Financial · PCI Security Standards Council
PCI DSS v4.0.1
All future-dated requirements became mandatory March 31, 2025. If you take cards, this applies now.
Who it applies to
The businesses that carry PCI DSS, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
Cyber and Data Protection Assessment
Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year
SOC 2 Readiness: Type 1 and Type 2
SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it
Practice Cybersecurity, Data Protection and HIPAA Package
Medical and dental practices, clinics, surgery centers, hospital departments and the business associates that serve them
What it asks for
In plain English, what PCI DSS expects you to have in place.
- Cardholder data scoped and segmentedKnow where card data flows, and keep everything else out of scope.
- Twelve requirementsNetwork controls, secure configurations, protection of stored and transmitted account data, vulnerability management, access control, logging, testing and a policy program.
- The right validationA Self-Assessment Questionnaire or a Report on Compliance, depending on your volume and how you take cards.
- E-commerce page controlsScript management and tamper detection on payment pages under v4.0.1.
- Third partiesProcessors and hosting providers listed, with their compliance evidence on file.
- Continuous rhythmQuarterly scans, annual validation and a targeted risk analysis for the requirements that allow flexibility.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about PCI DSS
Do you certify PCI DSS compliance?
Where do we start with PCI DSS?
We also need other frameworks. Do we do PCI DSS separately?
Also in financial: FTC Safeguards · SEC Reg S-P · NYDFS 500 · FINRA · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for PCI DSS.
Book the demo and see how one control set carries PCI DSS and everything else you owe. Or leave your details and an engineer replies within one business day.