Onwyn › Standards › PCI DSS v4.0.1

Scheme / framework · 4.0.1

PCI DSS v4.0.1

The Payment Card Industry Data Security Standard applies to every organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of a customer's cardholder data environment. Version 4.0.1 organises more than 400 sub-requirements under twelve requirements and six goals. Every control introduced in v4.0 became fully effective on 31 March 2025, including the two that now fail most often — 6.4.3 payment-page script management and 11.6.1 payment-page change detection. Scope is decided by where cardholder data flows and by what can reach the cardholder data environment; getting that boundary right, and shrinking it, is worth more than any individual control. This pack works at requirement and key sub-requirement level. Your validation route — self-assessment questionnaire type or a Report on Compliance by a QSA — depends on your merchant or service provider level and is set by the acquirer or the brands, not by this pack.

26
Requirements
7
Areas
12
Recommended documents
0
Mapped frameworks
Start PCI DSS v4.0.1 free Have us do it instead

What this standard asks for

Every requirement in PCI DSS v4.0.1, grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Build and maintain a secure network and systems

4 requirements

  • 1.2Network security controls are configured and maintained
  • 1.3Restrict network access to and from the cardholder data environment
  • 2.2System components are configured and managed securely
  • 2.3Vendor defaults are removed or changed before installation

Protect account data

3 requirements

  • 3.2Storage of account data is kept to a minimum
  • 3.5Primary account numbers are rendered unreadable wherever stored
  • 4.2Account data is protected with strong cryptography in transit

Maintain a vulnerability management programme

4 requirements

  • 5.2Malicious software is prevented, detected and addressed
  • 6.3Security vulnerabilities are identified and addressed
  • 6.4.3Payment page scripts are managed, justified and integrity-checked
  • 6.5Changes to system components are managed securely

Implement strong access control measures

6 requirements

  • 7.2Access to system components and data is defined and assigned
  • 8.2User identification and account lifecycle are managed
  • 8.3Strong authentication is established and managed
  • 8.4Multi-factor authentication is implemented for access to the CDE
  • 9.4Media with cardholder data is securely stored, transported and destroyed
  • 9.5Point-of-interaction devices are protected from tampering

Regularly monitor and test networks

5 requirements

  • 10.2Audit logs capture the events needed to detect and reconstruct
  • 10.4Audit logs are reviewed to identify anomalies
  • 11.3Internal and external vulnerability scans are performed and resolved
  • 11.4Penetration testing is performed and exploitable vulnerabilities corrected
  • 11.6.1Payment page change and tamper detection is deployed

Maintain an information security policy

2 requirements

  • 12.8Third-party service provider risk is managed
  • 12.10An incident response plan exists and is tested

Scope, validation and reporting

2 requirements

  • SCOPE.1Define and confirm the cardholder data environment
  • VAL.1Complete the correct validation and reporting

The documents you will end up with

The recommended document set for PCI DSS v4.0.1 — 12 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Cardholder Data Environment Scope Document

The dated definition of the CDE, the data flows behind it, and the annual confirmation that scope is still accurate.

Network Security Controls Standard

Ruleset governance, segmentation and the justification for every permitted flow into and out of the CDE.

Secure Configuration Standard

Hardening baselines for every system component type, and the removal of vendor defaults.

Account Data Retention and Disposal Policy

What card data is kept, why, for how long, and how it is securely destroyed when the reason ends.

Cryptographic Key Management Procedure

Key generation, distribution, storage, rotation and retirement for keys protecting account data.

Vulnerability and Patch Management Policy

Ranking, scanning cadence, patch timeframes and the handling of exceptions.

Secure Software Development Policy

Secure coding, review, change control and the payment-page script controls introduced in v4.

Access Control and Authentication Policy

Least privilege, role definitions, MFA, and the account and credential lifecycle.

Physical Security and Media Handling Policy

Facility access, media storage and destruction, and protection of point-of-interaction devices.

Logging and Monitoring Standard

Which events are logged, how logs are protected and retained, and how they are reviewed.

Incident Response Plan

Detection, containment, brand and acquirer notification, and the annual test.

Third-Party Service Provider Management Policy

Due diligence, written agreements acknowledging responsibility, and the annual monitoring of provider compliance.

Start PCI DSS v4.0.1 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.