Back to Frameworks

PCI DSS 4.0

International (payment card industry; enforced contractually by payment brands and acquirers)
v4.0.1 (June 2024), current; the graph name keeps 4.0: v4.0 (March 2022) was retired on 31 December 2024 and v4.0.1 is a limited revision with the same requirement numbering
16 domains
280 controls

PCI DSS, the PCI Security Standards Council's minimum set of technical and operational controls for every entity that stores, processes or transmits payment card account data or can affect its security, in twelve principal requirements (network security controls, secure configuration, stored account data, transmission encryption, anti-malware, secure software, need-to-know access, identification and authentication, physical security, logging and monitoring, security testing, policy and programs) plus Appendix A for multi-tenant providers, SSL/early TLS POS terminals and designated entities. Read against v4.0.1 (June 2024), the current edition: 280 requirements.

Verified

PCI DSS 4.0 is a compliance framework from International (payment card industry; enforced contractually by payment brands and acquirers) with 16 domains and 280 controls that map to 198 other frameworks. The largest domains are Req 12: Information Security Policies (37 controls), Req 3: Protect Stored Account Data (29 controls), Req 8: Identify and Authenticate Users (29 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (16)

Appendix A1: Additional requirements for multi-tenant service providers – PCI DSS 4.0

7 controls
Controls in the Appendix A1: Additional requirements for multi-tenant service providers – PCI DSS 4.0 domain of PCI DSS 4.0 — 7 controls
CodeTitle
pci-dss-4-0::A1.1.1A1.1.1 Logical separation between provider and customer environments
pci-dss-4-0::A1.1.2A1.1.2 Customers limited to their own cardholder data and CDE
pci-dss-4-0::A1.1.3A1.1.3 Customers restricted to their allocated resources
pci-dss-4-0::A1.1.4A1.1.4 Penetration testing of tenant separation every six months
pci-dss-4-0::A1.2.1A1.2.1 Per-customer audit logging consistent with Requirement 10
pci-dss-4-0::A1.2.2A1.2.2 Support for prompt forensic investigation of any customer
pci-dss-4-0::A1.2.3A1.2.3 Customer reporting and remediation of incidents and vulnerabilities

Appendix A2: Entities using SSL/early TLS for card-present POS POI terminal connections – PCI DSS 4.0

3 controls
Controls in the Appendix A2: Entities using SSL/early TLS for card-present POS POI terminal connections – PCI DSS 4.0 domain of PCI DSS 4.0 — 3 controls
CodeTitle
pci-dss-4-0::A2.1.1A2.1.1 Confirm SSL/early TLS POS POI devices resist known exploits
pci-dss-4-0::A2.1.2A2.1.2 Risk Mitigation and Migration Plan for SSL/early TLS connections
pci-dss-4-0::A2.1.3A2.1.3 Service providers offer a secure protocol option

Appendix A3: Designated Entities Supplemental Validation (DESV) – PCI DSS 4.0

20 controls
Controls in the Appendix A3: Designated Entities Supplemental Validation (DESV) – PCI DSS 4.0 domain of PCI DSS 4.0 — 20 controls
CodeTitle
pci-dss-4-0::A3.1.1A3.1.1 Executive management responsibility for the PCI DSS compliance program
pci-dss-4-0::A3.1.2A3.1.2 Formal PCI DSS compliance program elements
pci-dss-4-0::A3.1.3A3.1.3 Defined and assigned PCI DSS compliance roles
pci-dss-4-0::A3.1.4A3.1.4 Annual PCI DSS training for compliance personnel
pci-dss-4-0::A3.2.1A3.2.1 Quarterly and change-driven scope documentation and validation
pci-dss-4-0::A3.2.2A3.2.2 Scope impact of every system or network change
pci-dss-4-0::A3.2.2.1A3.2.2.1 Post-change confirmation that PCI DSS controls are in place
pci-dss-4-0::A3.2.3A3.2.3 Scope review after organizational structure changes
pci-dss-4-0::A3.2.4A3.2.4 Six-monthly penetration testing of segmentation controls
pci-dss-4-0::A3.2.5A3.2.5 Data-discovery methodology for cleartext PAN
pci-dss-4-0::A3.2.5.1A3.2.5.1 Annual confirmation of data-discovery effectiveness
pci-dss-4-0::A3.2.5.2A3.2.5.2 Response procedures when cleartext PAN is found outside the CDE
pci-dss-4-0::A3.2.6A3.2.6 Mechanisms to detect and block cleartext PAN leaving the CDE
pci-dss-4-0::A3.2.6.1A3.2.6.1 Response procedures for attempted removal of cleartext PAN
pci-dss-4-0::A3.3.1A3.3.1 Prompt detection and alerting of critical security control failures
pci-dss-4-0::A3.3.1.1A3.3.1.1 Prompt response to critical security control failures
pci-dss-4-0::A3.3.2A3.3.2 Annual review of hardware and software technologies
pci-dss-4-0::A3.3.3A3.3.3 Quarterly review that BAU activities are followed
pci-dss-4-0::A3.4.1A3.4.1 Six-monthly review of user accounts and access privileges
pci-dss-4-0::A3.5.1A3.5.1 Methodology for prompt detection of attack patterns

