We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 1 of 12

Requirement 1: Install and Maintain Network Security Controls

Firewalls became "network security controls" in v4 — the requirement now covers any technology that polices traffic between networks, including cloud security groups. What the assessor tests is whether every path into and out of the CDE is known, restricted and reviewed.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

1.2.3–1.2.4
Current network + data-flow diagrams

An accurate network diagram and a separate account-data-flow diagram, kept current. The first artefacts an assessor opens; stale diagrams cascade into scoping findings.

1.2.5
All allowed services, protocols and ports approved

Every permitted service and port needs an identified business need and approval. "Any-any" rules are indefensible under this control.

1.2.7
NSC configurations reviewed every six months

Rulesets and security-group configurations are reviewed at least once every six months to confirm relevance and tightness.

1.3.1–1.3.2
CDE inbound and outbound traffic restricted

Traffic to and from the CDE is limited to what is necessary — and everything else is denied, not just "not configured".

1.4.2
Inbound from untrusted networks terminated

Direct inbound traffic from untrusted networks to the CDE is prohibited; connections terminate in a controlled boundary first.

1.5.1
Devices that touch both worlds are controlled

Computing devices that connect to untrusted networks AND the CDE (laptops, jump hosts) need their own security controls — the control that catches split-tunnel VPNs.

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

"Segmentation" that has never been tested

A VLAN is not segmentation until a penetration test proves isolation (11.4.5). Flat networks discovered at assessment time re-scope the whole engagement.

Cloud security groups nobody reviews

v4 explicitly includes cloud NSCs. Six-monthly ruleset reviews (1.2.7) apply to AWS/Azure security groups exactly as to firewalls — most first-year cloud programmes miss this.

Outbound left open

1.3.2 restricts egress from the CDE too. Unrestricted outbound is both a finding and the exfiltration path in real breaches.

Diagrams updated only for the audit

If the diagram was last touched the week before the assessment, the assessor will test its accuracy against reality — and use discrepancies to expand sampling.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • Current network and account-data-flow diagrams with change history
  • Firewall / security-group exports with business justification per rule
  • Six-monthly ruleset review records with actions taken
  • Segmentation penetration-test report covering isolation of the CDE
  • Configuration standard for NSCs and evidence of secured config files

Requirement 1 FAQ

Is network segmentation mandatory under PCI DSS?

No — segmentation is not a requirement, but without it the entire network is in scope. Segmentation reduces scope and must then be verified by penetration testing at least annually (11.4.5).

Do cloud security groups count as firewalls?

Yes. v4 uses the term "network security controls" precisely so that security groups, NACLs and host-based firewalls are covered by Requirement 1, including the six-monthly review at 1.2.7.

How often must firewall rules be reviewed?

At least once every six months (1.2.7), confirming every rule still has a business need and removing what does not.

Requirement 2: Secure Configurations

Requirement 1 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.