PCI DSS Audit Process Guide
From initial scoping to final Attestation of Compliance — a complete walkthrough of every phase in the PCI DSS v4.0.1 audit lifecycle.
6-Phase Audit Lifecycle
1
Scoping
2–4 weeks- Define cardholder data environment (CDE)
- Inventory all in-scope systems
- Network segmentation review
- Document data flows
2
Gap Assessment
3–6 weeks- Review all 285 controls
- Identify gaps vs current state
- Prioritise remediation backlog
- Estimate remediation effort
3
Remediation
4–16 weeks- Close critical findings first
- Implement compensating controls where needed
- Document all changes
- Retest remediated items
4
Evidence Collection
4–8 weeks- Gather policy documents
- Run scans (ASV, internal)
- Collect system config screenshots
- Export log samples and reports
5
QSA Assessment
2–6 weeks- Submit evidence package
- QSA interviews and walkthroughs
- On-site visits (if required)
- Clarification requests
6
Report & Attestation
2–4 weeks- QSA drafts ROC
- Review and respond to findings
- Sign Attestation of Compliance (AOC)
- Submit to acquiring bank
FAQ
How long will your audit take?
Get a personalised audit effort estimate based on your organisation profile.
Run Free Benchmark →