PCI DSS 4.0 covers 42.1% of C5 (Germany)
51 of the 121 controls in C5 (Germany) are already satisfied by evidence you collected for PCI DSS 4.0. 70 are genuine gaps. Every claim below was judged against both control sets and then argued against; the ones that did not survive are published further down with the reason each failed.
This number is directional. It says how much of C5 (Germany) your PCI DSS 4.0 evidence satisfies. The reverse pair is a different number, often very different, because a security standard has enormous depth for access control and almost none for lawful basis or data subject rights.
131 candidate mappings were examined and 8 were removed. Signed off 2026-08-19, review level machine verified. Mappings were judged by Claude Code rather than read line by line by a practitioner. Every claim shows its reasoning so you can check it. Ask and a practitioner will review this pair.
Where the gaps are
Coverage is never evenly spread. A source standard usually satisfies one part of a target almost completely and barely touches another, and which part is which is the thing worth knowing before you plan the work.
Theme level, not control level, deliberately. The per-control list of what is evidenced and what is a gap is the report itself, so publishing it here would be publishing the thing being sold.
Claims that held
A sample. Each one names the control whose evidence does the work, the control it satisfies, and why.
A current inventory of all in scope components with their function is the asset record the criterion requires
Destroying electronic media so the data cannot be recovered is the erasure limb of decommissioning
Intrusion detection or prevention monitoring all traffic at the perimeter and critical internal points is the technical safeguard that detects irregular traffic
Network security controls placed between trusted and untrusted networks are the risk based security zones the criterion requires
Restricting inbound traffic from untrusted networks to authorised publicly accessible components is perimeter control of cross network access
An accurate and maintained network diagram of all connections is the traceable network documentation required
The documented and disseminated policies and procedures for protecting data in transmission are exactly the transmission policies required
Documented key management policies and procedures covering generation of strong keys are the issued encryption and key management policy
Claims that did not hold
8 proposed mappings for this pair were rejected. They are kept in the graph rather than deleted, so what was thrown out is as inspectable as what survived. A crosswalk that never rejects anything is not being judged.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. revoking physical access and recovering badges on termination is access withdrawal, not the statement of which obligations survive the engagement and for how long; the access limb belongs to C5-PS-04
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. this criterion is about which information security obligations continue to bind a person after their engagement ends and for how long; revoking logical access on termination is a different requirement, now mapped to C5-IDM-04
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. the title mentions failed logins but the basic criterion covers only dormancy: automatic locking after two months unused, approval to reinstate and revocation after six months; lockout after invalid authentication attempts satisfies none of it
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. the criterion requires the cloud customer to be told about every provider access to their unencrypted data, with cause, time, duration and scope, within 72 hours; restricting who may query stored data is access control and notifies nobody
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. an access control system enforcing need to know does not notify the affected cloud customer of provider access to their unencrypted data, which is the whole of this criterion
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. naming credential changes as a logged event type is log selection; the criterion requires automated analysis, correlation between events and automatic reporting of identified events
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. naming invalid access attempts as a logged event type is log selection; the criterion requires automated analysis, correlation between events and automatic reporting of identified events
Claimed at high confidence before it was rejected.
judged against C5 criterion titles before the framework carried requirement text; does not hold against the real criterion. the title says identification of events but the criterion requires automated analysis and correlation of logging data with automatic reporting to the responsible departments; naming administrative actions as a logged event type is log selection, which belongs to the logging concept
Claimed at high confidence before it was rejected.
The full report
Everything above is a sample. The report is every evidenced control and every gap, with the reasoning and the source document behind each one, in a form you can hand to an assessor. $299, emailed immediately.
Buy this crosswalk