PCI DSS Compliance
PCI DSS v4.0 sets the security requirements for any organisation that stores, processes or transmits payment card data.
- Standard
- PCI DSS v4.0
- Indicative timeline
- 12-20 weeks
- Discipline
- Compliance & Security
- Assessment type
- Independent third-party assessment
The standard
Overview
The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council on behalf of the major card brands. Version 4.0 sets twelve requirements under six control objectives, covering network security, stored account data, encryption in transit, malware defence, secure development, access control, logging, testing and policy.
PCI DSS is a contractual obligation rather than a statutory one. Depending on transaction volume and how card data is handled, an entity validates through a Self-Assessment Questionnaire or a Report on Compliance, supported by an Attestation of Compliance and, where internet-facing systems are in scope, quarterly external scans.
UKCert starts with scope, because scope drives effort more than any other factor. We map cardholder data flows, review segmentation, test each requirement against the defined or customised approach, and record the targeted risk analyses that version 4.0 requires. Findings are reported requirement by requirement.
Who this is for
- Merchants accepting card payments in store, online or by telephone
- Payment service providers, gateways and acquiring processors
- Hosting and managed service providers with access to client card environments
- Contact centres and outsourced operations that capture card details
- Software vendors whose products touch cardholder data
What it gives you
Why organisations certify
What a certified PCI DSS v4.0 assessment gives you once the certificate is issued.
Acquirer Assurance
Acquiring banks and card brands ask for validation evidence. A completed assessment gives them a clear, current statement of how account data is protected.
Reduced Breach Exposure
Requirements target the causes of card data loss: weak access control, unpatched systems, flat networks and poor logging. Addressing them lowers the chance of compromise.
Smaller Assessment Scope
Segmentation and tokenisation can take systems out of scope. Reviewing data flows early usually reduces the number of systems that must be assessed each year.
Contract Eligibility
Many payment contracts and enterprise supplier agreements require current PCI DSS validation before onboarding. Holding an Attestation of Compliance keeps those commercial routes open.
Clear Control Ownership
Version 4.0 asks for documented roles and responsibilities across the requirements. That removes ambiguity about who runs each control and who checks it.
Continuous Monitoring Habit
Quarterly scanning, annual penetration testing and routine log review turn security from a once-a-year exercise into a set of scheduled, evidenced activities.
Scope
What the assessment covers
The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.
- Cardholder data environment scoping
- Network segmentation validation
- Account data storage and retention review
- Encryption and key management controls
- Twelve-requirement control assessment
- Targeted risk analysis documentation
- ASV scan and penetration test evidence
- Self-Assessment Questionnaire or Report on Compliance support
How it runs
The assessment, stage by stage
From first enquiry to certificate. Each stage is agreed with you before it starts.
-
Scope Definition
We map every system, process and third party that stores, processes or transmits account data, then confirm which segmentation controls keep the remaining environment out of scope.
-
Validation Route
Transaction volumes, acceptance channels and card brand rules determine whether the entity reports through a Self-Assessment Questionnaire and which type applies, or through a full Report on Compliance.
-
Gap Assessment
Each of the twelve requirements is tested against current practice. We record what is met, what is partially met and what is missing, with the evidence seen.
-
Remediation Support
The organisation closes gaps: hardening standards, access reviews, logging, patch cycles and policy updates. We review remediation evidence as it is produced rather than at the end.
-
Evidence Review
Configuration exports, scan reports, penetration test results, training records, vendor attestations and risk analyses are collected and checked against each requirement's testing procedures.
-
Attestation and Upkeep
Findings are documented for the Attestation of Compliance and submitted to the acquirer. Quarterly scans, annual testing and yearly revalidation then keep the position current.
Questions
PCI DSS v4.0 — frequently asked
Anything here that does not cover your situation, put it to an assessor rather than guessing at it.
Same discipline
Other schemes in Compliance & Security
Certifying against more than one standard?
Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what PCI DSS v4.0 should sit alongside.