Back to Frameworks

PCI DSS 4.0

International
12 domains
168 controls

Payment Card Industry Data Security Standard version 4.0, published by PCI Security Standards Council.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Req 10: Logging and Monitoring

27 controls
Controls in the Req 10: Logging and Monitoring domain of PCI DSS 4.027 controls
CodeTitle
10.1.1Policy on the use of cryptographic controls (cloud)
10.1.2Key management (cloud)
10.2.1Audit logs enabled on system components
10.2.1.1Log all user access to CHD
10.2.1.2Log all admin actions
10.2.1.3Log access to audit logs
10.2.1.4Log invalid logical access attempts
10.2.1.5Log changes to identification and authentication
10.2.1.6Log initialization, stopping, or pausing of logs
10.2.1.7Log creation and deletion of system level objects
10.2.2Audit log content
10.3.1Read access to logs restricted
10.3.2Logs protected from modification
10.3.3Logs backed up to central server
10.3.4File integrity or change detection on logs
10.4.1Daily log review for critical systems
10.4.1.1Automated mechanisms for log review
10.4.2Periodic review of other system component logs
10.4.2.1Frequency defined by TRA
10.4.3Exceptions and anomalies addressed
10.5.1Audit log retention 12 months
10.6.1Time synchronization in use
10.6.2Time settings consistent and accurate
10.6.3Time settings protected
10.7.1Critical security control failure detection (SP)
10.7.2Critical security control failure detection (all entities)
10.7.3Failure response timeline

Req 11: Test Security Regularly

21 controls
Controls in the Req 11: Test Security Regularly domain of PCI DSS 4.021 controls
CodeTitle
11.1.1Testing policy documented
11.1.2Testing roles assigned
11.2.1Wireless AP detection
11.2.2Authorized wireless AP inventory
11.3.1Internal vulnerability scans quarterly
11.3.1.1Address non-high vulnerabilities per TRA
11.3.1.2Authenticated internal scans
11.3.1.3Internal scans after significant changes
11.3.2External vulnerability scans quarterly by ASV
11.3.2.1External scans after significant change
11.4.1Penetration testing methodology defined
11.4.2Internal penetration testing annually
11.4.3External penetration testing annually
11.4.4Pen test findings remediated
11.4.5Segmentation testing
11.4.6Segmentation testing (service providers) every 6 months
11.4.7Multi-tenant pen test support
11.5.1IDS/IPS in place
11.5.1.1Covert malware channel detection (SP)
11.5.2Change detection mechanism (FIM)
11.6.1Payment page change and tamper detection

Req 12: Information Security Policies

35 controls
Controls in the Req 12: Information Security Policies domain of PCI DSS 4.035 controls
CodeTitle
12.1.3Capacity management (cloud)
12.1.4CISO or equivalent responsibility
12.10.1Incident response plan
12.10.2IRP reviewed and tested annually
12.10.324/7 incident response coverage
12.10.4Incident responder training
12.10.4.1Periodic IR responder skill review
12.10.5IRP includes monitoring and response to security control alerts
12.10.6IRP refined based on lessons learned
12.10.7Response procedures for PAN detection in unexpected locations
12.2.1Acceptable use policies for end-user technologies
12.3.1Information backup (cloud)
12.3.2TRA for customized approach
12.3.3Cryptographic cipher suites and protocols inventory
12.3.4Hardware and software technologies reviewed annually
12.4.1Event logging (cloud)
12.4.2Quarterly PCI compliance reviews (SP)
12.4.2.1Documentation of quarterly reviews (SP)
12.5.1Inventory of system components in scope
12.5.2PCI DSS scope documented and confirmed annually
12.5.2.1Service provider scope confirmed every 6 months
12.5.3Impact analysis on org structure changes (SP)
12.6.1Management of technical vulnerabilities (cloud)
12.6.2Security awareness program reviewed annually
12.6.3Security awareness training delivered
12.6.3.1Training on phishing and social engineering
12.6.3.2Training on acceptable use of end-user technologies
12.7.1Personnel screening
12.8.1Third-party service provider inventory
12.8.2Written agreements with TPSPs
12.8.3TPSP due diligence
12.8.4TPSP compliance monitored
12.8.5Responsibility matrix with TPSPs
12.9.1TPSP written acknowledgement of responsibility (SP)
12.9.2TPSP supports customer requests for compliance info (SP)

Req 1: Network Security Controls

19 controls
Controls in the Req 1: Network Security Controls domain of PCI DSS 4.019 controls
CodeTitle
1.1.1NSC policies and procedures documented
1.1.2Roles and responsibilities for Requirement 1
1.2.1NSC configuration standards defined
1.2.2Changes to NSC reviewed and approved
1.2.3Network diagrams maintained
1.2.4Data flow diagram of account data
1.2.5Services, protocols, ports inventoried and justified
1.2.6Security features for insecure services defined
1.2.7NSC rule sets reviewed every six months
1.2.8Configuration files secured and synchronised
1.3.1Inbound traffic to CDE restricted
1.3.2Outbound traffic from CDE restricted
1.3.3NSCs between wireless and CDE
1.4.1NSCs between trusted and untrusted networks
1.4.2Inbound traffic from untrusted networks restricted
1.4.3Anti-spoofing measures implemented
1.4.4Account data not stored on internet-accessible systems
1.4.5Internal IP and routing information protected
1.5.1Security controls on dual-connected computing devices