Req 10: Logging and Monitoring

27 controls
Controls in the Req 10: Logging and Monitoring domain of PCI DSS 4.0 — 27 controls
CodeTitle
10.1.110.1.1 Requirement 10 policies and procedures maintained and in use
10.1.210.1.2 Roles for logging and monitoring assigned and understood
10.2.110.2.1 Audit logging enabled on all system components
10.2.1.110.2.1.1 Logs capture individual user access to cardholder data
10.2.1.210.2.1.2 Logs capture all administrative actions
10.2.1.310.2.1.3 Access to the audit logs is itself logged
10.2.1.410.2.1.4 Logs capture invalid logical access attempts
10.2.1.510.2.1.5 Logs capture changes to identification and authentication credentials
10.2.1.610.2.1.6 Logs capture initialization and stopping of audit logs
10.2.1.710.2.1.7 Logs capture creation and deletion of system-level objects
10.2.210.2.2 Required details recorded for each auditable event
10.3.110.3.1 Audit log read access limited to job need
10.3.210.3.2 Audit log files protected from modification
10.3.310.3.3 Audit logs promptly backed up to central secure storage
10.3.410.3.4 File integrity monitoring on audit logs
10.4.110.4.1 Daily review of security-relevant logs
10.4.1.110.4.1.1 Automated mechanisms used for audit log review
10.4.210.4.2 Periodic review of all other system component logs
10.4.2.110.4.2.1 Periodic log review frequency set by targeted risk analysis
10.4.310.4.3 Exceptions and anomalies from log review addressed
10.5.110.5.1 Keep logs 12 months, latest three months online
10.6.110.6.1 System clocks synchronized with time-sync technology
10.6.210.6.2 Systems configured to correct and consistent time
10.6.310.6.3 Time sync configuration and time data protected
10.7.110.7.1 Service providers detect critical control failures (superseded)
10.7.210.7.2 Detect and alert on critical security control failures
10.7.310.7.3 Respond promptly to critical security control failures

Req 11: Test Security Regularly

21 controls
Controls in the Req 11: Test Security Regularly domain of PCI DSS 4.0 — 21 controls
CodeTitle
11.1.111.1.1 Requirement 11 policies and procedures managed
11.1.211.1.2 Roles for security testing assigned and understood
11.2.111.2.1 Detect authorized and rogue wireless access points
11.2.211.2.2 Inventory of authorized wireless access points
11.3.111.3.1 Quarterly internal vulnerability scans
11.3.1.111.3.1.1 Lower-risk vulnerabilities handled per risk analysis
11.3.1.211.3.1.2 Authenticated internal vulnerability scanning
11.3.1.311.3.1.3 Internal scans after significant change
11.3.211.3.2 Quarterly ASV external vulnerability scans
11.3.2.111.3.2.1 External scans after significant change
11.4.111.4.1 Penetration testing methodology defined and implemented
11.4.211.4.2 Internal penetration testing annually and after change
11.4.311.4.3 External penetration testing annually and after change
11.4.411.4.4 Correct exploitable findings from penetration tests
11.4.511.4.5 Annual segmentation penetration testing
11.4.611.4.6 Service provider segmentation testing every six months
11.4.711.4.7 Multi-tenant providers support customer penetration testing
11.5.111.5.1 IDS/IPS monitoring of CDE traffic
11.5.1.111.5.1.1 Service providers detect covert malware channels
11.5.211.5.2 Change detection on critical files
11.6.111.6.1 Payment page tamper detection

