PCI DSS

Mandatory · Payments

PCI DSS — card data security scoped down to what you actually need.

PCI DSS v4.0 scoping, SAQ guidance, gap remediation, and ongoing compliance monitoring — engineered for SMB merchants, not card-brand giants.

Overview

Twelve requirements, eight SAQ types, one CDE definition.

PCI DSS applies to every organisation that processes, stores, or transmits cardholder data. Its compliance requirements depend on transaction volume, which determines your merchant level and validation method. PCI DSS v4.0 has been the only valid version since 31 March 2024, replacing v3.2.1.

Before applying any of the 12 requirements, you must define your Cardholder Data Environment (CDE) — the systems, people, processes, and network components that store, process, or transmit cardholder data, or that can affect the security of that data. Network segmentation to isolate the CDE is the single most powerful tool for reducing PCI DSS scope and compliance cost. Proper segmentation can reduce a SAQ D engagement to a SAQ C or even SAQ B-IP.

Merchant levels

Defined by annual transaction volume across all card brands. Most SMBs are Level 3 or Level 4.

  • Level 1 — over 6M transactions

    On-site QSA assessment + quarterly ASV scan. Mandatory for any merchant that has experienced a breach, regardless of volume.

  • Level 2 — 1M to 6M

    Annual SAQ + quarterly ASV scan.

  • Level 3 — 20K to 1M (e-commerce)

    Annual SAQ + quarterly ASV scan.

  • Level 4 — under 20K e-commerce or under 1M total

    Annual SAQ recommended; quarterly scan may be required by the acquirer.

The 12 requirements (v4.0)

What PCI DSS asks of you, in plain language.

  1. 01Req 1

    Network security controls

    Firewalls, routers, documented network connections — including documented diagrams of the CDE and segmentation.

  2. 02Req 2

    Secure configurations

    No vendor defaults, hardening baselines applied to all systems in scope.

  3. 03Req 3

    Protect stored account data

    Minimise storage, strong cryptography for primary account numbers (PANs).

  4. 04Req 4

    Protect data in transit

    Encryption over public networks, certificate management, deprecation of weak protocols.

  5. 05Req 5

    Protect against malicious software

    Anti-malware deployment with phishing awareness controls (new emphasis in v4.0).

  6. 06Req 6

    Develop & maintain secure systems

    Patching cadence, secure development, payment page script management (new in v4.0 — Req 6.4.3).

  7. 07Req 7

    Restrict access to system components

    Need-to-know basis, privileged access management, role-based access controls.

  8. 08Req 8

    Identify users & authenticate access

    Unique user IDs; MFA required for all access into the CDE (new in v4.0); strong password policy.

  9. 09Req 9

    Restrict physical access

    Control to sensitive areas, media protection, visitor management.

  10. 10Req 10

    Log & monitor all access

    Audit all access to system components and cardholder data; protect logs from modification.

  11. 11Req 11

    Test security regularly

    Quarterly vulnerability scans (ASV), annual penetration testing, segmentation testing.

  12. 12Req 12

    Information security policy

    Risk assessments, roles documentation, third-party management, formal awareness program (Req 12.6).

Penalties & consequences

Fines run monthly. Then come the breach costs.

Non-compliance combined with a breach is the worst-case scenario. Your acquiring bank will likely place you in a non-compliance program, triggering monthly fines of €5,000–€100,000 depending on your card brand. Add forensic investigation costs, card replacement for affected cardholders, fraud-loss liability, potential blacklisting from card brand networks, and — if EU residents are affected — GDPR breach notification obligations on top.

Completing the wrong SAQ is itself a compliance failure. We confirm the right SAQ before any work begins, and use proper CDE segmentation to keep your engagement at the simplest applicable level.

  • Monthly fines

    €5K–€100K

    depending on card brand and severity, while in non-compliance.

  • Quarterly ASV scans

    Mandatory

    for Levels 1, 2, 3 — and often required of Level 4 by the acquirer.

  • ISO 27001 overlap

    40–50%

    of PCI DSS satisfied by an existing ISMS — significantly cheaper than starting fresh.

Our approach

Scope down, gap analyse, validate.

What we deliver

  • SAQ confirmation — ensures you complete the correct one for your payment environment
  • CDE scoping and network segmentation strategy — biggest single lever for reducing compliance cost
  • Gap analysis against all 12 requirements (v4.0)
  • Annual SAQ submission support and quarterly ASV vulnerability scan management
  • Annual penetration testing coordination
  • Formal awareness program (Req 12.6) — annual training plus signed acknowledgement of the security policy
  • Existing ISO 27001 leverage — avoid duplication where the ISMS already covers the requirement
  • Ongoing compliance calendar management — never miss a quarterly scan or annual deadline

Typical timeline

Continuous program. Annual validation is the formal milestone; controls run year-round.

  1. Weeks 1–3

    Scope & gap analysis

    CDE definition, segmentation review, SAQ confirmation, gap analysis against the 12 requirements.

  2. Months 2–4

    Remediation

    Close gaps — MFA into the CDE, payment page script management, formal awareness program, log management.

  3. Annually

    Validation cycle

    SAQ submission, annual penetration test, awareness training refresh, policy review.

  4. Quarterly

    ASV scans

    External vulnerability scanning by an Approved Scanning Vendor; remediation of findings before passing scan.

FAQ

Common questions.

Do we still need PCI DSS if we use Stripe / PayPal / Adyen?
Yes — but at a much simpler level. Fully hosted payment pages typically reduce you to SAQ A (22 questions). If your website can be modified to intercept card data (e.g. you load the payment script directly), you may fall into SAQ A-EP (191 questions). The right SAQ depends on the precise integration; getting this wrong is itself a compliance failure.
What happens if we are non-compliant and suffer a breach?
Multi-layered consequences: monthly non-compliance fines from your acquirer (€5K–€100K), forensic investigation costs (PFI engagement), card replacement for affected cardholders, fraud-loss liability, potential blacklisting from card brand networks, and — if EU residents are affected — GDPR breach notification obligations and potential GDPR fines on top.
Does ISO 27001 reduce our PCI DSS work?
Significantly. An organisation with an existing ISO 27001 ISMS typically satisfies 40–50% of PCI DSS requirements through existing security controls and documentation — particularly access control, encryption, vulnerability management, security policy, incident management, and awareness. The additional effort to achieve PCI DSS on top of ISO 27001 is substantially lower than starting from scratch.
Do we need a Qualified Security Assessor (QSA)?
Mandatory only for Level 1 merchants. For Levels 2-4, the SAQ self-assessment is sufficient — but engaging a QSA voluntarily can be valuable for high-complexity environments or when preparing for a possible upgrade to Level 1. We work alongside QSAs where engaged and prepare your documentation to QSA-acceptable standard regardless.
How often does validation happen?
Annual SAQ or RoC submission. Quarterly external vulnerability scans by an Approved Scanning Vendor (ASV). Annual penetration testing minimum. Annual awareness training. In practice, PCI DSS is a continuous program — annual validation is the formal milestone, but the underlying controls must be maintained year-round.
How does network segmentation reduce our compliance scope?
Network segmentation isolates the CDE from the rest of your IT environment. The PCI Security Standards Council does not strictly require it — but organisations that implement proper segmentation reduce their compliance effort and cost dramatically. A correctly segmented environment can move you from SAQ D (329 questions) to SAQ C (160) or even SAQ B-IP (83). Segmentation testing is required to validate the isolation.