Onwyn › Standards › PCI DSS v4.0.1
Scheme / framework · 4.0.1PCI DSS v4.0.1
The Payment Card Industry Data Security Standard applies to every organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of a customer's cardholder data environment. Version 4.0.1 organises more than 400 sub-requirements under twelve requirements and six goals. Every control introduced in v4.0 became fully effective on 31 March 2025, including the two that now fail most often — 6.4.3 payment-page script management and 11.6.1 payment-page change detection. Scope is decided by where cardholder data flows and by what can reach the cardholder data environment; getting that boundary right, and shrinking it, is worth more than any individual control. This pack works at requirement and key sub-requirement level. Your validation route — self-assessment questionnaire type or a Report on Compliance by a QSA — depends on your merchant or service provider level and is set by the acquirer or the brands, not by this pack.
What this standard asks for
Every requirement in PCI DSS v4.0.1, grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
Build and maintain a secure network and systems
4 requirements
- 1.2Network security controls are configured and maintained
- 1.3Restrict network access to and from the cardholder data environment
- 2.2System components are configured and managed securely
- 2.3Vendor defaults are removed or changed before installation
Protect account data
3 requirements
- 3.2Storage of account data is kept to a minimum
- 3.5Primary account numbers are rendered unreadable wherever stored
- 4.2Account data is protected with strong cryptography in transit
Maintain a vulnerability management programme
4 requirements
- 5.2Malicious software is prevented, detected and addressed
- 6.3Security vulnerabilities are identified and addressed
- 6.4.3Payment page scripts are managed, justified and integrity-checked
- 6.5Changes to system components are managed securely
Implement strong access control measures
6 requirements
- 7.2Access to system components and data is defined and assigned
- 8.2User identification and account lifecycle are managed
- 8.3Strong authentication is established and managed
- 8.4Multi-factor authentication is implemented for access to the CDE
- 9.4Media with cardholder data is securely stored, transported and destroyed
- 9.5Point-of-interaction devices are protected from tampering
Regularly monitor and test networks
5 requirements
- 10.2Audit logs capture the events needed to detect and reconstruct
- 10.4Audit logs are reviewed to identify anomalies
- 11.3Internal and external vulnerability scans are performed and resolved
- 11.4Penetration testing is performed and exploitable vulnerabilities corrected
- 11.6.1Payment page change and tamper detection is deployed
Maintain an information security policy
2 requirements
- 12.8Third-party service provider risk is managed
- 12.10An incident response plan exists and is tested
Scope, validation and reporting
2 requirements
- SCOPE.1Define and confirm the cardholder data environment
- VAL.1Complete the correct validation and reporting
The documents you will end up with
The recommended document set for PCI DSS v4.0.1 — 12 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The dated definition of the CDE, the data flows behind it, and the annual confirmation that scope is still accurate.
Ruleset governance, segmentation and the justification for every permitted flow into and out of the CDE.
Hardening baselines for every system component type, and the removal of vendor defaults.
What card data is kept, why, for how long, and how it is securely destroyed when the reason ends.
Key generation, distribution, storage, rotation and retirement for keys protecting account data.
Ranking, scanning cadence, patch timeframes and the handling of exceptions.
Secure coding, review, change control and the payment-page script controls introduced in v4.
Least privilege, role definitions, MFA, and the account and credential lifecycle.
Facility access, media storage and destruction, and protection of point-of-interaction devices.
Which events are logged, how logs are protected and retained, and how they are reviewed.
Detection, containment, brand and acquirer notification, and the annual test.
Due diligence, written agreements acknowledging responsibility, and the annual monitoring of provider compliance.
Start PCI DSS v4.0.1 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.