Req 12: Information Security Policies

37 controls
Controls in the Req 12: Information Security Policies domain of PCI DSS 4.0 — 37 controls
CodeTitle
12.1.112.1.1 Overall information security policy established and disseminated
12.1.212.1.2 Security policy reviewed annually and updated as needed
12.1.312.1.3 Security roles defined and acknowledged by all personnel
12.1.412.1.4 Executive ownership of information security formally assigned
12.10.112.10.1 Incident response plan ready for activation
12.10.212.10.2 Annual review and testing of the incident response plan
12.10.312.10.3 Incident response personnel available 24/7
12.10.412.10.4 Periodic training for incident response personnel
12.10.4.112.10.4.1 Responder training frequency set by targeted risk analysis
12.10.512.10.5 Plan covers alerts from security monitoring systems
12.10.612.10.6 Plan evolved from lessons learned and industry developments
12.10.712.10.7 Response procedures for PAN found in unexpected locations
12.2.112.2.1 Rules for acceptable use of end-user technology
12.3.112.3.1 Targeted risk analysis for flexible-frequency requirements
12.3.212.3.2 Targeted risk analysis for each customized-approach requirement
12.3.312.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
12.3.412.3.4 Annual review of hardware and software technologies
12.4.112.4.1 Executive responsibility for a PCI DSS compliance program
12.4.212.4.2 Quarterly reviews that personnel follow security procedures
12.4.2.112.4.2.1 Documentation of quarterly operational reviews
12.5.112.5.1 Inventory of in-scope system components
12.5.212.5.2 Annual and change-driven scope confirmation
12.5.2.112.5.2.1 Six-monthly scope confirmation for service providers
12.5.312.5.3 Scope review after significant organisational change
12.6.112.6.1 Formal security awareness program
12.6.212.6.2 Awareness program reviewed annually and updated
12.6.312.6.3 Security awareness training on hire and annually with acknowledgment
12.6.3.112.6.3.1 Awareness training covers phishing and social engineering
12.6.3.212.6.3.2 Awareness training covers acceptable use of end-user technologies
12.7.112.7.1 Pre-hire screening of personnel with CDE access
12.8.112.8.1 List of third-party service providers
12.8.212.8.2 TPSP contracts acknowledging account data responsibility
12.8.312.8.3 Due diligence before engaging TPSPs
12.8.412.8.4 Annual monitoring of TPSP compliance status
12.8.512.8.5 Responsibility allocation between entity and TPSPs
12.9.112.9.1 TPSP written acknowledgments to customers
12.9.212.9.2 TPSP support for customer information requests

Req 1: Network Security Controls

19 controls
Controls in the Req 1: Network Security Controls domain of PCI DSS 4.0 — 19 controls
CodeTitle
1.1.11.1.1 Requirement 1 policies and procedures governed
1.1.21.1.2 Requirement 1 roles and responsibilities assigned
1.2.11.2.1 Ruleset configuration standards for NSCs
1.2.21.2.2 Network connection and NSC changes under change control
1.2.31.2.3 Accurate network diagram of CDE connections
1.2.41.2.4 Accurate data-flow diagram for account data
1.2.51.2.5 Allowed services, protocols and ports justified
1.2.61.2.6 Security features for insecure services in use
1.2.71.2.7 Six-monthly review of NSC configurations
1.2.81.2.8 NSC configuration files secured and consistent
1.3.11.3.1 Inbound CDE traffic restricted
1.3.21.3.2 Outbound CDE traffic restricted
1.3.31.3.3 NSCs between wireless networks and the CDE
1.4.11.4.1 NSCs between trusted and untrusted networks
1.4.21.4.2 Restricting traffic entering trusted networks from outside
1.4.31.4.3 Anti-spoofing measures at trusted boundary
1.4.41.4.4 Cardholder data stores not reachable from untrusted networks
1.4.51.4.5 Internal IP and routing disclosure limited
1.5.11.5.1 Security controls on dual-connected devices

Req 2: Secure Configurations

11 controls
Controls in the Req 2: Secure Configurations domain of PCI DSS 4.0 — 11 controls
CodeTitle
2.1.12.1.1 Requirement 2 policies and procedures governed
2.1.22.1.2 Requirement 2 roles and responsibilities assigned
2.2.12.2.1 System configuration standards maintained
2.2.22.2.2 Vendor default accounts managed
2.2.32.2.3 Primary functions with different security levels managed
2.2.42.2.4 Only necessary functionality enabled
2.2.52.2.5 Insecure services, protocols or daemons secured
2.2.62.2.6 System security parameters configured against misuse
2.2.72.2.7 Non-console administrative access encrypted
2.3.12.3.1 Wireless vendor defaults changed or confirmed secure
2.3.22.3.2 Wireless encryption keys changed on triggers

