Free download · PCI DSS v4.0.1 evidence checklist
PCI DSS v4.0.1 evidence & screenshot checklist
The exact evidence a QSA asks for, requirement by requirement — with the screenshot or export that satisfies each one. Stop guessing what your assessor wants and walk into the on-site with a complete, organised evidence pack.
Requirements
All 12
Evidence items
250+
Format
Excel + PDF
Standard
v4.0.1
Get the pci dss v4.0.1 evidence checklist
Enter your work email and we’ll send it straight to your inbox.
What’s included
Evidence item per requirement
Every applicable requirement and testing procedure mapped to the specific artefact, screenshot or export that evidences it.
Screenshot guide
What each screenshot must show (and what invalidates it) so evidence is accepted first time.
v4.0.1 deltas
The newly-enforced v4.0.1 controls (MFA into the CDE, targeted risk analyses) called out so nothing is missed.
Tracking workbook
A status tracker (collected / pending / N-A) with owner and due date to run evidence collection like a project.
Who it’s for
- Payment aggregators, gateways and fintechs preparing for a Level 1 RoC
- Security and compliance leads owning PCI DSS evidence
- Anyone whose last assessment stalled on missing or rejected evidence
Inside the pci dss v4.0.1 evidence checklist
- Requirement-by-requirement evidence list (all 12)
- Screenshot acceptance criteria
- v4.0.1 hardening deltas
- ASV scan, pentest and change-management evidence
- Status tracker with owners and due dates
Prepared by CyberSigma PCI QSA practice · Reviewed by a PCI SSC-qualified QSA · Last updated July 2026
Want us to run the evidence gap for you?
A PCI SSC-listed QSA reviews your current evidence against v4.0.1 and tells you exactly what is missing before the on-site.