Req 2: Secure Configurations

7 controls
Controls in the Req 2: Secure Configurations domain of PCI DSS 4.07 controls
CodeTitle
2.2.3Primary functions isolated or secured to highest level
2.2.4Only necessary services enabled
2.2.5Insecure services or protocols documented
2.2.6System security parameters configured
2.2.7Non-console administrative access encrypted
2.3.1Wireless vendor defaults changed before installation
2.3.2Wireless encryption keys rotated

Req 3: Protect Stored Account Data

22 controls
Controls in the Req 3: Protect Stored Account Data domain of PCI DSS 4.022 controls
CodeTitle
3.3.1.1Full track data not stored after authorization
3.3.1.2Card verification code not stored after authorization
3.3.1.3PIN and PIN block not stored after authorization
3.3.2SAD stored prior to authorization is encrypted
3.3.3SAD storage by issuers limited
3.4.2Technical controls prevent unauthorized PAN copy
3.5.1PAN rendered unreadable wherever stored
3.5.1.1Hashes of PAN use keyed cryptographic functions
3.5.1.2Disk-level encryption with logical access controls
3.5.1.3Disk-level encryption key management
3.6.1.1Documented description of cryptographic architecture
3.6.1.2Secret and private keys restricted to fewest custodians
3.6.1.3Access to cryptographic keys restricted
3.6.1.4Cryptographic keys stored in fewest possible locations
3.7.2Secure key distribution
3.7.3Secure key storage
3.7.4Cryptoperiod and key changes
3.7.5Retirement or replacement of keys
3.7.6Manual cleartext key operations use split knowledge
3.7.7Prevent unauthorised substitution of keys
3.7.8Custodians acknowledge responsibilities
3.7.9Service provider customer key responsibilities

Req 4: Protect Cardholder Data in Transit

2 controls
Controls in the Req 4: Protect Cardholder Data in Transit domain of PCI DSS 4.02 controls
CodeTitle
4.2.1.1Inventory of trusted keys and certificates
4.2.1.2Wireless networks transmitting PAN use strong cryptography

Req 5: Anti-Malware

4 controls
Controls in the Req 5: Anti-Malware domain of PCI DSS 4.04 controls
CodeTitle
5.2.3.1Frequency of periodic evaluations per targeted risk analysis
5.3.2.1Periodic scan frequency per targeted risk analysis
5.3.4Audit logs for anti-malware enabled
5.3.5Anti-malware cannot be disabled by users

Req 6: Secure Systems and Software

5 controls
Controls in the Req 6: Secure Systems and Software domain of PCI DSS 4.05 controls
CodeTitle
6.2.3Custom software reviewed prior to production
6.2.3.1Code review findings corrected
6.2.4Coding practices prevent common attacks
6.5.5Live PANs not used in pre-production
6.5.6Test data and accounts removed before production

Req 7: Restrict Access by Need to Know

1 controls
Controls in the Req 7: Restrict Access by Need to Know domain of PCI DSS 4.01 controls
CodeTitle
7.2.5.1App and system account review cadence

Req 8: Identify and Authenticate Users

8 controls
Controls in the Req 8: Identify and Authenticate Users domain of PCI DSS 4.08 controls
CodeTitle
8.2.7Third-party access managed
8.2.8Session idle timeout
8.3.10Service provider customer password guidance
8.3.10.1SP password rotation or posture
8.3.11Hardware token and other factor protection
8.3.7Password history
8.3.8Authentication policy communicated
8.3.9Password change frequency if only factor

Req 9: Restrict Physical Access

17 controls
Controls in the Req 9: Restrict Physical Access domain of PCI DSS 4.017 controls
CodeTitle
9.2.3Management of privileged access rights (cloud)
9.2.4Management of secret authentication information (cloud)
9.3.1.1Personnel access readily revoked
9.3.4Visitor log retention
9.4.1Information access restriction (cloud)
9.4.1.1Offline media backup security
9.4.1.2Offsite backup location reviewed
9.4.2Media classified by sensitivity
9.4.3Media sent outside facility secured
9.4.4Use of privileged utility programs (cloud)
9.4.5Inventory logs of electronic media
9.4.6Hard copy media destruction
9.4.7Electronic media destruction
9.5.1POI device protection
9.5.1.1POI inventory maintained
9.5.1.2POI tamper inspection
9.5.1.3POI personnel training

Your Compliance Coverage

If you comply with PCI DSS 4.0, you already cover:

Maps to 5 other frameworks

168 total controls
ISO 27018:2019
8 source controls mapped|8 target controls covered
5%
ISO 27002:2022
3 source controls mapped|3 target controls covered
2%
NIST SP 800-218
3 source controls mapped|7 target controls covered
2%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
1%
ISO 37001:2016
1 source controls mapped|1 target controls covered
1%

Frequently Asked Questions

What is PCI DSS 4.0?

PCI DSS 4.0 is a compliance framework from International with 12 domains and 168 controls. Payment Card Industry Data Security Standard version 4.0, published by PCI Security Standards Council. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does PCI DSS 4.0 have?

PCI DSS 4.0 has 168 controls organised across 12 domains. The largest domains are Req 12: Information Security Policies (35 controls), Req 10: Logging and Monitoring (27 controls), Req 3: Protect Stored Account Data (22 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does PCI DSS 4.0 map to?

PCI DSS 4.0 maps to 5 other compliance frameworks. The top mapping partners are ISO 27018:2019 (5% coverage), ISO 27002:2022 (2% coverage), NIST SP 800-218 (2% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with PCI DSS 4.0 compliance?

Start your PCI DSS 4.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI DSS 4.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 168 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required