What are the PCI DSS requirements?
PCI DSS 4.0.1 has 12 requirements grouped under 6 goals, and they apply to any organization that stores, processes, or transmits payment card data. The goals are: build and maintain a secure network and systems, protect account data, maintain a vulnerability management program, implement strong access control, regularly monitor and test networks, and maintain an information security policy.
The 12 requirements, grouped into 6 goals
The 12 requirements are: (1) install and maintain network security controls; (2) apply secure configurations to all system components; (3) protect stored account data; (4) protect cardholder data with strong cryptography during transmission over open, public networks; (5) protect all systems and networks from malicious software; (6) develop and maintain secure systems and software; (7) restrict access to system components and cardholder data by business need to know; (8) identify users and authenticate access; (9) restrict physical access to cardholder data; (10) log and monitor all access; (11) test the security of systems and networks regularly; and (12) support information security with organizational policies and programs.
Who it applies to, and how you validate
PCI DSS applies to merchants and service providers that touch cardholder data. How you validate depends on your volume and how you handle card data: smaller merchants typically complete a Self-Assessment Questionnaire (SAQ), while the largest (Level 1) need an annual Report on Compliance (ROC) from a Qualified Security Assessor (QSA). A quarterly external vulnerability scan by an Approved Scanning Vendor is required for many.
You can shrink scope by not touching card data
The single biggest lever is scope. If you fully outsource payments to a PCI-compliant processor using a hosted checkout or tokenization, so card data never reaches your servers, you can validate with the shortest questionnaire (SAQ A). The more your own systems store or transmit the primary account number, the more of the 12 requirements come into scope.
Where Keel fits
Keel ships the PCI DSS 4.0.1 requirements as a trackable control set, crosswalked to the SOC 2, ISO 27001, and other controls you already run, so most of your evidence carries over and PCI becomes a mapping exercise rather than a fresh project.
FAQ
What version of PCI DSS is current?
PCI DSS 4.0.1, a minor clarifying update to version 4.0. The previously future-dated 4.0 requirements are now in full effect, so a current program should be validating against 4.0.1.
Do I self-assess or get audited?
Most smaller merchants and service providers self-assess with the appropriate SAQ. Level 1 merchants and Level 1 service providers need an independent Report on Compliance from a QSA (or an internal auditor where permitted).
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free