Req 3: Protect Stored Account Data

29 controls
Controls in the Req 3: Protect Stored Account Data domain of PCI DSS 4.0 — 29 controls
CodeTitle
3.3.1.13.3.1.1 Full track data not retained after authorization
3.3.1.23.3.1.2 Card verification code not retained after authorization
3.3.1.33.3.1.3 PIN and PIN block not retained after authorization
3.3.23.3.2 Pre-authorization SAD stored electronically is strongly encrypted
3.3.33.3.3 Issuer SAD storage limited, justified and encrypted
3.4.23.4.2 Remote access blocks copying or relocating PAN
3.5.13.5.1 Stored PAN rendered unreadable
3.5.1.13.5.1.1 PAN hashes are keyed cryptographic hashes
3.5.1.23.5.1.2 Disk or partition encryption only on removable media
3.5.1.33.5.1.3 Disk encryption access independent of OS authentication
3.6.1.13.6.1.1 Service provider cryptographic architecture documented
3.6.1.23.6.1.2 Permitted storage forms for secret and private keys
3.6.1.33.6.1.3 Cleartext key component access limited to minimum custodians
3.6.1.43.6.1.4 Cryptographic keys kept in fewest locations
3.7.23.7.2 Secure distribution of cryptographic keys
3.7.33.7.3 Secure storage of cryptographic keys
3.7.43.7.4 Key changes at end of cryptoperiod
3.7.53.7.5 Retirement, replacement or destruction of keys
3.7.63.7.6 Split knowledge and dual control for manual key operations
3.7.73.7.7 Prevent unauthorized substitution of keys
3.7.83.7.8 Key custodians formally acknowledge responsibilities
3.7.93.7.9 Key guidance for service provider customers
pci-dss-4-0::3.1.13.1.1 Requirement 3 policies and procedures maintained and in use
pci-dss-4-0::3.1.23.1.2 Assigned duties for Requirement 3 activities
pci-dss-4-0::3.2.13.2.1 Data retention and disposal minimise stored account data
pci-dss-4-0::3.3.13.3.1 SAD not retained after authorization, even encrypted
pci-dss-4-0::3.4.13.4.1 PAN masked on display except for authorized roles
pci-dss-4-0::3.6.13.6.1 Procedures protect keys against disclosure and misuse
pci-dss-4-0::3.7.13.7.1 Generation of strong cryptographic keys

Req 4: Protect Cardholder Data in Transit

6 controls
Controls in the Req 4: Protect Cardholder Data in Transit domain of PCI DSS 4.0 — 6 controls
CodeTitle
4.1.14.1.1 Requirement 4 policies and procedures maintained and communicated
4.1.24.1.2 Requirement 4 roles and responsibilities assigned
4.2.14.2.1 Strong cryptography safeguards PAN over public networks
4.2.1.14.2.1.1 Inventory of trusted transmission keys and certificates
4.2.1.24.2.1.2 Wireless networks use strong cryptography
4.2.24.2.2 PAN secured when sent by end-user messaging

Req 5: Anti-Malware

13 controls
Controls in the Req 5: Anti-Malware domain of PCI DSS 4.0 — 13 controls
CodeTitle
5.1.15.1.1 Requirement 5 policies and procedures maintained and communicated
5.1.25.1.2 Requirement 5 roles and responsibilities assigned
5.2.3.15.2.3.1 Targeted risk analysis sets evaluation frequency
5.3.2.15.3.2.1 Targeted risk analysis sets malware scan frequency
5.3.45.3.4 Anti-malware audit logs enabled and retained
5.3.55.3.5 Users cannot disable or alter anti-malware
5.4.15.4.1 Mechanisms detect and protect against phishing
pci-dss-4-0::5.2.15.2.1 Anti-malware deployed on all system components
pci-dss-4-0::5.2.25.2.2 Anti-malware detects and handles all known malware
pci-dss-4-0::5.2.35.2.3 Periodic evaluation of components not at risk from malware
pci-dss-4-0::5.3.15.3.1 Anti-malware kept current through automatic updates
pci-dss-4-0::5.3.25.3.2 Periodic and real-time scans or continuous behavioural analysis
pci-dss-4-0::5.3.35.3.3 Anti-malware covers removable electronic media

