PCI DSS v4.0

The card-data standard: twelve requirements that apply when, and only when, you touch cardholder data.

Conditional standard · Payment Card Industry Data Security Standard, version 4.0

Issued by

PCI Security Standards Council

Region

International

Effective

v4.0 published March 2022; fully in force since March 2025

Oversight

Enforced via card brands and acquirers; assessed by QSAs or SAQ

Applies when

You store, process or transmit cardholder data, or can affect its security

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

PCI DSS applies conditionally: if cardholder data crosses your systems, the standard follows it. Version 4.0 kept the twelve-requirement shape but pushed toward continuous compliance, customised approaches and targeted risk analyses.

The practical work is scoping: knowing where cardholder data lives, segmenting what does not need to be in scope, and evidencing the controls that protect what remains.

Where programmes are tested.

01

Scope and segmentation

A defensible cardholder-data environment boundary, reviewed as the estate changes.

02

The twelve requirements

From network security and access control to logging, testing and policy, evidenced continuously rather than annually.

03

Assessment and attestation

Self-assessment or QSA assessment, with the evidence trail behind every answer.

Curated once, evidenced continuously.

  • PCI requirements are curated and cross-mapped, so the access, logging and vulnerability controls you already run for ISO and SOC 2 count toward PCI where they genuinely overlap.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

PCI DSS v4.0, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who must comply with PCI DSS?

Any entity that stores, processes or transmits cardholder data, or could affect its security, from global merchants to a startup with a payment form. Compliance is enforced contractually through acquirers and card brands rather than by a government regulator.

What are the PCI DSS compliance levels?

Merchants and service providers are tiered by transaction volume, which determines the assessment: the largest undergo an on-site assessment by a Qualified Security Assessor producing a Report on Compliance, while smaller entities complete the applicable Self-Assessment Questionnaire.

What changed in PCI DSS v4.0?

v4.0 introduced the customised approach, targeted risk analyses, and stronger requirements around authentication and e-commerce protection. Its future-dated requirements became mandatory in March 2025, which is when the compliance bar effectively rose.

Does using a payment provider or tokenisation take us out of scope?

It shrinks scope, sometimes dramatically, but never to zero: the integration, the redirect or the iframe you control still affects the security of cardholder data, and the scoping decision itself must be documented and defensible.

Where it connects.

The full catalog
Carried by these modules
Who answers to it

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.