SEO Pillar
PCI DSS v4.0.1 Complete Guide
Everything you need to understand, implement, and automate PCI DSS v4.0.1 compliance — from requirements mapping to QSA audit preparation and industry benchmark data.
285
Requirements
test procedures
64
New in v4.0
new requirements
March 2024
Retired
PCI DSS v3.2.1
1,600 hrs
Avg Audit (L1)
industry average
The 12 PCI DSS v4.0.1 Requirements
PCI DSS v4.0.1 organises 285 security controls across 12 principal requirements and 6 control objectives.
| Req | Requirement Title | Control Objective | Controls |
|---|---|---|---|
| 1 | Install and maintain network security controls | Build and Maintain a Secure Network | 19 |
| 2 | Apply secure configurations to all system components | Build and Maintain a Secure Network | 15 |
| 3 | Protect stored account data | Protect Account Data | 24 |
| 4 | Protect cardholder data with strong cryptography | Protect Account Data | 6 |
| 5 | Protect all systems and networks from malware | Maintain a Vulnerability Management Program | 14 |
| 6 | Develop and maintain secure systems and software | Maintain a Vulnerability Management Program | 24 |
| 7 | Restrict access to system components and cardholder data | Implement Strong Access Control Measures | 16 |
| 8 | Identify users and authenticate access | Implement Strong Access Control Measures | 27 |
| 9 | Restrict physical access to cardholder data | Implement Strong Access Control Measures | 14 |
| 10 | Log and monitor all access to system components and cardholder data | Regularly Monitor and Test Networks | 15 |
| 11 | Test security of systems and networks regularly | Regularly Monitor and Test Networks | 17 |
| 12 | Support information security with organisational policies and programs | Maintain an Information Security Policy | 23 |
Deep-Dive Resources
Explore the supporting cluster topics for in-depth guidance on every aspect of PCI DSS compliance.
📋
PCI Audit Process
Step-by-step ROC and SAQ audit guide
💰
PCI Compliance Cost
Cost breakdown by org size and SAQ type
📁
PCI Evidence Collection
Evidence types, retention, and automation
🔧
PCI Remediation Workflows
Finding closure, tracking, and best practices
⚡
PCI Automation
Automating compliance for 60% efficiency gains
📊
Run PCI Benchmark
See how your programme compares to 4,700+ orgs
Frequently Asked Questions
See How Your Programme Compares
Run the PCI Efficiency Benchmark to get your maturity score, estimated audit hours, and industry percentile in 3 minutes.
Run Free Benchmark →