Req 6: Secure Systems and Software

19 controls
Controls in the Req 6: Secure Systems and Software domain of PCI DSS 4.0 — 19 controls
CodeTitle
6.1.16.1.1 Requirement 6 policies and procedures maintained and communicated
6.1.26.1.2 Requirement 6 roles and responsibilities assigned
6.2.16.2.1 Secure development of bespoke and custom software
6.2.26.2.2 Annual secure software training for developers
6.2.36.2.3 Code review before release
6.2.3.16.2.3.1 Manual code review independence and approval
6.2.46.2.4 Engineering techniques against common software attacks
6.4.16.4.1 Public web application review or automated protection
6.4.26.4.2 Automated web attack detection and prevention
6.5.56.5.5 No live PANs in pre-production
6.5.66.5.6 Remove test data and accounts before production
pci-dss-4-0::6.3.16.3.1 Vulnerability identification and risk ranking
pci-dss-4-0::6.3.26.3.2 Inventory of bespoke software and components
pci-dss-4-0::6.3.36.3.3 Timely installation of security patches
pci-dss-4-0::6.4.36.4.3 Payment page script management
pci-dss-4-0::6.5.16.5.1 Change control procedure for production
pci-dss-4-0::6.5.26.5.2 Confirm PCI DSS controls after significant change
pci-dss-4-0::6.5.36.5.3 Separate pre-production from production
pci-dss-4-0::6.5.46.5.4 Separate roles between production and pre-production

Req 7: Restrict Access by Need to Know

12 controls
Controls in the Req 7: Restrict Access by Need to Know domain of PCI DSS 4.0 — 12 controls
CodeTitle
7.1.17.1.1 Requirement 7 policies and procedures maintained
7.1.27.1.2 Requirement 7 roles and responsibilities assigned
7.2.17.2.1 Access control model defined
7.2.27.2.2 User access assigned by job function and least privilege
7.2.37.2.3 Privileges approved by authorized personnel
7.2.5.17.2.5.1 Application and system account access reviewed periodically
7.3.27.3.2 Access control system enforces role-based permissions
7.3.37.3.3 Access control default deny all
pci-dss-4-0::7.2.47.2.4 User accounts and privileges reviewed every six months
pci-dss-4-0::7.2.57.2.5 Application and system accounts least privilege
pci-dss-4-0::7.2.67.2.6 Query access to stored cardholder data restricted
pci-dss-4-0::7.3.17.3.1 Need-to-know access control system covers all components

Req 8: Identify and Authenticate Users

29 controls
Controls in the Req 8: Identify and Authenticate Users domain of PCI DSS 4.0 — 29 controls
CodeTitle
8.2.18.2.1 Unique ID assigned to every user
8.2.28.2.2 Shared and generic IDs only by exception
8.2.38.2.3 Service provider unique factors per customer
8.2.48.2.4 User ID lifecycle changes authorized
8.2.58.2.5 Terminated users' access revoked immediately
8.2.68.2.6 Inactive accounts removed within 90 days
8.2.78.2.7 Third-party remote access accounts controlled
8.2.88.2.8 Re-authentication after 15 minutes idle
8.3.18.3.1 Access authenticated with at least one factor
8.3.108.3.10 Service provider customer password guidance
8.3.10.18.3.10.1 Service provider customer passwords 90 days or dynamic
8.3.118.3.11 Tokens, smart cards and certificates individually assigned
8.3.28.3.2 Authentication factors unreadable with strong cryptography
8.3.38.3.3 Identity verified before factor changes
8.3.48.3.4 Lockout after 10 attempts for 30 minutes
8.3.58.3.5 Initial and reset passwords unique and changed
8.3.68.3.6 Password minimum length 12 and complexity
8.3.78.3.7 No reuse of last four passwords
8.3.88.3.8 Authentication policies communicated to users
8.3.98.3.9 Single-factor passwords changed every 90 days or dynamic analysis
8.4.18.4.1 MFA for non-console administrative CDE access
8.4.28.4.2 MFA for all non-console CDE access
8.4.38.4.3 MFA for remote access that could reach CDE
8.5.18.5.1 MFA system resistant to replay and bypass
pci-dss-4-0::8.1.18.1.1 Requirement 8 policies and procedures maintained
pci-dss-4-0::8.1.28.1.2 Requirement 8 roles and responsibilities assigned
pci-dss-4-0::8.6.18.6.1 Interactive use of system accounts controlled
pci-dss-4-0::8.6.28.6.2 No hard-coded passwords for interactive system accounts
pci-dss-4-0::8.6.38.6.3 System account passwords protected against misuse

