PCI DSS — card data security scoped down to what you actually need.
PCI DSS v4.0 scoping, SAQ guidance, gap remediation, and ongoing compliance monitoring — engineered for SMB merchants, not card-brand giants.
Overview
Twelve requirements, eight SAQ types, one CDE definition.
PCI DSS applies to every organisation that processes, stores, or transmits cardholder data. Its compliance requirements depend on transaction volume, which determines your merchant level and validation method. PCI DSS v4.0 has been the only valid version since 31 March 2024, replacing v3.2.1.
Before applying any of the 12 requirements, you must define your Cardholder Data Environment (CDE) — the systems, people, processes, and network components that store, process, or transmit cardholder data, or that can affect the security of that data. Network segmentation to isolate the CDE is the single most powerful tool for reducing PCI DSS scope and compliance cost. Proper segmentation can reduce a SAQ D engagement to a SAQ C or even SAQ B-IP.
Merchant levels
Defined by annual transaction volume across all card brands. Most SMBs are Level 3 or Level 4.
Level 1 — over 6M transactions
On-site QSA assessment + quarterly ASV scan. Mandatory for any merchant that has experienced a breach, regardless of volume.
Level 2 — 1M to 6M
Annual SAQ + quarterly ASV scan.
Level 3 — 20K to 1M (e-commerce)
Annual SAQ + quarterly ASV scan.
Level 4 — under 20K e-commerce or under 1M total
Annual SAQ recommended; quarterly scan may be required by the acquirer.
The 12 requirements (v4.0)
What PCI DSS asks of you, in plain language.
- 01Req 1
Network security controls
Firewalls, routers, documented network connections — including documented diagrams of the CDE and segmentation.
- 02Req 2
Secure configurations
No vendor defaults, hardening baselines applied to all systems in scope.
- 03Req 3
Protect stored account data
Minimise storage, strong cryptography for primary account numbers (PANs).
- 04Req 4
Protect data in transit
Encryption over public networks, certificate management, deprecation of weak protocols.
- 05Req 5
Protect against malicious software
Anti-malware deployment with phishing awareness controls (new emphasis in v4.0).
- 06Req 6
Develop & maintain secure systems
Patching cadence, secure development, payment page script management (new in v4.0 — Req 6.4.3).
- 07Req 7
Restrict access to system components
Need-to-know basis, privileged access management, role-based access controls.
- 08Req 8
Identify users & authenticate access
Unique user IDs; MFA required for all access into the CDE (new in v4.0); strong password policy.
- 09Req 9
Restrict physical access
Control to sensitive areas, media protection, visitor management.
- 10Req 10
Log & monitor all access
Audit all access to system components and cardholder data; protect logs from modification.
- 11Req 11
Test security regularly
Quarterly vulnerability scans (ASV), annual penetration testing, segmentation testing.
- 12Req 12
Information security policy
Risk assessments, roles documentation, third-party management, formal awareness program (Req 12.6).
Penalties & consequences
Fines run monthly. Then come the breach costs.
Non-compliance combined with a breach is the worst-case scenario. Your acquiring bank will likely place you in a non-compliance program, triggering monthly fines of €5,000–€100,000 depending on your card brand. Add forensic investigation costs, card replacement for affected cardholders, fraud-loss liability, potential blacklisting from card brand networks, and — if EU residents are affected — GDPR breach notification obligations on top.
Completing the wrong SAQ is itself a compliance failure. We confirm the right SAQ before any work begins, and use proper CDE segmentation to keep your engagement at the simplest applicable level.
Monthly fines
€5K–€100K
depending on card brand and severity, while in non-compliance.
Quarterly ASV scans
Mandatory
for Levels 1, 2, 3 — and often required of Level 4 by the acquirer.
ISO 27001 overlap
40–50%
of PCI DSS satisfied by an existing ISMS — significantly cheaper than starting fresh.
Our approach
Scope down, gap analyse, validate.
What we deliver
- SAQ confirmation — ensures you complete the correct one for your payment environment
- CDE scoping and network segmentation strategy — biggest single lever for reducing compliance cost
- Gap analysis against all 12 requirements (v4.0)
- Annual SAQ submission support and quarterly ASV vulnerability scan management
- Annual penetration testing coordination
- Formal awareness program (Req 12.6) — annual training plus signed acknowledgement of the security policy
- Existing ISO 27001 leverage — avoid duplication where the ISMS already covers the requirement
- Ongoing compliance calendar management — never miss a quarterly scan or annual deadline
Typical timeline
Continuous program. Annual validation is the formal milestone; controls run year-round.
Weeks 1–3
Scope & gap analysis
CDE definition, segmentation review, SAQ confirmation, gap analysis against the 12 requirements.
Months 2–4
Remediation
Close gaps — MFA into the CDE, payment page script management, formal awareness program, log management.
Annually
Validation cycle
SAQ submission, annual penetration test, awareness training refresh, policy review.
Quarterly
ASV scans
External vulnerability scanning by an Approved Scanning Vendor; remediation of findings before passing scan.
FAQ