20 certification schemes

PCI DSS v4.0

PCI DSS Compliance

PCI DSS v4.0 sets the security requirements for any organisation that stores, processes or transmits payment card data.

Standard
PCI DSS v4.0
Indicative timeline
12-20 weeks
Discipline
Compliance & Security
Assessment type
Independent third-party assessment

The standard

Overview

The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council on behalf of the major card brands. Version 4.0 sets twelve requirements under six control objectives, covering network security, stored account data, encryption in transit, malware defence, secure development, access control, logging, testing and policy.

PCI DSS is a contractual obligation rather than a statutory one. Depending on transaction volume and how card data is handled, an entity validates through a Self-Assessment Questionnaire or a Report on Compliance, supported by an Attestation of Compliance and, where internet-facing systems are in scope, quarterly external scans.

UKCert starts with scope, because scope drives effort more than any other factor. We map cardholder data flows, review segmentation, test each requirement against the defined or customised approach, and record the targeted risk analyses that version 4.0 requires. Findings are reported requirement by requirement.

Who this is for

  • Merchants accepting card payments in store, online or by telephone
  • Payment service providers, gateways and acquiring processors
  • Hosting and managed service providers with access to client card environments
  • Contact centres and outsourced operations that capture card details
  • Software vendors whose products touch cardholder data

What it gives you

Why organisations certify

What a certified PCI DSS v4.0 assessment gives you once the certificate is issued.

Acquirer Assurance

Acquiring banks and card brands ask for validation evidence. A completed assessment gives them a clear, current statement of how account data is protected.

Reduced Breach Exposure

Requirements target the causes of card data loss: weak access control, unpatched systems, flat networks and poor logging. Addressing them lowers the chance of compromise.

Smaller Assessment Scope

Segmentation and tokenisation can take systems out of scope. Reviewing data flows early usually reduces the number of systems that must be assessed each year.

Contract Eligibility

Many payment contracts and enterprise supplier agreements require current PCI DSS validation before onboarding. Holding an Attestation of Compliance keeps those commercial routes open.

Clear Control Ownership

Version 4.0 asks for documented roles and responsibilities across the requirements. That removes ambiguity about who runs each control and who checks it.

Continuous Monitoring Habit

Quarterly scanning, annual penetration testing and routine log review turn security from a once-a-year exercise into a set of scheduled, evidenced activities.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • Cardholder data environment scoping
  • Network segmentation validation
  • Account data storage and retention review
  • Encryption and key management controls
  • Twelve-requirement control assessment
  • Targeted risk analysis documentation
  • ASV scan and penetration test evidence
  • Self-Assessment Questionnaire or Report on Compliance support

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scope Definition

    We map every system, process and third party that stores, processes or transmits account data, then confirm which segmentation controls keep the remaining environment out of scope.

  2. Validation Route

    Transaction volumes, acceptance channels and card brand rules determine whether the entity reports through a Self-Assessment Questionnaire and which type applies, or through a full Report on Compliance.

  3. Gap Assessment

    Each of the twelve requirements is tested against current practice. We record what is met, what is partially met and what is missing, with the evidence seen.

  4. Remediation Support

    The organisation closes gaps: hardening standards, access reviews, logging, patch cycles and policy updates. We review remediation evidence as it is produced rather than at the end.

  5. Evidence Review

    Configuration exports, scan reports, penetration test results, training records, vendor attestations and risk analyses are collected and checked against each requirement's testing procedures.

  6. Attestation and Upkeep

    Findings are documented for the Attestation of Compliance and submitted to the acquirer. Quarterly scans, annual testing and yearly revalidation then keep the position current.

Questions

PCI DSS v4.0 — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

It depends on scope and current state. A small merchant using a Self-Assessment Questionnaire with a narrow cardholder data environment may complete the work in a few weeks. A service provider validating through a Report on Compliance usually needs longer, commonly twelve to twenty weeks, because remediation, scanning and penetration testing all sit on the critical path.

Validation covers a twelve-month period. The Attestation of Compliance is dated and must be renewed annually. Between assessments the requirements still apply continuously: quarterly external scans by an Approved Scanning Vendor, internal scans, annual penetration testing, log review and change control all have their own frequencies written into the standard.

No. PCI DSS is not statute. It is enforced contractually by the card brands through acquiring banks and payment processors, and failure to validate can lead to higher fees, penalties passed down by the acquirer, or withdrawal of card acceptance. Separately, UK GDPR obliges organisations to protect personal data, and payment card data falls within that duty.

PCI DSS is revalidated every year. In the intervening months the organisation runs quarterly external scans, internal vulnerability scans, annual penetration tests and segmentation testing, and keeps policies, training and vendor records current. Significant changes to the cardholder data environment, such as a new payment channel, should be assessed when they happen rather than at renewal.

Version 4.0 allows an entity to meet a requirement's stated objective using controls other than those defined in the standard. The customised approach needs a documented control design, a targeted risk analysis, evidence that the objective is met, and testing procedures agreed with the assessor. It suits mature organisations; most entities still use the defined approach.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what PCI DSS v4.0 should sit alongside.