Req 9: Restrict Physical Access

26 controls
Controls in the Req 9: Restrict Physical Access domain of PCI DSS 4.0 — 26 controls
CodeTitle
9.1.19.1.1 Requirement 9 policies and procedures maintained
9.1.29.1.2 Requirement 9 roles and responsibilities assigned
9.2.19.2.1 Facility entry controls for CDE systems
9.2.1.19.2.1.1 Monitoring of entry to sensitive areas
9.2.29.2.2 Controls on publicly accessible network jacks
9.2.39.2.3 Physical protection of network hardware and lines
9.2.49.2.4 Locking of consoles in sensitive areas
9.3.19.3.1 Personnel physical access procedures for the CDE
9.3.1.19.3.1.1 Personnel access to sensitive areas controlled
9.3.29.3.2 Visitor access procedures for the CDE
9.3.39.3.3 Visitor badges returned or deactivated
9.3.49.3.4 Visitor logs for facility and sensitive areas
9.4.19.4.1 Physical security of all media
9.4.1.19.4.1.1 Secure storage location for offline backups
9.4.1.29.4.1.2 Annual review of offline backup location security
9.4.29.4.2 Classification of media by data sensitivity
9.4.39.4.3 Securing media sent outside the facility
9.4.49.4.4 Management approval for media leaving facility
9.4.59.4.5 Inventory logs of electronic media
9.4.5.19.4.5.1 Annual inventories of electronic media
9.4.69.4.6 Destruction of hard-copy materials
9.4.79.4.7 Destruction of electronic media
9.5.19.5.1 Protection of POI devices from tampering
9.5.1.19.5.1.1 Current register of POI devices
9.5.1.29.5.1.2 Periodic inspection of POI device surfaces
9.5.1.39.5.1.3 Training for personnel in POI environments

Req 9: Restrict Physical Access – PCI DSS 4.0

1 controls
Controls in the Req 9: Restrict Physical Access – PCI DSS 4.0 domain of PCI DSS 4.0 — 1 controls
CodeTitle
pci-dss-4-0::9.5.1.2.19.5.1.2.1 Risk-based frequency and type of POI inspections

Your Compliance Coverage

If you comply with PCI DSS 4.0, you already cover:

