HomeFrameworksInformation Security & PrivacyPCI DSS

Framework  Information Security & Privacy

PCI DSS

The Payment Card Industry Data Security Standard is the card brands' baseline for any organization that stores, processes or transmits cardholder data or can affect its security. The current version is PCI DSS v4.0.1, published June 11, 2024; v4.0 was retired on December 31, 2024, and the requirements that were future-dated in v4.0 became mandatory on March 31, 2025.

The standard has twelve requirements covering network security, secure configuration, protection of stored account data, encryption in transit, malware protection, secure development, access control, authentication, physical security, logging, testing and information security policy, plus a customized approach for organizations that want to meet objectives differently.

PCI DSS is documentation-intensive. It expects a maintained cardholder data environment scope and data flow diagrams, an information security policy reviewed annually, targeted risk analyses for frequency-based controls, documented roles and responsibilities for every requirement, an incident response plan, third-party service provider inventories and responsibility matrices, and an annual Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) with an Attestation of Compliance.

Which validation path applies (QSA ROC or a specific SAQ) is decided by the acquirer and card brand programs based on merchant or service provider level.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSecurity policy 2026by name, on record
Req. 12.1 Handledwith AllyMatter
Card It the Modern WayRequirement 12 policies, acknowledged by everyone who touches card data
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every cashier and engineer on record
Annual acknowledgment, re-collected each cycle
03
Hand the QSA the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Merchants, service providers, acquirers, issuers and any other entity that stores, processes or transmits cardholder data or sensitive authentication data, or that could affect its security. Validation level depends on annual transaction volume and the brand program: Level 1 merchants and most service providers need a QSA ROC; smaller merchants complete an SAQ.

What the assessor asks to see

CDE scope, network and data flow diagrams; asset inventory; information security policy and procedures per requirement; firewall and configuration standards; encryption and key management documentation; vulnerability scan and penetration test reports; access control lists and MFA evidence; log samples and daily review records; change control records; secure development evidence; physical security records; awareness training; incident response plan and test; third-party service provider list and responsibility matrix; prior ROC, SAQ and AOC.

Where the requirement sits: 12.1.1 policy reviewed annually; 12.6.3 awareness training at hire and annually with acknowledgment; 12.10 IR plan. Technical: 5, 10 (logging), 11 (scanning)

Self-Assessment Questionnaires under v4.0.1

Ten SAQs exist: SAQ A (card-not-present, fully outsourced payment page), SAQ A-EP (e-commerce where the merchant site affects the payment page), SAQ B (imprint or standalone dial-out terminals), SAQ B-IP (standalone PTS-approved IP-connected terminals), SAQ C (payment application systems connected to the internet), SAQ C-VT (virtual terminal on a single computer), SAQ P2PE (validated P2PE solution only), SAQ SPoC (software-based PIN entry on COTS), SAQ D for Merchants (all other merchants) and SAQ D for Service Providers (the only SAQ for eligible service providers).

Eligibility is set by the SAQ instructions and the acquirer.

Version timeline

PCI DSS v3.2.1 was retired March 31, 2024. v4.0.1 was published June 11, 2024 as a limited revision correcting v4.0, which was retired December 31, 2024. The 51 requirements that were best practice under v4.0 became mandatory on March 31, 2025.

Check the PCI SSC document library for any later revision.

What AllyMatter does here

The Requirement 12 policy and annual-acknowledgment layer of PCI DSS.

AllyMatter publishes this site.

Assessors

Who assesses PCI DSS

A PCI SSC qualified Qualified Security Assessor (QSA) company with certified QSA employees performs the ROC. Certified Internal Security Assessors (ISAs) can support internal assessments where the acquirer permits. Approved Scanning Vendors (ASVs) perform quarterly external vulnerability scans.

Small merchants self-assess on an SAQ. Accredited by PCI Security Standards Council qualifies QSA, ISA and ASV companies and individuals; there is no national accreditation body.

Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors/

No firm has claimed a PCI DSS assessor listing yet. Claim yours →

Consultants

Who helps with PCI DSS

A very large ecosystem: QSA companies selling readiness and gap assessments, PCI consultancies, managed security providers, ASV scanning vendors and compliance platforms. Engagements range from SAQ assistance to multi-month ROC readiness projects. The readiness consultant and the signing QSA may be the same firm subject to independence rules.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. PCI DSS v4.0.1 unveiled: what's new and what it means for youA QSA company goes through the v4.0.1 clarifications and the future-dated requirements that became mandatory in March 2025.Schellman
  2. Targeted risk assessments in PCI DSS 4.0.1Explains the targeted risk analysis documents assessors now expect, and how they set your own control frequencies.Frazier & Deeter

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for PCI DSS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of PCI DSS in AllyMatter

Approve the policies PCI DSS asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.