Back to Resources
PCI DSS Implementation Checklist: visual preview
Checklist

PCI DSS Implementation Checklist

Payment Card Data Security Requirements

Overview

If your organization processes, stores, or transmits payment card data, PCI DSS compliance is not optional. Version 4.0, released in March 2022 with a transition deadline of March 2025 for most requirements, represents the biggest update in over a decade. This checklist walks through all 12 requirements with practical implementation guidance, helping you understand what is expected and where organizations most commonly fall short.

The 12 PCI DSS Requirements

  • Install and maintain network security controls
  • Apply secure configurations to all system components
  • Protect stored account data
  • Protect cardholder data with strong cryptography during transmission
  • Protect all systems and networks from malicious software
  • Develop and maintain secure systems and software
  • Restrict access to system components and cardholder data by business need to know
  • Identify users and authenticate access to system components
  • Restrict physical access to cardholder data
  • Log and monitor all access to system components and cardholder data
  • Test security of systems and networks regularly
  • Support information security with organizational policies and programs

Key Changes in PCI DSS v4.0

AreaWhat changedImpact
Customized approachOrganizations can design their own controls if they meet the security objectiveMore flexibility but requires deeper documentation and validation
AuthenticationMFA required for all access to the CDE, not just remoteBroader MFA deployment across the organization
EncryptionDisk-level encryption no longer acceptable as sole control for stored dataMay require re-architecting data-at-rest protection
Targeted risk analysisDocumented risk analysis required for flexible requirementsOrganizations must justify their control frequency and scope
Script managementPayment page scripts must be inventoried and authorizedAddresses supply-chain attacks like Magecart
Vulnerability managementInternal vulnerability scans must achieve a passing scoreRemediation SLAs must be formalized

Scoping Your Cardholder Data Environment

Accurate scoping is the single most important step in PCI DSS compliance. Your CDE includes every system that stores, processes, or transmits cardholder data, plus any system connected to or providing security services to those systems. Reducing scope reduces cost and complexity. Strategies include network segmentation, tokenization, point-to-point encryption, and outsourcing payment processing to PCI-compliant service providers. Validate your scope annually and any time there is a significant change to payment architecture.

Common Compliance Gaps

  • Flat network architecture without segmentation between the CDE and corporate network
  • Default credentials on point-of-sale terminals and payment devices
  • Incomplete logging that does not capture all access to cardholder data systems
  • Antivirus or anti-malware not deployed on all applicable systems
  • Accesss reviews not performed regularly for CDE accounts
  • Penetration testing that does not include segmentation validation
  • Missing or outdated data flow diagrams and network diagrams

Assessment and Validation

Your validation method depends on your merchant level. Level 1 merchants (over 6 million transactions per year) require an annual on-site assessment by a Qualified Security Assessor (QSA). Level 2 through 4 merchants can self-assess using the appropriate Self-Assessment Questionnaire (SAQ). Regardless of level, quarterly external vulnerability scans by an Approved Scanning Vendor (ASV) are required. Internal vulnerability scans and penetration tests must be performed at least annually and after significant changes.

Frequently asked questions