Maps to 198 other frameworks

280 total controls
SOC 2
247 source controls mapped|48 target controls covered
88%
ISO 27002:2022
247 source controls mapped|85 target controls covered
88%
NIST SP 800-53 Rev 5
246 source controls mapped|205 target controls covered
88%
ISO 27001:2022
246 source controls mapped|88 target controls covered
88%
FedRAMP Moderate
245 source controls mapped|265 target controls covered
88%
FedRAMP High
245 source controls mapped|266 target controls covered
88%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
240 source controls mapped|162 target controls covered
86%
NIST Cybersecurity Framework 2.0
215 source controls mapped|87 target controls covered
77%
NIST SP 800-171 Rev 3
211 source controls mapped|87 target controls covered
75%
ISO 27701:2019
206 source controls mapped|71 target controls covered
74%
CMMC 2.0
199 source controls mapped|102 target controls covered
71%
CIS Controls v8
190 source controls mapped|141 target controls covered
68%
C5 (Germany)
168 source controls mapped|94 target controls covered
60%
HIPAA Security Rule
153 source controls mapped|59 target controls covered
55%
NIST SP 800-66 Rev 2
152 source controls mapped|50 target controls covered
54%
Azure Security Benchmark
141 source controls mapped|68 target controls covered
50%
AWS Well-Architected Security Pillar
116 source controls mapped|59 target controls covered
41%
PCI 3DS Core Security Standard
103 source controls mapped|117 target controls covered
37%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
97 source controls mapped|41 target controls covered
35%
NIST SP 800-161 Rev 1
82 source controls mapped|70 target controls covered
29%
NIST SP 800-172
79 source controls mapped|33 target controls covered
28%
ISO 22301:2019
65 source controls mapped|44 target controls covered
23%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
60 source controls mapped|26 target controls covered
21%
ASD Strategies to Mitigate Cyber Security Incidents
57 source controls mapped|34 target controls covered
20%
NIS2 Directive
48 source controls mapped|17 target controls covered
17%
UK Cyber Essentials
44 source controls mapped|28 target controls covered
16%
APRA CPS 234
38 source controls mapped|23 target controls covered
14%
ACSC Essential Eight
37 source controls mapped|18 target controls covered
13%
Australia Consumer Data Right - Banking (CDR)
34 source controls mapped|12 target controls covered
12%
NIST SP 800-218
26 source controls mapped|24 target controls covered
9%
APPI
13 source controls mapped|5 target controls covered
5%
Authorised Economic Operator (AEO) Programmes - Global Standards
9 source controls mapped|6 target controls covered
3%
ISO 27018:2019
8 source controls mapped|8 target controls covered
3%
ISO/IEC 42001:2023
7 source controls mapped|6 target controls covered
3%
NIST SP 800-181
6 source controls mapped|7 target controls covered
2%
NIST SP 800-53A Rev. 5
5 source controls mapped|4 target controls covered
2%
PTES
3 source controls mapped|5 target controls covered
1%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
3 source controls mapped|5 target controls covered
1%
ICH E6(R3) - Good Clinical Practice
3 source controls mapped|2 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
3 source controls mapped|3 target controls covered
1%
1%
IEC 62304:2015 Medical Device Software Lifecycle Processes
3 source controls mapped|4 target controls covered
1%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
3 source controls mapped|3 target controls covered
1%
ISO/IEC 25012:2008 - Data Quality Model
3 source controls mapped|3 target controls covered
1%
FSSC 22000 - Food Safety System Certification
2 source controls mapped|1 target controls covered
1%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
2 source controls mapped|2 target controls covered
1%
GS1 Global Standards - Supply Chain Traceability and Data Security
2 source controls mapped|2 target controls covered
1%
SWIFT CSCF
2 source controls mapped|3 target controls covered
1%
SQF Code Edition 9 - Safe Quality Food
2 source controls mapped|1 target controls covered
1%
21 CFR Part 211 - Current Good Manufacturing Practice
2 source controls mapped|3 target controls covered
1%
21 CFR Part 58 - Good Laboratory Practice (GLP)
2 source controls mapped|1 target controls covered
1%
Singapore AI Governance Framework
2 source controls mapped|1 target controls covered
1%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
0%
WCAG 2.2
1 source controls mapped|1 target controls covered
0%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
0%
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
1 source controls mapped|1 target controls covered
0%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
0%
UK Gambling Commission LCCP and Remote Technical Standards
1 source controls mapped|2 target controls covered
0%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
0%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
0%
UK Bribery Act 2010
1 source controls mapped|3 target controls covered
0%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|3 target controls covered
0%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
0%
Tanzania Personal Data Protection Act 2022
1 source controls mapped|2 target controls covered
0%
SLSA
1 source controls mapped|1 target controls covered
0%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
0%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
0%
Protective Security Policy Framework (PSPF) Release 2026
1 source controls mapped|1 target controls covered
0%
PSD2 SCA
1 source controls mapped|1 target controls covered
0%
Philippines Cybercrime Prevention Act (RA 10175)
1 source controls mapped|1 target controls covered
0%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
0%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|2 target controls covered
0%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
0%
OWASP SAMM
1 source controls mapped|1 target controls covered
0%
OWASP MASVS
1 source controls mapped|1 target controls covered
0%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|2 target controls covered
0%
OWASP ASVS
1 source controls mapped|1 target controls covered
0%
OSFI B-13
1 source controls mapped|1 target controls covered
0%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
0%
Open Banking Security
1 source controls mapped|1 target controls covered
0%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|1 target controls covered
0%
O-RAN WG11 Security Specification
1 source controls mapped|3 target controls covered
0%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
1 source controls mapped|5 target controls covered
0%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
0%
NIST SP 800-92
1 source controls mapped|1 target controls covered
0%
NIST SP 800-88
1 source controls mapped|1 target controls covered
0%
0%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
0%
NIST SP 800-61 Rev. 3
1 source controls mapped|1 target controls covered
0%
NIST SP 800-146
1 source controls mapped|1 target controls covered
0%
NIST SP 800-145
1 source controls mapped|1 target controls covered
0%
NIST SP 800-144
1 source controls mapped|1 target controls covered
0%
NIST SP 800-137
1 source controls mapped|1 target controls covered
0%
NIST SP 800-123
1 source controls mapped|1 target controls covered
0%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
0%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|3 target controls covered
0%
Nebraska Data Privacy Act
1 source controls mapped|3 target controls covered
0%
MTCS (Singapore)
1 source controls mapped|2 target controls covered
0%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
0%
MITRE D3FEND
1 source controls mapped|1 target controls covered
0%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
0%
South Korea PIPA
1 source controls mapped|1 target controls covered
0%
ITU Radio Regulations and Space Security Standards
1 source controls mapped|1 target controls covered
0%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
0%
Israel Protection of Privacy Law (5741-1981)
1 source controls mapped|2 target controls covered
0%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
0%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
0%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
1 source controls mapped|1 target controls covered
0%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|2 target controls covered
0%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
0%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|2 target controls covered
0%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
0%
HKMA SPM
1 source controls mapped|1 target controls covered
0%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
0%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
0%
GLBA
1 source controls mapped|1 target controls covered
0%
GAMP 5 - Good Automated Manufacturing Practice
1 source controls mapped|2 target controls covered
0%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
0%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
0%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
0%
FedRAMP Rev 5
1 source controls mapped|4 target controls covered
0%
FATF Recommendation 16 - Payment Transparency (Travel Rule)
1 source controls mapped|1 target controls covered
0%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
0%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|2 target controls covered
0%
ISO 22320:2018
1 source controls mapped|3 target controls covered
0%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
0%
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
1 source controls mapped|1 target controls covered
0%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|3 target controls covered
0%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
0%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
0%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
0%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|3 target controls covered
0%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
0%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
0%
Kuwait National Cybersecurity Framework
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|3 target controls covered
0%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
0%
ISO/IEC 23837:2023
1 source controls mapped|1 target controls covered
0%
WHO Global Strategy on Digital Health 2020-2025
1 source controls mapped|1 target controls covered
0%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
0%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
0%
SANS Incident Handler's Handbook and PICERL Methodology
1 source controls mapped|2 target controls covered
0%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
0%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|2 target controls covered
0%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27050-1:2019
1 source controls mapped|1 target controls covered
0%
NIST SP 800-190
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27043:2015
1 source controls mapped|1 target controls covered
0%
South Korea ISMS-P
1 source controls mapped|1 target controls covered
0%
COBIT 2019
1 source controls mapped|1 target controls covered
0%
US SEC Digital Assets and Crypto Regulatory Framework
1 source controls mapped|2 target controls covered
0%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
0%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
0%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
0%
PCI SSF
1 source controls mapped|1 target controls covered
0%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
0%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
0%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|2 target controls covered
0%
ISO 56002
1 source controls mapped|2 target controls covered
0%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|2 target controls covered
0%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
0%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|1 target controls covered
0%
PCI P2PE
1 source controls mapped|1 target controls covered
0%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
0%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
0%
Albania Law No. 124/2024 on Personal Data Protection
1 source controls mapped|2 target controls covered
0%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
0%
ISO 8000 - Data Quality
1 source controls mapped|2 target controls covered
0%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
0%
UK Open Banking Standard
1 source controls mapped|1 target controls covered
0%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
1 source controls mapped|1 target controls covered
0%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|2 target controls covered
0%
PCI PIN Security
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27003:2017
1 source controls mapped|1 target controls covered
0%
ISO/IEC 23894:2023
1 source controls mapped|3 target controls covered
0%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
0%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
0%
ISO/SAE 21434
1 source controls mapped|1 target controls covered
0%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
0%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27011:2024
1 source controls mapped|2 target controls covered
0%
Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018)
1 source controls mapped|1 target controls covered
0%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
0%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
0%
ISO 37001:2016
1 source controls mapped|1 target controls covered
0%

