare for PCI DSS Compliance?
A common mistake is to start with a checklist before determining what actually falls within the scope. Instead, organizations should first understand their payment environment and identify the systems, data, processes, and controls that require attention.
A practical approach aligned with PCI SSC guidance is:
SCOPE → CONTROL → EVIDENCE → VALIDATE
| Stage | Focus |
|---|---|
| Scope | Identify relevant systems, data, processes, applications, networks, and third parties. Use network diagrams, data-flow diagrams, and system inventories to define the environment. |
| Control | Map each applicable requirement to the existing technical and operational controls. Then, identify any gaps. |
| Evidence | Prepare evidence that demonstrates how controls operate. Examples include configurations, log review records, vulnerability scan results, approved policies, and training records. |
| Validate | Determine the appropriate assessment method, such as an SAQ or ROC, based on the applicable compliance program. Then, complete the required official documentation, including the AOC and ASV scan where applicable. |
For example, an e-commerce company may use an external payment gateway without storing card data in its internal database. Even so, the company still needs to understand its payment architecture and accurately determine its scope.
The organization should also review its integration method, such as redirect, iframe, or direct post. In addition, it should establish clear responsibilities with the payment provider. PCI SSC provides specific criteria for e-commerce merchants and third-party payment pages, including eligibility for SAQ A and SAQ A-EP.
The SCOPE → CONTROL → EVIDENCE → VALIDATE framework represents a practical approach, not an official PCI SSC framework. Meanwhile, PCI SSC explains scoping and segmentation principles in its official Guidance for PCI DSS Scoping and Segmentation document.
PCI DSS Compliance vs. “Certification”
The term “PCI DSS certification” often appears in business and online searches. However, organizations should distinguish certification from compliance and validation.
PCI SSC does not issue compliance certificates to entities. Instead, organizations use official validation documents such as ROC, SAQ, and AOC, depending on the applicable validation method.
PCI-DSS compliance means meeting the applicable requirements. Meanwhile, validation documents the assessment results through official PCI SSC forms.
Therefore, organizations should not rely on the term “certification” as evidence of compliance because PCI SSC does not recognize it as an official validation method.
Conclusion
PCI DSS compliance requires more than completing a security checklist. First, organizations need to define their scope accurately. Next, they need to identify the applicable requirements and ensure that the relevant controls operate effectively.
Organizations should also prepare evidence that supports control implementation. Finally, they need to select the appropriate assessment and validation method based on the applicable compliance program.
As a result, structured preparation and reference to official PCI SSC documentation can help organizations understand their compliance position and identify potential gaps before the assessment begins.
Need Support in Preparing for PCI DSS Compliance?
Preparing for PCI DSS compliance requires a clear understanding of scope, applicable requirements, security controls, and supporting evidence.
If your organization needs to determine its scope, evaluate control readiness, or prepare for assessment and validation, CBQA Global can help discuss your requirements based on your business and technology environment.
With Certification, Audit, Training, Verification, and Validation services, CBQA Global supports organizations in strengthening assurance, compliance readiness, and risk management.
Contact CBQA Global:
Email: info@cbqaglobal.com
Marketing Email: marketing.cbqaglobal@gmail.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200
CBQA Global. We Inspire in Trust.
Certification | Audit | Training | Sustainability