Free resource · PCI DSS v4.0

PCI DSS Compliance Checklist

All 12 PCI DSS v4.0 requirements across the six goals, plus SAQ scoping. Work through it below, or download the CSV with status and evidence columns.

Build & maintain a secure network

  • 1 — Install and maintain network security controls (firewalls / NSCs; segment the CDE)
  • 2 — Apply secure configurations to all system components (no vendor defaults)

Protect account data

  • 3 — Protect stored account data (minimise storage; render PAN unreadable; key management)
  • 4 — Protect cardholder data with strong cryptography during transmission over open networks

Maintain a vulnerability management program

  • 5 — Protect all systems and networks from malicious software
  • 6 — Develop and maintain secure systems and software (patching, secure SDLC, web-app protection)

Implement strong access control

  • 7 — Restrict access to system components and cardholder data by business need to know
  • 8 — Identify users and authenticate access (unique IDs, MFA into the CDE)
  • 9 — Restrict physical access to cardholder data

Regularly monitor & test networks

  • 10 — Log and monitor all access (audit logs, time sync, 12-month retention)
  • 11 — Test security of systems and networks regularly (ASV scans, penetration testing)

Maintain an information security policy

  • 12 — Support information security with organizational policies and programs (risk assessment, training, incident response, TPSP management)

Summarised from PCI DSS v4.0 (PCI Security Standards Council) — see pcisecuritystandards.org for the authoritative standard. Not a substitute for a QSA assessment.

PCI DSS checklist FAQ

What are the 12 PCI DSS requirements?
PCI DSS organises its controls into 12 requirements grouped under 6 goals — from installing network security controls and protecting stored account data through access control, logging and monitoring, regular testing, and maintaining a security policy. This checklist lists all 12 (PCI DSS v4.0) with room to record your status and evidence.
Which SAQ do I need?
Your Self-Assessment Questionnaire type depends on how you handle card data — e.g. SAQ A for fully outsourced e-commerce, A-EP for e-commerce that affects the payment page, B/B-IP for terminals, C/C-VT for payment applications or virtual terminals, and D for everyone else (or a Report on Compliance for larger merchants). Scope first; the requirements that apply follow from your SAQ type.
What changed in PCI DSS v4.0?
v4.0 keeps the 12 requirements but adds emphasis on continuous security (not point-in-time), expands MFA to all access into the cardholder data environment, strengthens authentication and password rules, and introduces the customised-approach option alongside the defined approach. Several v4.0 requirements became mandatory after the transition period.
Can CATAAM help with PCI DSS?
CATAAM automates and continuously proves many of the technical requirements — secure configuration, access control and MFA, logging and monitoring, vulnerability management and testing evidence — and maps them to the 12 requirements, so continuous compliance is evidence-backed rather than a once-a-year scramble.

Make PCI DSS continuous, not annual

CATAAM automates the technical requirements — secure config, access & MFA, logging, vulnerability management — and proves them continuously against all 12 requirements.