Coverage is not the same as your position

This page shows what PCI DSS 4.0 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is PCI DSS 4.0 and who does it apply to?

PCI DSS 4.0 is a compliance framework from International (payment card industry; enforced contractually by payment brands and acquirers) with 16 domains and 280 controls. PCI DSS, the PCI Security Standards Council's minimum set of technical and operational controls for every entity that stores, processes or transmits payment card account data or can affect its security, in twelve principal requirements (network security controls, secure configuration, stored account data, transmission encryption, anti-malware, secure software, need-to-know access, identification and authentication, physical security, logging and monitoring, security testing, policy and programs) plus Appendix A for multi-tenant providers, SSL/early TLS POS terminals and designated entities. Read against v4.0.1 (June 2024), the current edition: 280 requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does PCI DSS 4.0 actually require?

PCI DSS 4.0 has 280 controls organised across 16 domains. The largest domains are Req 12: Information Security Policies (37 controls), Req 3: Protect Stored Account Data (29 controls), Req 8: Identify and Authenticate Users (29 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of PCI DSS 4.0 do I already cover?

PCI DSS 4.0 maps to 198 other compliance frameworks. The top mapping partners are SOC 2 (88% coverage), ISO 27002:2022 (88% coverage), NIST SP 800-53 Rev 5 (88% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement PCI DSS 4.0?

Start your PCI DSS 4.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI DSS 4.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 280 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required